Skip to content

Commit 345c3d9

Browse files
authored
Upgrade to Netty 4.2.15 to address CVEs (apache#4813)
1 parent 0af6e60 commit 345c3d9

7 files changed

Lines changed: 194 additions & 194 deletions

File tree

bookkeeper-dist/src/main/resources/LICENSE-all.bin.txt

Lines changed: 49 additions & 49 deletions
Original file line numberDiff line numberDiff line change
@@ -217,33 +217,33 @@ Apache Software License, Version 2.
217217
- lib/commons-io-commons-io-2.19.0.jar [8]
218218
- lib/commons-logging-commons-logging-1.3.5.jar [10]
219219
- lib/io.github.merlimat.slog-slog-0.9.9.jar [64]
220-
- lib/io.netty-netty-buffer-4.2.14.Final.jar [11]
221-
- lib/io.netty-netty-codec-base-4.2.14.Final.jar [11]
222-
- lib/io.netty-netty-codec-compression-4.2.14.Final.jar [11]
223-
- lib/io.netty-netty-codec-dns-4.2.14.Final.jar [11]
224-
- lib/io.netty-netty-codec-http-4.2.14.Final.jar [11]
225-
- lib/io.netty-netty-codec-http2-4.2.14.Final.jar [11]
226-
- lib/io.netty-netty-codec-socks-4.2.14.Final.jar [11]
227-
- lib/io.netty-netty-common-4.2.14.Final.jar [11]
228-
- lib/io.netty-netty-handler-4.2.14.Final.jar [11]
229-
- lib/io.netty-netty-handler-proxy-4.2.14.Final.jar [11]
230-
- lib/io.netty-netty-resolver-4.2.14.Final.jar [11]
231-
- lib/io.netty-netty-resolver-dns-4.2.14.Final.jar [11]
220+
- lib/io.netty-netty-buffer-4.2.15.Final.jar [11]
221+
- lib/io.netty-netty-codec-base-4.2.15.Final.jar [11]
222+
- lib/io.netty-netty-codec-compression-4.2.15.Final.jar [11]
223+
- lib/io.netty-netty-codec-dns-4.2.15.Final.jar [11]
224+
- lib/io.netty-netty-codec-http-4.2.15.Final.jar [11]
225+
- lib/io.netty-netty-codec-http2-4.2.15.Final.jar [11]
226+
- lib/io.netty-netty-codec-socks-4.2.15.Final.jar [11]
227+
- lib/io.netty-netty-common-4.2.15.Final.jar [11]
228+
- lib/io.netty-netty-handler-4.2.15.Final.jar [11]
229+
- lib/io.netty-netty-handler-proxy-4.2.15.Final.jar [11]
230+
- lib/io.netty-netty-resolver-4.2.15.Final.jar [11]
231+
- lib/io.netty-netty-resolver-dns-4.2.15.Final.jar [11]
232232
- lib/io.netty-netty-tcnative-boringssl-static-2.0.77.Final.jar [11]
233233
- lib/io.netty-netty-tcnative-boringssl-static-2.0.77.Final-linux-aarch_64.jar [11]
234234
- lib/io.netty-netty-tcnative-boringssl-static-2.0.77.Final-linux-x86_64.jar [11]
235235
- lib/io.netty-netty-tcnative-boringssl-static-2.0.77.Final-osx-aarch_64.jar [11]
236236
- lib/io.netty-netty-tcnative-boringssl-static-2.0.77.Final-osx-x86_64.jar [11]
237237
- lib/io.netty-netty-tcnative-boringssl-static-2.0.77.Final-windows-x86_64.jar [11]
238238
- lib/io.netty-netty-tcnative-classes-2.0.77.Final.jar [11]
239-
- lib/io.netty-netty-transport-4.2.14.Final.jar [11]
240-
- lib/io.netty-netty-transport-classes-epoll-4.2.14.Final.jar [11]
241-
- lib/io.netty-netty-transport-classes-io_uring-4.2.14.Final.jar [11]
242-
- lib/io.netty-netty-transport-native-epoll-4.2.14.Final-linux-aarch_64.jar [11]
243-
- lib/io.netty-netty-transport-native-epoll-4.2.14.Final-linux-x86_64.jar [11]
244-
- lib/io.netty-netty-transport-native-io_uring-4.2.14.Final-linux-aarch_64.jar [11]
245-
- lib/io.netty-netty-transport-native-io_uring-4.2.14.Final-linux-x86_64.jar [11]
246-
- lib/io.netty-netty-transport-native-unix-common-4.2.14.Final.jar [11]
239+
- lib/io.netty-netty-transport-4.2.15.Final.jar [11]
240+
- lib/io.netty-netty-transport-classes-epoll-4.2.15.Final.jar [11]
241+
- lib/io.netty-netty-transport-classes-io_uring-4.2.15.Final.jar [11]
242+
- lib/io.netty-netty-transport-native-epoll-4.2.15.Final-linux-aarch_64.jar [11]
243+
- lib/io.netty-netty-transport-native-epoll-4.2.15.Final-linux-x86_64.jar [11]
244+
- lib/io.netty-netty-transport-native-io_uring-4.2.15.Final-linux-aarch_64.jar [11]
245+
- lib/io.netty-netty-transport-native-io_uring-4.2.15.Final-linux-x86_64.jar [11]
246+
- lib/io.netty-netty-transport-native-unix-common-4.2.15.Final.jar [11]
247247
- lib/io.prometheus-simpleclient-0.15.0.jar [12]
248248
- lib/io.prometheus-simpleclient_common-0.15.0.jar [12]
249249
- lib/io.prometheus-simpleclient_hotspot-0.15.0.jar [12]
@@ -353,7 +353,7 @@ Apache Software License, Version 2.
353353
[8] Source available at https://github.com/apache/commons-io/tree/rel/commons-io-2.19.0
354354
[9] Source available at https://github.com/apache/commons-lang/tree/LANG_2_6
355355
[10] Source available at https://github.com/apache/commons-logging/tree/commons-logging-1.3.5
356-
[11] Source available at https://github.com/netty/netty/tree/netty-4.2.14.Final
356+
[11] Source available at https://github.com/netty/netty/tree/netty-4.2.15.Final
357357
[12] Source available at https://github.com/prometheus/client_java/tree/parent-0.15.0
358358
[13] Source available at https://github.com/vert-x3/vertx-auth/tree/4.3.2
359359
[14] Source available at https://github.com/vert-x3/vertx-bridge-common/tree/4.3.2
@@ -397,9 +397,9 @@ Apache Software License, Version 2.
397397
[62] Source available at https://github.com/apache/commons-beanutils/tree/rel/commons-beanutils-1.11.0
398398
[64] Source available at https://github.com/merlimat/slog/tree/v0.9.9
399399
------------------------------------------------------------------------------------
400-
lib/io.netty-netty-codec-base-4.2.14.Final.jar bundles some 3rd party dependencies
400+
lib/io.netty-netty-codec-base-4.2.15.Final.jar bundles some 3rd party dependencies
401401

