beam icon indicating copy to clipboard operation
beam copied to clipboard

beam-vendor-grpc-1_43_2 shades vulnerable Netty version

Open damccorm opened this issue 3 years ago • 0 comments

The beam-vendor-grpc-1_43_2 dependency (that is pulled transitively by the beam-runners-flink-1.13) shades a vulnerable Netty version, i.e. 4.1.63.Final: https://mvnrepository.com/artifact/io.netty/netty-all/4.1.63.Final

In turn, our Beam pipelines builds are marked as vulnerable and we're having issues promoting them to higher environments. 

Because Netty is shaded, we can't simply override the version in the build tool.

Imported from Jira BEAM-14118. Original Jira may contain additional context. Reported by: jigga.

damccorm avatar Jun 05 '22 01:06 damccorm