-
Notifications
You must be signed in to change notification settings - Fork 412
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[7.67.x-blue] update protobuf libraries version to 3.25.6 #2553
Conversation
Jenkins run fdb |
jenkins run cdb |
jenkins run fdb |
jenkins run cdb |
API changes?
|
I had checked to see all the possibilities to upgrade to 4.x and didn't see any migration guide or any possibilities to do the same. Hence, will go with @yesamer suggestion to version 3.25.6 |
…eed significant api changes
jenkins run fdb |
jenkins run cdb |
jenkins run cdb |
From mailing-list, Seems protobuf 3.25.6 might have a breaking change. https://lists.apache.org/thread/87osjw051xnx5l5v50dt3t81yfjxygwr and GH PR |
Thank you @akumar074, if that issue affects 3.25.6 only, we can consider using 3.25.5, the CVE should be solved in that version too |
jenkins run cdb |
jenkins run fdb |
jenkins run cdb |
1 similar comment
jenkins run cdb |
We have the same CDB failure in another PR, so this is not related #2552. |
Merging. |
The current protobuf-java '3.19.6' version is is affected by https://access.redhat.com/security/cve/cve-2024-7254
Updating to '4.28.2' resolves the CVE, as all the other lower versions including 4.28.1 has this vulnerability.