Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[2.2] Protobuf Java and gRPC version updates (CVE-2021-22569) #22761

Merged
merged 1 commit into from
Feb 23, 2022

Conversation

cescoffier
Copy link
Member

@cescoffier cescoffier commented Jan 10, 2022

Update Protobuf Java to 3.18.2 and gRPC Java to 1.41.2

Upgraded Protobuf Java to 3.18.2 to avoid CVE-2021-22569 - GHSA-wrvw-hg22-4m67

@quarkus-bot
Copy link

quarkus-bot bot commented Jan 10, 2022

Thanks for your pull request!

The title of your pull request does not follow our editorial rules. Could you have a look?

  • title should preferably start with an uppercase character (if it makes sense!)

This message is automatically generated by a bot.

@cescoffier cescoffier changed the base branch from main to 2.2 January 10, 2022 09:20
@cescoffier cescoffier requested a review from gsmet January 10, 2022 09:20
@quarkus-bot quarkus-bot bot added area/amazon-lambda area/dependencies Pull requests that update a dependency file labels Jan 10, 2022
@cescoffier cescoffier changed the title [2.2] PRotobuf Java and gRPC version updates (CVE-2021-22569) [2.2] Protobuf Java and gRPC version updates (CVE-2021-22569) Jan 10, 2022
@gsmet gsmet added this to the 2.2.6.Final milestone Jan 10, 2022
@sberyozkin sberyozkin self-requested a review February 7, 2022 14:19
@gsmet gsmet merged commit 44d5298 into quarkusio:2.2 Feb 23, 2022
@cescoffier cescoffier deleted the 2.2-protobuf-update branch February 23, 2022 18:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/dependencies Pull requests that update a dependency file area/grpc gRPC
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Documentation is unclear about how to mount a PVC on Openshift Dev UI - Test report output not visible
3 participants