Commit 0a26b29
fix: upgrade io.netty:netty-codec-http to 4.2.13.Final (GHSA-57rv-r2g8-2cj3)
Add resolutionStrategy.eachDependency constraint to force io.netty:netty-codec-http
to 4.2.13.Final to address HttpClientCodec response desynchronization vulnerability.
Related: CHK-13428, GHSA-57rv-r2g8-2cj3, GitHub alert #60
Agent-Logs-Url: https://github.com/getyourguide/openapi-validation-java/sessions/9949f828-0f32-4b78-be7b-ae7303b39bb2
Co-authored-by: gygrobot <19344429+gygrobot@users.noreply.github.com>1 parent e39dd4e commit 0a26b29
1 file changed
Lines changed: 5 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
35 | 35 | | |
36 | 36 | | |
37 | 37 | | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
38 | 43 | | |
39 | 44 | | |
40 | 45 | | |
| |||
0 commit comments