Skip to content

Update netty to 4.1.130.Final and vertx to 4.5.24#2310

Open
ivonaest wants to merge 5 commits into
linkedin:mainfrom
Nordix:fix/netty-update
Open

Update netty to 4.1.130.Final and vertx to 4.5.24#2310
ivonaest wants to merge 5 commits into
linkedin:mainfrom
Nordix:fix/netty-update

Conversation

@ivonaest
Copy link
Copy Markdown

Summary

  1. Why:
    To remove CVEs:

  2. What:

Additional evidence

Partial output from security scanner Trivy:
cves netty

Categorization

  • security/CVE

@ivonaest ivonaest changed the title fix: Remediate CVE-2025-58057, CVE-2025-58056 and CVE-2025-55163 by u… Update netty to 4.1.127.Final and vertex to 4.5.21 Oct 2, 2025
@ivonaest
Copy link
Copy Markdown
Author

ivonaest commented Oct 9, 2025

Hi @CCisGG , would you be able to retrigger the build as it seems to be failing due to time out issue. The project was building successfully and has passed all of the tests after the changes have been made.
Thank you

@ivonaest
Copy link
Copy Markdown
Author

Hi @CCisGG ,

One of the test failed

image

So I have rerun it on my local machine. It passed there

image

Could this be a problem with tests? Would another rerun resolve it?

Thank you

…pgrading netty to 4.1.127.Final and vertx to 4.5.21

Signed-off-by: ivonaest <ivona.cvija@est.tech>
@ivonaest
Copy link
Copy Markdown
Author

Hi @kyguy, could you please check out this CVE fix. Would you like it done differently or is this okay?
Thank you, Ivona

Copy link
Copy Markdown
Contributor

@kyguy kyguy left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

could you please check out this CVE fix. Would you like it done differently or is this okay?

Hi @ivonaest, yes this format is fine, I have tested these changes in a build and everything works as expected

@kyguy
Copy link
Copy Markdown
Contributor

kyguy commented Nov 4, 2025

Hi @ivonaest, now that Vert.x 4.5.22 has been released we should bump the PR to that version since it addresses the most recent CVEs!

@ivonaest
Copy link
Copy Markdown
Author

ivonaest commented Nov 4, 2025

Hi @ivonaest, now that Vert.x 4.5.22 has been released we should bump the PR to that version since it addresses the most recent CVEs!

Hi @kyguy , no worries. I will update vertx to that version and make another commit. Thank you for assistance

akatona84 and others added 3 commits November 4, 2025 15:36
@ivonaest ivonaest changed the title Update netty to 4.1.127.Final and vertex to 4.5.21 Update netty to 4.1.127.Final and vertex to 4.5.22 Nov 10, 2025
Signed-off-by: ivonaest <ivona.cvije@est.tech>
@ivonaest ivonaest changed the title Update netty to 4.1.127.Final and vertex to 4.5.22 Update netty to 4.1.130.Final and vertex to 4.5.24 Jan 20, 2026
@ivonaest ivonaest changed the title Update netty to 4.1.130.Final and vertex to 4.5.24 Update netty to 4.1.130.Final and vertx to 4.5.24 Jan 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants