Skip to content

Bump netty and fasterxml-jackson for CVE fixes#2

Open
macnev2013 wants to merge 1 commit into
masterfrom
fix/cves
Open

Bump netty and fasterxml-jackson for CVE fixes#2
macnev2013 wants to merge 1 commit into
masterfrom
fix/cves

Conversation

@macnev2013
Copy link
Copy Markdown

@macnev2013 macnev2013 commented May 20, 2026

Summary

  • Bump netty.version from 4.2.7.Final to 4.2.13.Final
  • Bump fasterxml-jackson.version from 2.15.0 to 2.18.6

Both upgrades address known CVEs in the transitive dependency chain pulled in via the KCL MultiLangDaemon.

Test plan

  • python setup.py download_jars resolves the new versions
  • python setup.py install succeeds
  • Sample consumer (amazon_kclpy_helper.py --print_command --java $(which java) --properties samples/sample.properties) runs end-to-end against a Kinesis stream
  • CI unit tests pass

🤖 Generated with Claude Code

@macnev2013 macnev2013 deployed to manual-approval May 20, 2026 09:44 — with GitHub Actions Active
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant