Skip to content

Upgrade netty due to CVE-2024-47535 #2630

@ptrthomas

Description

@ptrthomas

we have received a report of security scans finding the netty dependency to be problematic. to quote:

Scan an OCI image containing the karate.jar, with for example trivy, and discover a 
high severity finding of CWE-400 by usage of io.netty:netty-common

link: GHSA-xq3w-v528-46rv

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions