From 44b7fcf527fcba94f600e31270a44b5e3e346761 Mon Sep 17 00:00:00 2001 From: cleverchuk Date: Thu, 7 May 2026 16:03:21 -0400 Subject: [PATCH] bump netty and grpc version to fix CVEs --- dependencyManagement/build.gradle.kts | 2 +- libs/core/build.gradle.kts | 8 +++++--- 2 files changed, 6 insertions(+), 4 deletions(-) diff --git a/dependencyManagement/build.gradle.kts b/dependencyManagement/build.gradle.kts index 1145aa30..d8f0e35f 100644 --- a/dependencyManagement/build.gradle.kts +++ b/dependencyManagement/build.gradle.kts @@ -25,7 +25,7 @@ javaPlatform { } dependencies { - api(platform("io.netty:netty-bom:4.1.132.Final")) + api(platform("io.netty:netty-bom:4.1.133.Final")) constraints { api("org.mockito:mockito-core:$mockitoVersion") diff --git a/libs/core/build.gradle.kts b/libs/core/build.gradle.kts index 4dd15465..fc1753b6 100644 --- a/libs/core/build.gradle.kts +++ b/libs/core/build.gradle.kts @@ -4,14 +4,16 @@ plugins { description = "core" +val grpcVersion = "1.81.0" + dependencies { implementation(project(":libs:logging")) implementation(project(":libs:config")) implementation(project(":libs:sampling")) - implementation("io.grpc:grpc-netty:1.80.0") - implementation("io.grpc:grpc-stub:1.80.0") - implementation("io.grpc:grpc-protobuf:1.80.0") + implementation("io.grpc:grpc-netty:$grpcVersion") + implementation("io.grpc:grpc-stub:$grpcVersion") + implementation("io.grpc:grpc-protobuf:$grpcVersion") compileOnly("org.json:json") compileOnly("io.opentelemetry:opentelemetry-api")