Skip to content

Conversation

sgrampone
Copy link
Contributor

@sgrampone sgrampone commented Oct 13, 2025

Issue:206683
Bump google-cloud-storage from version 1.118.1 to version 2.58.1 (latest)

Fix CVE-2021-22573 from transitive dependency google-oauth-client
Fix CVE-2022-25647 from transitive dependency gson

Add overwrite to transitive dependency grpc-netty-shaded version 1.71.0 to 1.75.0 because of CVE-2025-55163

#GXSEC

@sgrampone sgrampone requested a review from ggallotti October 13, 2025 15:44
@sgrampone sgrampone added the dependencies Pull requests that update a dependency file label Oct 13, 2025
@genexusbot
Copy link
Collaborator

Cherry pick to beta success

1 similar comment
@genexusbot
Copy link
Collaborator

Cherry pick to beta success

@genexusbot
Copy link
Collaborator

Cherry pick to beta success

@sgrampone sgrampone requested review from iroqueta and removed request for ggallotti October 13, 2025 16:59
<groupId>com.google.api.grpc</groupId>
<artifactId>proto-google-iam-v1</artifactId>
</exclusion>
<exclusion>
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is it okay to remove this exclusion?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, I did it in a second commit because it failed the test execution. It was looking for a protbuf class in runtime.

Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

But for some reason that dependency had been excluded... I don't think it's good to add it just like that without being clear about why you need it now and before your change you didn't.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The original library (v1.118.1) was made on August 2021, we are updating it to the latest from october 2025.
When we added it it didn't use anything from protobuf for the functions we use in GX, therefore someone exclude it, samewere in 4 years they made changes there and now they use a class from protobuf to a function we need on GX since it failed on the tests. What? Why? I don't know, it's a transitive reference, tests failed with the message that it couldn't find some protbuf class executing on github. We could try to exclude it again but the test will fail again.

Copy link
Collaborator

@iroqueta iroqueta left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Leave a question

@sgrampone
Copy link
Contributor Author

You question has an answer

@sgrampone sgrampone merged commit 5d5ec8a into master Oct 15, 2025
10 checks passed
@sgrampone sgrampone deleted the fix/bump-google-cloud-storage branch October 15, 2025 20:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bot closed dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants