From 485ad701c0e7b2a589a5be86214c4bab91c4f651 Mon Sep 17 00:00:00 2001 From: Mikhail Date: Mon, 30 Sep 2024 18:08:38 +0100 Subject: [PATCH 1/2] Update grpc-core version io.grpc:grpc-core package in version 1.36.0 contains multiple [CVE's](https://mvnrepository.com/artifact/io.grpc/grpc-core/1.36.0). Bump grpc-core version to latest 1.68.0 version to mitigate potential vulnerabilities. --- grpc/flatbuffers-java-grpc/pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/grpc/flatbuffers-java-grpc/pom.xml b/grpc/flatbuffers-java-grpc/pom.xml index f7d41763747..1f88d29a5b6 100644 --- a/grpc/flatbuffers-java-grpc/pom.xml +++ b/grpc/flatbuffers-java-grpc/pom.xml @@ -24,7 +24,7 @@ - 1.36.0 + 1.68.0 From 5e79a1e7ff4b9ca07ae81cd97e178c87813ee406 Mon Sep 17 00:00:00 2001 From: Mikhail Date: Sat, 5 Oct 2024 08:33:52 +0100 Subject: [PATCH 2/2] Update grpc version to 1.67.1 grpc was mistakenly released to maven under version 1.68.0 whenever a real release was done for version 1.67.1 [1]. The mistake was fixed later. [1] https://github.com/grpc/grpc-java/releases --- grpc/flatbuffers-java-grpc/pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/grpc/flatbuffers-java-grpc/pom.xml b/grpc/flatbuffers-java-grpc/pom.xml index 1f88d29a5b6..dee931344d4 100644 --- a/grpc/flatbuffers-java-grpc/pom.xml +++ b/grpc/flatbuffers-java-grpc/pom.xml @@ -24,7 +24,7 @@ - 1.68.0 + 1.67.1