402-
lib/io.netty-netty-codec-base-4.2.14.Final.jar contains the extensions to Java Collections Framework which has
402+
lib/io.netty-netty-codec-base-4.2.15.Final.jar contains the extensions to Java Collections Framework which has
403403
been derived from the works by JSR-166 EG, Doug Lea, and Jason T. Greene:
404404

405405
* LICENSE:
@@ -408,31 +408,31 @@ been derived from the works by JSR-166 EG, Doug Lea, and Jason T. Greene:
408408
* http://gee.cs.oswego.edu/cgi-bin/viewcvs.cgi/jsr166/
409409
* http://viewvc.jboss.org/cgi-bin/viewvc.cgi/jbosscache/experimental/jsr166/
410410

411-
lib/io.netty-netty-codec-base-4.2.14.Final.jar contains a modified version of Robert Harder's Public Domain
411+
lib/io.netty-netty-codec-base-4.2.15.Final.jar contains a modified version of Robert Harder's Public Domain
412412
Base64 Encoder and Decoder, which can be obtained at:
413413

414414
* LICENSE:
415415
* deps/netty/LICENSE.base64.txt (Public Domain)
416416
* HOMEPAGE:
417417
* http://iharder.sourceforge.net/current/java/base64/
418418

419-
lib/io.netty-netty-codec-base-4.2.14.Final.jar contains a modified portion of 'Webbit', an event based
419+
lib/io.netty-netty-codec-base-4.2.15.Final.jar contains a modified portion of 'Webbit', an event based
420420
WebSocket and HTTP server, which can be obtained at:
421421

422422
* LICENSE:
423423
* deps/netty/LICENSE.webbit.txt (BSD License)
424424
* HOMEPAGE:
425425
* https://github.com/joewalnes/webbit
426426

427-
lib/io.netty-netty-codec-base-4.2.14.Final.jar contains a modified portion of 'SLF4J', a simple logging
427+
lib/io.netty-netty-codec-base-4.2.15.Final.jar contains a modified portion of 'SLF4J', a simple logging
428428
facade for Java, which can be obtained at:
429429

430430
* LICENSE:
431431
* deps/netty/LICENSE.slf4j.txt (MIT License)
432432
* HOMEPAGE:
433433
* http://www.slf4j.org/
434434

435-
lib/io.netty-netty-codec-base-4.2.14.Final.jar contains a modified portion of 'Apache Harmony', an open source
435+
lib/io.netty-netty-codec-base-4.2.15.Final.jar contains a modified portion of 'Apache Harmony', an open source
436436
Java SE, which can be obtained at:
437437

438438
* NOTICE:
@@ -442,15 +442,15 @@ Java SE, which can be obtained at:
442442
* HOMEPAGE:
443443
* http://archive.apache.org/dist/harmony/
444444

445-
lib/io.netty-netty-codec-base-4.2.14.Final.jar contains a modified portion of 'jbzip2', a Java bzip2 compression
445+
lib/io.netty-netty-codec-base-4.2.15.Final.jar contains a modified portion of 'jbzip2', a Java bzip2 compression
446446
and decompression library written by Matthew J. Francis. It can be obtained at:
447447

448448
* LICENSE:
449449
* deps/netty/LICENSE.jbzip2.txt (MIT License)
450450
* HOMEPAGE:
451451
* https://code.google.com/p/jbzip2/
452452

453-
lib/io.netty-netty-codec-base-4.2.14.Final.jar contains a modified portion of 'libdivsufsort', a C API library to construct
453+
lib/io.netty-netty-codec-base-4.2.15.Final.jar contains a modified portion of 'libdivsufsort', a C API library to construct
454454
the suffix array and the Burrows-Wheeler transformed string for any input string of
455455
a constant-size alphabet written by Yuta Mori. It can be obtained at:
456456

@@ -459,63 +459,63 @@ a constant-size alphabet written by Yuta Mori. It can be obtained at:
459459
* HOMEPAGE:
460460
* https://github.com/y-256/libdivsufsort
461461

462-
lib/io.netty-netty-codec-base-4.2.14.Final.jar contains a modified portion of Nitsan Wakart's 'JCTools',
462+
lib/io.netty-netty-codec-base-4.2.15.Final.jar contains a modified portion of Nitsan Wakart's 'JCTools',
463463
Java Concurrency Tools for the JVM, which can be obtained at:
464464

465465
* LICENSE:
466466
* deps/netty/LICENSE.jctools.txt (ASL2 License)
467467
* HOMEPAGE:
468468
* https://github.com/JCTools/JCTools
469469

470-
lib/io.netty-netty-codec-base-4.2.14.Final.jar optionally depends on 'JZlib', a re-implementation of zlib in
470+
lib/io.netty-netty-codec-base-4.2.15.Final.jar optionally depends on 'JZlib', a re-implementation of zlib in
471471
pure Java, which can be obtained at:
472472

473473
* LICENSE:
474474
* deps/netty/LICENSE.jzlib.txt (BSD style License)
475475
* HOMEPAGE:
476476
* http://www.jcraft.com/jzlib/
477477

478-
lib/io.netty-netty-codec-base-4.2.14.Final.jar optionally depends on 'Compress-LZF', a Java library for encoding and
478+
lib/io.netty-netty-codec-base-4.2.15.Final.jar optionally depends on 'Compress-LZF', a Java library for encoding and
479479
decoding data in LZF format, written by Tatu Saloranta. It can be obtained at:
480480

481481
* LICENSE:
482482
* deps/netty/LICENSE.compress-lzf.txt (Apache License 2.0)
483483
* HOMEPAGE:
484484
* https://github.com/ning/compress
485485

486-
lib/io.netty-netty-codec-base-4.2.14.Final.jar optionally depends on 'lz4-java', a LZ4 Java compression
486+
lib/io.netty-netty-codec-base-4.2.15.Final.jar optionally depends on 'lz4-java', a LZ4 Java compression
487487
and decompression library written by Adrien Grand. It can be obtained at:
488488

489489
* LICENSE:
490490
* deps/netty/LICENSE.lz4.txt (Apache License 2.0)
491491
* HOMEPAGE:
492492
* https://github.com/yawkat/lz4-java
493493

494-
lib/io.netty-netty-codec-base-4.2.14.Final.jar optionally depends on 'lzma-java', a LZMA Java compression
494+
lib/io.netty-netty-codec-base-4.2.15.Final.jar optionally depends on 'lzma-java', a LZMA Java compression
495495
and decompression library, which can be obtained at:
496496

497497
* LICENSE:
498498
* deps/netty/LICENSE.lzma-java.txt (Apache License 2.0)
499499
* HOMEPAGE:
500500
* https://github.com/jponge/lzma-java
501501

502-
lib/io.netty-netty-codec-base-4.2.14.Final.jar contains a modified portion of 'jfastlz', a Java port of FastLZ compression
502+
lib/io.netty-netty-codec-base-4.2.15.Final.jar contains a modified portion of 'jfastlz', a Java port of FastLZ compression
503503
and decompression library written by William Kinney. It can be obtained at:
504504

505505
* LICENSE:
506506
* deps/netty/LICENSE.jfastlz.txt (MIT License)
507507
* HOMEPAGE:
508508
* https://code.google.com/p/jfastlz/
509509

510-
lib/io.netty-netty-codec-base-4.2.14.Final.jar contains a modified portion of and optionally depends on 'Protocol Buffers',
510+
lib/io.netty-netty-codec-base-4.2.15.Final.jar contains a modified portion of and optionally depends on 'Protocol Buffers',
511511
Google's data interchange format, which can be obtained at:
512512

513513
* LICENSE:
514514
* deps/netty/LICENSE.protobuf.txt (New BSD License)
515515
* HOMEPAGE:
516516
* https://github.com/google/protobuf
517517

518-
lib/io.netty-netty-codec-base-4.2.14.Final.jar optionally depends on 'Bouncy Castle Crypto APIs' to generate
518+
lib/io.netty-netty-codec-base-4.2.15.Final.jar optionally depends on 'Bouncy Castle Crypto APIs' to generate
519519
a temporary self-signed X.509 certificate when the JVM does not provide the
520520
equivalent functionality. It can be obtained at:
521521

@@ -524,79 +524,79 @@ equivalent functionality. It can be obtained at:
524524
* HOMEPAGE:
525525
* http://www.bouncycastle.org/
526526

527-
lib/io.netty-netty-codec-base-4.2.14.Final.jar optionally depends on 'Snappy', a compression library produced
527+
lib/io.netty-netty-codec-base-4.2.15.Final.jar optionally depends on 'Snappy', a compression library produced
528528
by Google Inc, which can be obtained at:
529529

530530
* LICENSE:
531531
* deps/netty/LICENSE.snappy.txt (New BSD License)
532532
* HOMEPAGE:
533533
* https://github.com/google/snappy
534534

535-
lib/io.netty-netty-codec-base-4.2.14.Final.jar optionally depends on 'JBoss Marshalling', an alternative Java
535+
lib/io.netty-netty-codec-base-4.2.15.Final.jar optionally depends on 'JBoss Marshalling', an alternative Java
536536
serialization API, which can be obtained at:
537537

538538
* LICENSE:
539539
* deps/netty/LICENSE.jboss-marshalling.txt (Apache License 2.0)
540540
* HOMEPAGE:
541541
* https://github.com/jboss-remoting/jboss-marshalling
542542

543-
lib/io.netty-netty-codec-base-4.2.14.Final.jar optionally depends on 'Caliper', Google's micro-
543+
lib/io.netty-netty-codec-base-4.2.15.Final.jar optionally depends on 'Caliper', Google's micro-
544544
benchmarking framework, which can be obtained at:
545545

546546
* LICENSE:
547547
* deps/netty/LICENSE.caliper.txt (Apache License 2.0)
548548
* HOMEPAGE:
549549
* https://github.com/google/caliper
550550

551-
lib/io.netty-netty-codec-base-4.2.14.Final.jar optionally depends on 'Apache Commons Logging', a logging
551+
lib/io.netty-netty-codec-base-4.2.15.Final.jar optionally depends on 'Apache Commons Logging', a logging
552552
framework, which can be obtained at:
553553

554554
* LICENSE:
555555
* deps/netty/LICENSE.commons-logging.txt (Apache License 2.0)
556556
* HOMEPAGE:
557557
* http://commons.apache.org/logging/
558558

