1.0.1 (2026-07-14)
Dependency-security patch release — CVE-clearing pins over Finagle 24.2.0's frozen transitive set. No API or behavior changes.
- netty
4.1.135.Final(clears 56 alerts). - jackson core/databind/annotations/module-scala_2.13 aligned at
2.18.9(GHSA-5jmj-h7xm-6q6v). All four move together becausejackson-module-scalaenforces a matchingjackson-databindversion at runtime. - scala-library
2.13.16. - snakeyaml
2.4(CVE-2022-1471 RCE). - aws-java-sdk-s3/core
1.12.797(drops vulnerable transitiveion-java). - plexus-utils
3.6.1, guava32.0.1-jre, httpclient4.5.14, gson2.10.1. libthriftremains0.12.0(scrooge 24.2.0 codegen constraint; vulnerable TLS transport unused).
Artifacts published to Nubank CodeArtifact (private-maven): finagle-clojure/{core,http,thrift} and lein-finagle-clojure, all 1.0.1.