Skip to content

Conversation

@octo-sts
Copy link
Contributor

@octo-sts octo-sts bot commented Sep 4, 2025

apache-pulsar/4.0.6-r1: fix GHSA-3p8m-j85q-pgmj

Advisory data: https://github.com/wolfi-dev/advisories/blob/main/apache-pulsar.advisories.yaml


"Breadcrumbs" for this automated service

@octo-sts
Copy link
Contributor Author

octo-sts bot commented Sep 4, 2025

📦 Build Failed: Missing Dependency

package io.netty.buffer does not exist

Build Details

Category Details
Build System Maven
Failure Point maven-compiler-plugin:3.11.0:compile (default-compile) on project java-test-plugins

Root Cause Analysis 🔍

The Netty dependency is missing from the classpath. Multiple Java source files are trying to import Netty packages (io.netty.buffer, io.netty.channel, io.netty.channel.socket) but these packages are not available, causing compilation failures. This indicates that the Netty library dependency is either missing from the pom.xml file or not properly resolved during the Maven build process.


Was this comment helpful? Please use 👍 or 👎 reactions on this comment.

@octo-sts octo-sts bot added the ai/skip-comment Stop AI from commenting on PR label Sep 4, 2025
@dnegreira dnegreira self-assigned this Sep 5, 2025
Remediate GHSA-3p8m-j85q-pgmj
Bump netty.version to 4.1.125.Final

Signed-off-by: David Negreira <david.negreira@chainguard.dev>
@dnegreira dnegreira force-pushed the cve-apache-pulsar-4.0.6-r1-efe4e7b6711536ffd39e102d336e4e69 branch from efe838c to 63cc8b2 Compare September 5, 2025 13:32
@octo-sts octo-sts bot added the bincapz/blocking Bincapz (aka malcontent) scan results detected CRITICALs on the packages. label Sep 5, 2025
@dnegreira dnegreira enabled auto-merge September 5, 2025 15:26
@stevebeattie
Copy link
Member

stevebeattie commented Sep 8, 2025

The vendored statically linked netty-tcnative windows dll v2.0.73 has started being flagged by malcontent as matching the NitrogenLoader Config Extraction malware; both virustotal and Hybrid Analyze also flag this DLL, for unknown reasons. The v2.0.72 version does not get flagged. See the upstream report at netty/netty-tcnative#938 .

This should be safe for linux image consumers as the windows dll should not be used (so marking this as reviewed), but it also raises the question as to whether or not (a) the packaging can be adjusted to not include statically linked windows DLLs and (b) statically linked SSL libraries could possibly cause problems for FIPs version of packaging.

@stevebeattie stevebeattie added the malcontent/reviewed The malcontent findings in this PR have been manually reviewed by security. label Sep 8, 2025
efbar and others added 2 commits September 9, 2025 10:44
Signed-off-by: Francesco Bartolini <francesco.bartolini@chainguard.dev>
Signed-off-by: David Negreira <david.negreira@chainguard.dev>
@octo-sts octo-sts bot added bincapz/pass bincapz/pass Bincapz (aka. malcontent) scan didn't detect any CRITICALs on the scanned packages. manual/review-needed and removed bincapz/blocking Bincapz (aka malcontent) scan results detected CRITICALs on the packages. labels Sep 9, 2025
@dnegreira dnegreira merged commit 02e8585 into main Sep 10, 2025
17 of 18 checks passed
@dnegreira dnegreira deleted the cve-apache-pulsar-4.0.6-r1-efe4e7b6711536ffd39e102d336e4e69 branch September 10, 2025 06:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ai/skip-comment Stop AI from commenting on PR apache-pulsar automated pr bincapz/pass bincapz/pass Bincapz (aka. malcontent) scan didn't detect any CRITICALs on the scanned packages. GHSA-3p8m-j85q-pgmj malcontent/reviewed The malcontent findings in this PR have been manually reviewed by security. manual/review-needed maven/pombump request-cve-remediation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants