Skip to content

Updated netty to 4.1.130.Final and vertx to 4.5.24#5

Open
andrewlamb-est wants to merge 1 commit into2.5.146-estfrom
cherrypick/2.5.146-commit8a20899-netty-update
Open

Updated netty to 4.1.130.Final and vertx to 4.5.24#5
andrewlamb-est wants to merge 1 commit into2.5.146-estfrom
cherrypick/2.5.146-commit8a20899-netty-update

Conversation

@andrewlamb-est
Copy link
Copy Markdown

Summary

  1. Why:
    ESTA-351 cherrypick and merge netty update commit from:
    linkedin@8a20899
    into Nordix cruise-control branch 2.5.146-est, to remove CVEs:
    CVE-2025-58057
    CVE-2025-58056
    CVE-2025-55163

  2. What:
    Update netty to 4.1.130.Final to remove CVE-2025-58057
    and vertx to 4.5.24 to remove CVE-2025-58056 and CVE-2025-55163
    Additional evidence
    Partial output from security scanner Trivy:

image

Categorization

  • documentation
  • bugfix
  • new feature
  • refactor
  • security/CVE
  • other

Signed-off-by: ivonaest <ivona.cvije@est.tech>
@andrewlamb-est andrewlamb-est mentioned this pull request Apr 30, 2026
1 task
@andrewlamb-est
Copy link
Copy Markdown
Author

Replaces previous PR: #4
( Cherry-picking instead of requesting complete PR from https://github.com/Nordix/cruise-control/tree/fix/netty-update )
Waiting for workflow before seeking reviews.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant