Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade to Netty 4.1.42.Final #18609

Closed
wilkinsona opened this issue Oct 15, 2019 · 5 comments
Closed

Upgrade to Netty 4.1.42.Final #18609

wilkinsona opened this issue Oct 15, 2019 · 5 comments
Assignees
Labels
type: dependency-upgrade A dependency upgrade
Milestone

Comments

@wilkinsona
Copy link
Member

No description provided.

@wilkinsona wilkinsona added the type: dependency-upgrade A dependency upgrade label Oct 15, 2019
@wilkinsona wilkinsona added this to the 2.2.0 milestone Oct 15, 2019
@wilkinsona wilkinsona self-assigned this Oct 15, 2019
@dreis2211
Copy link
Contributor

May I ask why the upgrade was done although reactor/reactor-netty#844 is not resolved yet? Afaik it blocked earlier upgrades.

@wilkinsona
Copy link
Member Author

Of course. The recently announced vulnerability in Netty's HTTP codec caused us to re-evaluate things. Given a choice between UDP client problems and an HTTP server vulnerability, we decided that the former was less bad than the latter. Things are less clear-cut in the 2.1.x line as there's also a connection pooling problem with Reactor Netty 0.8.x and recent Netty 4.1.x releases. Our hope is that these will be addressed in Reactor Netty in time for our 2.1.10 release.

/cc @smaldini @violetagg

@violetagg
Copy link
Member

Reactor Netty releases 0.8.13, 0.9.1 are scheduled for Monday 28.10
In the snapshots we've already updated Netty to the latest released version (4.1.42.Final)

@snicoll
Copy link
Member

snicoll commented Oct 25, 2019

@violetagg for the record 4.1.43.Final was released yesterday.

@violetagg
Copy link
Member

thanks - both 0.8.13 and 0.9.1 snapshots are updated to Netty 4.1.43.Final

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
type: dependency-upgrade A dependency upgrade
Projects
None yet
Development

No branches or pull requests

4 participants