Skip to content

Conversation

@guusdk
Copy link
Member

@guusdk guusdk commented Dec 18, 2025

Updates all Netty dependencies to 4.1.130.Final to incorporate the latest security fixes and improvements in the 4.1.x branch. This reduces exposure to reported Netty CVEs and addresses vulnerability scan findings, while maintaining compatibility with Openfire.

Updates all Netty dependencies to 4.1.130.Final to incorporate the latest security fixes and improvements in the 4.1.x branch. This reduces exposure to reported Netty CVEs and addresses vulnerability scan findings, while maintaining compatibility with Openfire.
@guusdk guusdk added the backport 5.0 on merge, GHA will generate a PR with these changes against 5.0 branch label Dec 18, 2025
@guusdk
Copy link
Member Author

guusdk commented Dec 18, 2025

Note that we're probably interested in moving to upgrading to newer versions (eg: 4.2). This upgrade brings us to the latest patch release of the branch that we're currently on. I'd like to backport that to Openfire's 5.0.x branch. The upgrade to Netty 4.2 (or later) is a more significant change, which should not go in one of our patch released. Instead it should be applied to the Main branch (to be included in a non-patch release).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport 5.0 on merge, GHA will generate a PR with these changes against 5.0 branch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant