This is an automated email from the ASF dual-hosted git repository.
wusheng pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/skywalking-java.git
The following commit(s) were added to refs/heads/main by this push:
new 0d8f758bf0 fix CVE-2022-41915 (#434)
0d8f758bf0 is described below
commit 0d8f758bf0874372a0cb82bbc1aab3bf248f6069
Author: alan <[email protected]>
AuthorDate: Wed Dec 28 17:26:25 2022 +0800
fix CVE-2022-41915 (#434)
---
CHANGES.md | 1 +
dist-material/LICENSE | 2 +-
pom.xml | 2 +-
3 files changed, 3 insertions(+), 2 deletions(-)
diff --git a/CHANGES.md b/CHANGES.md
index 67ebcbf918..f67237ae94 100644
--- a/CHANGES.md
+++ b/CHANGES.md
@@ -22,6 +22,7 @@ Release Notes.
* Fix In the higher version of mysql-connector-java 8x, there is an error in
the value of db.instance.
* Add support for KafkaClients 3.x.
* Support to customize the collect period of JVM relative metrics.
+* Upgrade netty-codec-http2 to 4.1.86.Final.
#### Documentation
diff --git a/dist-material/LICENSE b/dist-material/LICENSE
index e2c7a77be5..c78714d002 100755
--- a/dist-material/LICENSE
+++ b/dist-material/LICENSE
@@ -220,7 +220,7 @@ The text of each license is the standard Apache 2.0 license.
Google: gson 2.8.9: https://github.com/google/gson , Apache 2.0
Google: proto-google-common-protos 2.0.1:
https://github.com/googleapis/googleapis , Apache 2.0
Google: jsr305 3.0.2:
http://central.maven.org/maven2/com/google/code/findbugs/jsr305/3.0.0/jsr305-3.0.0.pom
, Apache 2.0
- netty 4.1.79: https://github.com/netty/netty/blob/4.1/LICENSE.txt, Apache
2.0
+ netty 4.1.86: https://github.com/netty/netty/blob/4.1/LICENSE.txt, Apache
2.0
========================================================================
BSD licenses
diff --git a/pom.xml b/pom.xml
index 1e64fc68c9..aae5e42eb7 100755
--- a/pom.xml
+++ b/pom.xml
@@ -88,7 +88,7 @@
<!-- core lib dependency -->
<bytebuddy.version>1.12.19</bytebuddy.version>
<grpc.version>1.50.0</grpc.version>
- <netty.version>4.1.79.Final</netty.version>
+ <netty.version>4.1.86.Final</netty.version>
<gson.version>2.8.9</gson.version>
<os-maven-plugin.version>1.6.2</os-maven-plugin.version>
<protobuf-maven-plugin.version>0.6.1</protobuf-maven-plugin.version>