Skip to content

Commit e0e9868

Browse files
authored
GH-5050: add netty dependency management to fix CVEs (#5051)
Signed-off-by: Bart Hanssens <bart.hanssens@bosa.fgov.be>
1 parent 01b7798 commit e0e9868

1 file changed

Lines changed: 8 additions & 0 deletions

File tree

pom.xml

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -377,6 +377,7 @@
377377
<servlet.version>3.1.0</servlet.version>
378378
<junit.version>5.9.3</junit.version>
379379
<jetty.version>9.4.54.v20240208</jetty.version>
380+
<netty.version>4.1.111.Final</netty.version>
380381
</properties>
381382
<dependencyManagement>
382383
<dependencies>
@@ -396,6 +397,13 @@
396397
<type>pom</type>
397398
<scope>import</scope>
398399
</dependency>
400+
<dependency>
401+
<groupId>io.netty</groupId>
402+
<artifactId>netty-bom</artifactId>
403+
<version>${netty.version}</version>
404+
<type>pom</type>
405+
<scope>import</scope>
406+
</dependency>
399407
<!-- Annotations is designed to be fixed at the 2.x.0 minor version level, but in practice is still being released for
400408
2.8.x patch versions. See https://github.com/FasterXML/jackson-bom/issues/4 -->
401409
<dependency>

0 commit comments

Comments
 (0)