Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
chore(dependencies): pin io.netty:netty-bom to 4.1.100.Final (#1158)
to resolve sonatype-2023-4380 / GHSA-xpw8-rcwv-8f8p Before this, spring boot 2.5.15 brought in version 4.1.92.Final of netty. Note that one of the aws sdk v2 dependencies was expecting 4.1.86.Final: | \--- software.amazon.awssdk:netty-nio-client:2.19.0 | +--- software.amazon.awssdk:annotations:2.19.0 | +--- software.amazon.awssdk:http-client-spi:2.19.0 (*) | +--- software.amazon.awssdk:utils:2.19.0 (*) | +--- software.amazon.awssdk:metrics-spi:2.19.0 (*) | +--- io.netty:netty-codec-http:4.1.86.Final -> 4.1.92.Final | | +--- io.netty:netty-common:4.1.92.Final | | +--- io.netty:netty-buffer:4.1.92.Final | | | \--- io.netty:netty-common:4.1.92.Final | | +--- io.netty:netty-transport:4.1.92.Final | | | +--- io.netty:netty-common:4.1.92.Final | | | +--- io.netty:netty-buffer:4.1.92.Final (*) | | | \--- io.netty:netty-resolver:4.1.92.Final | | | \--- io.netty:netty-common:4.1.92.Final | | +--- io.netty:netty-codec:4.1.92.Final | | | +--- io.netty:netty-common:4.1.92.Final | | | +--- io.netty:netty-buffer:4.1.92.Final (*) | | | \--- io.netty:netty-transport:4.1.92.Final (*) | | \--- io.netty:netty-handler:4.1.92.Final | | +--- io.netty:netty-common:4.1.92.Final | | +--- io.netty:netty-resolver:4.1.92.Final (*) | | +--- io.netty:netty-buffer:4.1.92.Final (*) | | +--- io.netty:netty-transport:4.1.92.Final (*) | | +--- io.netty:netty-transport-native-unix-common:4.1.92.Final | | | +--- io.netty:netty-common:4.1.92.Final | | | +--- io.netty:netty-buffer:4.1.92.Final (*) | | | \--- io.netty:netty-transport:4.1.92.Final (*) | | \--- io.netty:netty-codec:4.1.92.Final (*) | +--- io.netty:netty-codec-http2:4.1.86.Final -> 4.1.92.Final | | +--- io.netty:netty-common:4.1.92.Final | | +--- io.netty:netty-buffer:4.1.92.Final (*) | | +--- io.netty:netty-transport:4.1.92.Final (*) | | +--- io.netty:netty-codec:4.1.92.Final (*) | | +--- io.netty:netty-handler:4.1.92.Final (*) | | \--- io.netty:netty-codec-http:4.1.92.Final (*) | +--- io.netty:netty-codec:4.1.86.Final -> 4.1.92.Final (*) | +--- io.netty:netty-transport:4.1.86.Final -> 4.1.92.Final (*) | +--- io.netty:netty-common:4.1.86.Final -> 4.1.92.Final | +--- io.netty:netty-buffer:4.1.86.Final -> 4.1.92.Final (*) | +--- io.netty:netty-handler:4.1.86.Final -> 4.1.92.Final (*) | +--- io.netty:netty-transport-classes-epoll:4.1.86.Final -> 4.1.92.Final | | +--- io.netty:netty-common:4.1.92.Final | | +--- io.netty:netty-buffer:4.1.92.Final (*) | | +--- io.netty:netty-transport:4.1.92.Final (*) | | \--- io.netty:netty-transport-native-unix-common:4.1.92.Final (*) This commit updates v2 of the aws sdk to 2.23.7 of v2 of the aws sdk. As of 21-jan-24, this is the most recent version that uses version 4.1.100.Final of netty. | \--- software.amazon.awssdk:netty-nio-client:2.23.7 | +--- software.amazon.awssdk:annotations:2.23.7 | +--- software.amazon.awssdk:http-client-spi:2.23.7 (*) | +--- software.amazon.awssdk:utils:2.23.7 (*) | +--- software.amazon.awssdk:metrics-spi:2.23.7 (*) | +--- io.netty:netty-codec-http:4.1.100.Final | | +--- io.netty:netty-common:4.1.100.Final | | +--- io.netty:netty-buffer:4.1.100.Final | | | \--- io.netty:netty-common:4.1.100.Final | | +--- io.netty:netty-transport:4.1.100.Final | | | +--- io.netty:netty-common:4.1.100.Final | | | +--- io.netty:netty-buffer:4.1.100.Final (*) | | | \--- io.netty:netty-resolver:4.1.100.Final | | | \--- io.netty:netty-common:4.1.100.Final | | +--- io.netty:netty-codec:4.1.100.Final | | | +--- io.netty:netty-common:4.1.100.Final | | | +--- io.netty:netty-buffer:4.1.100.Final (*) | | | \--- io.netty:netty-transport:4.1.100.Final (*) | | \--- io.netty:netty-handler:4.1.100.Final | | +--- io.netty:netty-common:4.1.100.Final | | +--- io.netty:netty-resolver:4.1.100.Final (*) | | +--- io.netty:netty-buffer:4.1.100.Final (*) | | +--- io.netty:netty-transport:4.1.100.Final (*) | | +--- io.netty:netty-transport-native-unix-common:4.1.100.Final | | | +--- io.netty:netty-common:4.1.100.Final | | | +--- io.netty:netty-buffer:4.1.100.Final (*) | | | \--- io.netty:netty-transport:4.1.100.Final (*) | | \--- io.netty:netty-codec:4.1.100.Final (*) | +--- io.netty:netty-codec-http2:4.1.100.Final | | +--- io.netty:netty-common:4.1.100.Final | | +--- io.netty:netty-buffer:4.1.100.Final (*) | | +--- io.netty:netty-transport:4.1.100.Final (*) | | +--- io.netty:netty-codec:4.1.100.Final (*) | | +--- io.netty:netty-handler:4.1.100.Final (*) | | \--- io.netty:netty-codec-http:4.1.100.Final (*) | +--- io.netty:netty-codec:4.1.100.Final (*) | +--- io.netty:netty-transport:4.1.100.Final (*) | +--- io.netty:netty-common:4.1.100.Final | +--- io.netty:netty-buffer:4.1.100.Final (*) | +--- io.netty:netty-handler:4.1.100.Final (*) | +--- io.netty:netty-transport-classes-epoll:4.1.100.Final | | +--- io.netty:netty-common:4.1.100.Final | | +--- io.netty:netty-buffer:4.1.100.Final (*) | | +--- io.netty:netty-transport:4.1.100.Final (*) | | \--- io.netty:netty-transport-native-unix-common:4.1.100.Final (*)
- Loading branch information