Skip to content

[Backport 2.12] Bump armeria + grpc + protobuf to fix CVE-2024-7254#5924

Merged
dlvenable merged 1 commit into2.12from
backport/backport-5891-to-2.12
Jul 30, 2025
Merged

[Backport 2.12] Bump armeria + grpc + protobuf to fix CVE-2024-7254#5924
dlvenable merged 1 commit into2.12from
backport/backport-5891-to-2.12

Conversation

@opensearch-trigger-bot
Copy link
Copy Markdown
Contributor

Backport 292a547 from #5891

Bump armeria + grpc + protobuf to fix CVE-2024-7254

Upgrades protobuf dependencies with versions that fix
Fixes CVE-2024-7254.

Use inline mocks in DnsPeerListProviderCreationTest to support mocking final classes. Updates to the GrpcRequestExceptionHandlerTest required by the update to the Armeria test library. Enforce a consistent JUnit version across the project to avoid JUnit consistency issues.

Signed-off-by: Karsten Schnitter <k.schnitter@sap.com>
Signed-off-by: David Venable <dlv@amazon.com>
Co-authored-by: David Venable <dlv@amazon.com>
(cherry picked from commit 292a547)
@github-actions
Copy link
Copy Markdown

github-actions bot commented Jul 30, 2025

Unit Test Results

  3 385 files  +   580    3 385 suites  +580   1h 28m 45s ⏱️ + 15m 51s
11 694 tests +   354  11 687 ✔️ +   354    6 💤 ±0  1 ±0 
29 348 runs  +4 344  29 334 ✔️ +4 344  13 💤 ±0  1 ±0 

For more details on these failures, see this check.

Results for commit 5d02890. ± Comparison against base commit ff4d849.

♻️ This comment has been updated with latest results.

@dlvenable dlvenable merged commit 140ae03 into 2.12 Jul 30, 2025
84 of 94 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants