Skip to content

Conversation

@onelapahead
Copy link

Upgrades log4j, netty, and vertex for MEDIUM CVEs. log4j upgrade requires some extra code and settings in order to avoid compiler warnings I was getting that were being marked as errors due to-Werror.

And then includes a gradle.lockfile for tracking deps that can be consumed by trivy in order to generate SBOMs and perform license/vulnerability scans more easily and accurately.

… Locking and Easier SBOM Generation

Signed-off-by: hfuss <hayden.fuss@kaleido.io>
@onelapahead
Copy link
Author

Opened upstream OSS PR to propose lockfile's long-term in Besu: hyperledger#9603

Copy link

@matthew1001 matthew1001 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@matthew1001 matthew1001 merged commit 5d81acd into kaleido-besu-release-25.8.0 Jan 6, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants