Skip to content

Bump netty and fasterxml-jackson for CVE fixes#2

Merged
macnev2013 merged 1 commit into
masterfrom
fix/cves
May 21, 2026
Merged

Bump netty and fasterxml-jackson for CVE fixes#2
macnev2013 merged 1 commit into
masterfrom
fix/cves

Conversation

@macnev2013
Copy link
Copy Markdown

@macnev2013 macnev2013 commented May 20, 2026

Summary

  • Bump netty.version from 4.2.7.Final to 4.2.13.Final
  • Bump fasterxml-jackson.version from 2.15.0 to 2.18.6

Both upgrades address known CVEs in the transitive dependency chain pulled in via the KCL MultiLangDaemon.

Test plan

  • python setup.py download_jars resolves the new versions
  • python setup.py install succeeds
  • Sample consumer (amazon_kclpy_helper.py --print_command --java $(which java) --properties samples/sample.properties) runs end-to-end against a Kinesis stream
  • CI unit tests pass

🤖 Generated with Claude Code

@macnev2013 macnev2013 temporarily deployed to manual-approval May 20, 2026 09:44 — with GitHub Actions Inactive
@macnev2013 macnev2013 merged commit 9b08f66 into master May 21, 2026
3 of 9 checks passed
@macnev2013 macnev2013 deleted the fix/cves branch May 21, 2026 08:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant