Skip to content

1.0.1

Latest

Choose a tag to compare

@bpalermo bpalermo released this 14 Jul 21:42
· 2 commits to master since this release
1.0.1
5aed25a

1.0.1 (2026-07-14)

Dependency-security patch release — CVE-clearing pins over Finagle 24.2.0's frozen transitive set. No API or behavior changes.

  • netty 4.1.135.Final (clears 56 alerts).
  • jackson core/databind/annotations/module-scala_2.13 aligned at 2.18.9 (GHSA-5jmj-h7xm-6q6v). All four move together because jackson-module-scala enforces a matching jackson-databind version at runtime.
  • scala-library 2.13.16.
  • snakeyaml 2.4 (CVE-2022-1471 RCE).
  • aws-java-sdk-s3/core 1.12.797 (drops vulnerable transitive ion-java).
  • plexus-utils 3.6.1, guava 32.0.1-jre, httpclient 4.5.14, gson 2.10.1.
  • libthrift remains 0.12.0 (scrooge 24.2.0 codegen constraint; vulnerable TLS transport unused).

Artifacts published to Nubank CodeArtifact (private-maven): finagle-clojure/{core,http,thrift} and lein-finagle-clojure, all 1.0.1.