559-
lib/io.netty-netty-codec-base-4.2.14.Final.jar optionally depends on 'Apache Log4J', a logging framework, which
559+
lib/io.netty-netty-codec-base-4.2.15.Final.jar optionally depends on 'Apache Log4J', a logging framework, which
560560
can be obtained at:
561561

562562
* LICENSE:
563563
* deps/netty/LICENSE.log4j.txt (Apache License 2.0)
564564
* HOMEPAGE:
565565
* http://logging.apache.org/log4j/
566566

567-
lib/io.netty-netty-codec-base-4.2.14.Final.jar optionally depends on 'Aalto XML', an ultra-high performance
567+
lib/io.netty-netty-codec-base-4.2.15.Final.jar optionally depends on 'Aalto XML', an ultra-high performance
568568
non-blocking XML processor, which can be obtained at:
569569

570570
* LICENSE:
571571
* deps/netty/LICENSE.aalto-xml.txt (Apache License 2.0)
572572
* HOMEPAGE:
573573
* http://wiki.fasterxml.com/AaltoHome
574574

575-
lib/io.netty-netty-codec-base-4.2.14.Final.jar contains a modified version of 'HPACK', a Java implementation of
575+
lib/io.netty-netty-codec-base-4.2.15.Final.jar contains a modified version of 'HPACK', a Java implementation of
576576
the HTTP/2 HPACK algorithm written by Twitter. It can be obtained at:
577577

578578
* LICENSE:
579579
* deps/netty/LICENSE.hpack.txt (Apache License 2.0)
580580
* HOMEPAGE:
581581
* https://github.com/twitter/hpack
582582

583-
lib/io.netty-netty-codec-base-4.2.14.Final.jar contains a modified version of 'HPACK', a Java implementation of
583+
lib/io.netty-netty-codec-base-4.2.15.Final.jar contains a modified version of 'HPACK', a Java implementation of
584584
the HTTP/2 HPACK algorithm written by Cory Benfield. It can be obtained at:
585585

586586
* LICENSE:
587587
* deps/netty/LICENSE.hyper-hpack.txt (MIT License)
588588
* HOMEPAGE:
589589
* https://github.com/python-hyper/hpack/
590590

591-
lib/io.netty-netty-codec-base-4.2.14.Final.jar contains a modified version of 'HPACK', a Java implementation of
591+
lib/io.netty-netty-codec-base-4.2.15.Final.jar contains a modified version of 'HPACK', a Java implementation of
592592
the HTTP/2 HPACK algorithm written by Tatsuhiro Tsujikawa. It can be obtained at:
593593

594594
* LICENSE:
595595
* deps/netty/LICENSE.nghttp2-hpack.txt (MIT License)
596596
* HOMEPAGE:
597597
* https://github.com/nghttp2/nghttp2/
598598

599-
lib/io.netty-netty-codec-base-4.2.14.Final.jar contains a modified portion of 'Apache Commons Lang', a Java library
599+
lib/io.netty-netty-codec-base-4.2.15.Final.jar contains a modified portion of 'Apache Commons Lang', a Java library
600600
provides utilities for the java.lang API, which can be obtained at:
601601

602602
* LICENSE:
@@ -605,15 +605,15 @@ provides utilities for the java.lang API, which can be obtained at:
605605
* https://commons.apache.org/proper/commons-lang/
606606

607607

608-
lib/io.netty-netty-codec-base-4.2.14.Final.jar contains the Maven wrapper scripts from 'Maven Wrapper',
608+
lib/io.netty-netty-codec-base-4.2.15.Final.jar contains the Maven wrapper scripts from 'Maven Wrapper',
609609
that provides an easy way to ensure a user has everything necessary to run the Maven build.
610610

611611
* LICENSE:
612612
* deps/netty/LICENSE.mvn-wrapper.txt (Apache License 2.0)
613613
* HOMEPAGE:
614614
* https://github.com/takari/maven-wrapper
615615

616-
lib/io.netty-netty-codec-base-4.2.14.Final.jar contains the dnsinfo.h header file,
616+
lib/io.netty-netty-codec-base-4.2.15.Final.jar contains the dnsinfo.h header file,
617617
that provides a way to retrieve the system DNS configuration on MacOS.
618618
This private header is also used by Apple's open source
619619
mDNSResponder (https://opensource.apple.com/tarballs/mDNSResponder/).

0 commit comments

Comments
 (0)