Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump protobuf-java to 3.23.0 #4008

Merged
merged 1 commit into from
Jun 16, 2023

Conversation

devinrsmith
Copy link
Member

https://nvd.nist.gov/vuln/detail/CVE-2022-3171
https://nvd.nist.gov/vuln/detail/CVE-2022-3509
https://nvd.nist.gov/vuln/detail/CVE-2022-3510

This might not be sufficient to take care of the CVEs above - it is probably more important to update the compilation protoc versions, which comes from protoc-base image, deephaven/deephaven-base-images#62

@devinrsmith devinrsmith added this to the June 2023 milestone Jun 15, 2023
@devinrsmith devinrsmith self-assigned this Jun 15, 2023
@devinrsmith devinrsmith marked this pull request as ready for review June 16, 2023 14:20
@devinrsmith
Copy link
Member Author

Actually, I think this is sufficient to fix the problem, as it seems to be the reflection-based API that is updated for CVEs mentioned above.

@devinrsmith devinrsmith merged commit 2b2630a into deephaven:main Jun 16, 2023
@devinrsmith devinrsmith deleted the bump-protobuf-java branch June 16, 2023 20:26
@github-actions github-actions bot locked and limited conversation to collaborators Jun 16, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants