We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
we have received a report of security scans finding the netty dependency to be problematic. to quote:
Scan an OCI image containing the karate.jar, with for example trivy, and discover a high severity finding of CWE-400 by usage of io.netty:netty-common
link: GHSA-xq3w-v528-46rv
The text was updated successfully, but these errors were encountered:
upgrade armeria #2630
8e0c491
upgrading armeria ensures that netty 4.1.115.Final is used which resolves the CVE cc @SkyHuk
karate 1.5.1 will be released soon (ETA to be determined), and can be expedited on request
note that teams should be able to over-ride dependencies without waiting for a release as explained here: #1834 (comment)
Sorry, something went wrong.
ptrthomas
No branches or pull requests
we have received a report of security scans finding the netty dependency to be problematic. to quote:
link: GHSA-xq3w-v528-46rv
The text was updated successfully, but these errors were encountered: