Skip to content

Conversation

@LMarkie
Copy link
Contributor

@LMarkie LMarkie commented Sep 26, 2023

What this PR does:
Overrides the netty dependencies within grpc-netty.

This removes CVE-2023-34462 which will address complaints made by FusionReactor customers.

Uses latest netty version as grpc guys found a regression in 4.1.94.Final.

Which issue(s) this PR fixes:
Fixes #

Checklist

  • Tests updated
  • Documentation added
  • CHANGELOG.md updated - the order of entries should be [CHANGE], [FEATURE], [ENHANCEMENT], [BUGFIX]

@Umaaz
Copy link
Member

Umaaz commented Sep 27, 2023

This might be worth a look instead: grpc/grpc-java#10468 (comment)

@Umaaz
Copy link
Member

Umaaz commented Sep 27, 2023

@LMarkie Can you merge master and re-push this pls.

@LMarkie
Copy link
Contributor Author

LMarkie commented Sep 27, 2023

This might be worth a look instead: grpc/grpc-java#10468 (comment)

@Umaaz
I've used grpc-netty-shaded instead, if that's what you meant, which serves my purpose but increases the jar size slightly (0.3MB) in case that's a problem for you.
It looks like grpc's shaded netty is larger than deep's shaded netty.

@Umaaz
Copy link
Member

Umaaz commented Sep 28, 2023

@LMarkie that was originally what I thought yes. Could you revert that last commit for now though. I initially missed the comment about the performance being fixed in 4.1.96.Final.

@Umaaz Umaaz merged commit 2135c29 into intergral:master Sep 29, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants