Skip to content

Fix CVE-2025-58057, CVE-2025-58056, CVE-2025-55163 using netty-bom#331

Open
alishaaaqil wants to merge 1 commit intokiegroup:7.67.x-bluefrom
alishaaaqil:fix-netty-cve-2025-58057
Open

Fix CVE-2025-58057, CVE-2025-58056, CVE-2025-55163 using netty-bom#331
alishaaaqil wants to merge 1 commit intokiegroup:7.67.x-bluefrom
alishaaaqil:fix-netty-cve-2025-58057

Conversation

@alishaaaqil
Copy link
Copy Markdown

@alishaaaqil alishaaaqil commented Feb 26, 2026

Fixes netty vulnerabilities in docker-workitem module by upgrading to netty 4.1.128.Final.
Add version.netty=4.1.128.Final property
Import netty-bom in dependencyManagement for complete coverage
Add docker-java-transport-netty dependency to docker-workitem

Ensemble PR: kiegroup/process-migration-service#143

@akumar074
Copy link
Copy Markdown
Member

Jenkins run fdb

2 similar comments
@akumar074
Copy link
Copy Markdown
Member

Jenkins run fdb

@akumar074
Copy link
Copy Markdown
Member

Jenkins run fdb

@akumar074
Copy link
Copy Markdown
Member

Jenkins retest this

@akumar074
Copy link
Copy Markdown
Member

Jenkins run fdb

@akumar074
Copy link
Copy Markdown
Member

Jenkins retest this

@RishiRajAnand
Copy link
Copy Markdown
Member

I suppose fdb is broken for jbpm-work-items

[2026-03-16T12:17:04.740Z] [WARNING] The requested profile "no-showcase" could not be activated because it does not exist.
[2026-03-16T12:17:04.740Z] [ERROR] Failed to execute goal org.apache.maven.plugins:maven-dependency-plugin:3.1.1:unpack (get-business-central) on project add-ons-distribution: Unable to find/resolve artifact. Could not find artifact org.drools:droolsjbpm-brms-distribution:zip:bin:7.67.2-SNAPSHOT in mirror-central (https://baqe-nexus.apps.int.prod-scale-spoke1-aws-us-east-1.itup.redhat.com/nexus/content/groups/kie-all/) -> [Help 1]
[2026-03-16T12:17:04.740Z] org.apache.maven.lifecycle.LifecycleExecutionException: Failed to execute goal org.apache.maven.plugins:maven-dependency-plugin:3.1.1:unpack (get-business-central) on project add-ons-distribution: Unable to find/resolve artifact.

@RishiRajAnand
Copy link
Copy Markdown
Member

so i reran FDB on kiegroup/process-migration-service#143

@akumar074
Copy link
Copy Markdown
Member

Jenkins run fdb

@akumar074
Copy link
Copy Markdown
Member

The PR check failure is consistent.
[ERROR] Failed to execute goal org.apache.maven.plugins:maven-dependency-plugin:3.1.1:unpack (get-business-central) on project add-ons-distribution: Unable to find/resolve artifact. Could not find artifact org.drools:droolsjbpm-brms-distribution:zip:bin:7.67.2-SNAPSHOT in mirror-central (https://baqe-nexus.apps.int.prod-scale-spoke1-aws-us-east-1.itup.redhat.com/nexus/content/groups/kie-all/) -> [Help 1] [2026-03-23T12:49:45.043Z] org.apache.maven.lifecycle.LifecycleExecutionException: Failed to execute goal org.apache.maven.plugins:maven-dependency-plugin:3.1.1:unpack (get-business-central) on project add-ons-distribution: Unable to find/resolve artifact.

@akumar074
Copy link
Copy Markdown
Member

Jenkins run fdb

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants