From 27fa54bdb5a719acf696bfd2821c9b9ed1cbfce3 Mon Sep 17 00:00:00 2001 From: Simon Dudley Date: Fri, 27 Oct 2023 13:25:08 +1000 Subject: [PATCH 1/5] Upgrade netty and grpc Signed-off-by: Simon Dudley --- gradle/verification-metadata.xml | 913 ++++++++++++++----------------- gradle/versions.gradle | 12 +- 2 files changed, 410 insertions(+), 515 deletions(-) diff --git a/gradle/verification-metadata.xml b/gradle/verification-metadata.xml index 39a5dccc217..aa70abab0a7 100644 --- a/gradle/verification-metadata.xml +++ b/gradle/verification-metadata.xml @@ -3,10 +3,6 @@ true false - - - - @@ -99,26 +95,6 @@ - - - - - - - - - - - - - - - - - - - - @@ -134,11 +110,6 @@ - - - - - @@ -587,12 +558,12 @@ - - - + + + - - + + @@ -661,6 +632,14 @@ + + + + + + + + @@ -669,6 +648,11 @@ + + + + + @@ -701,9 +685,6 @@ - - - @@ -777,14 +758,6 @@ - - - - - - - - @@ -793,6 +766,14 @@ + + + + + + + + @@ -822,16 +803,16 @@ - - - - - + + + + + @@ -981,6 +962,14 @@ + + + + + + + + @@ -1004,16 +993,16 @@ - - - - - + + + + + @@ -1027,14 +1016,6 @@ - - - - - - - - @@ -1043,12 +1024,20 @@ - - - + + + - - + + + + + + + + + + @@ -1061,22 +1050,22 @@ - - - - - - - - + + + - - + + + + + + + @@ -1456,156 +1445,180 @@ - - - + + + - - + + - - - + + + - - + + - - - + + + - - + + - - - + + + - - + + - - - + + + - - + + - - - + + + - - + + - - - + + + - - + + - - - + + + - - + + - - - + + + - - + + - - - + + + - - + + - - - + + + - - + + - - - + + + - - + + - - - + + + - - + + - - - + + + - - + + - - - + + + - - + + - - - + + + - - + + - - - + + + - - + + - - - + + + - - + + - - - + + + - - + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -1645,12 +1658,12 @@ - - - + + + - - + + @@ -1663,17 +1676,25 @@ + + + + + + + + - - - + + + - - + + @@ -1684,12 +1705,12 @@ - - - + + + - - + + @@ -1700,20 +1721,20 @@ - - - + + + - - + + - - - + + + - - + + @@ -1724,17 +1745,12 @@ - - - + + + - - - - - - - + + @@ -1745,44 +1761,49 @@ - - - + + + - - + + + + + + + - - - + + + - - + + - - - + + + - - + + - - - + + + - - + + - - - + + + - - + + @@ -1793,28 +1814,28 @@ - - - + + + - - + + - - - + + + - - + + - - - + + + - - + + @@ -1822,12 +1843,12 @@ - - - + + + - - + + @@ -1838,17 +1859,12 @@ - - - - - - + + + - - - - + + @@ -1859,25 +1875,22 @@ - - - - - - + + + - - - + + + - - + + - - - + + + @@ -1885,9 +1898,17 @@ - - - + + + + + + + + + + + @@ -1895,12 +1916,12 @@ - - - + + + - - + + @@ -1911,52 +1932,52 @@ - - - + + + - - + + - - - + + + - - + + - - - - + + - - + + + + - - + + - - - + + + - - + + - - - - - - + + + - - - + + + + + + @@ -1964,88 +1985,80 @@ - - - + + + - - + + - - - + + + - - + + - - - + + + - - + + - - - - + + - - - - - - - - + + - - - + + + - - + + - - + + - - + + - - - + + + - - + + - - - + + + - - + + - - - + + + - - + + - - - + + + - - + + @@ -2342,15 +2355,15 @@ - - - + + + - - + + - - + + @@ -3473,14 +3486,6 @@ - - - - - - - - @@ -3505,14 +3510,6 @@ - - - - - - - - @@ -3521,14 +3518,6 @@ - - - - - - - - @@ -3609,22 +3598,22 @@ - - - + + + - - + + - - - + + + - - - + + + @@ -3953,11 +3942,6 @@ - - - - - @@ -4051,11 +4035,6 @@ - - - - - @@ -4180,17 +4159,6 @@ - - - - - - - - - - - @@ -4202,17 +4170,6 @@ - - - - - - - - - - - @@ -4224,17 +4181,6 @@ - - - - - - - - - - - @@ -4246,17 +4192,6 @@ - - - - - - - - - - - @@ -4268,17 +4203,6 @@ - - - - - - - - - - - @@ -4290,17 +4214,6 @@ - - - - - - - - - - - @@ -4684,9 +4597,6 @@ - - - @@ -4793,9 +4703,6 @@ - - - @@ -4817,9 +4724,6 @@ - - - @@ -4847,9 +4751,6 @@ - - - @@ -4879,9 +4780,6 @@ - - - @@ -4903,9 +4801,6 @@ - - - diff --git a/gradle/versions.gradle b/gradle/versions.gradle index af5d4fc47ce..b5177767d52 100644 --- a/gradle/versions.gradle +++ b/gradle/versions.gradle @@ -67,7 +67,7 @@ dependencyManagement { entry 'picocli-codegen' } - dependencySet(group: 'io.grpc', version: '1.53.0') { + dependencySet(group: 'io.grpc', version: '1.59.0') { entry 'grpc-all' entry 'grpc-core' entry 'grpc-netty' @@ -76,11 +76,11 @@ dependencyManagement { dependency 'io.kubernetes:client-java:18.0.0' - dependency 'io.netty:netty-all:4.1.90.Final' - dependency 'io.netty:netty-tcnative-boringssl-static:2.0.59.Final' - dependency group: 'io.netty', name: 'netty-transport-native-epoll', version:'4.1.90.Final', classifier: 'linux-x86_64' - dependency group: 'io.netty', name: 'netty-transport-native-kqueue', version:'4.1.90.Final', classifier: 'osx-x86_64' - dependency 'io.netty:netty-transport-native-unix-common:4.1.90.Final' + dependency 'io.netty:netty-all:4.1.100.Final' + dependency 'io.netty:netty-tcnative-boringssl-static:2.0.62.Final' + dependency group: 'io.netty', name: 'netty-transport-native-epoll', version:'4.1.100.Final', classifier: 'linux-x86_64' + dependency group: 'io.netty', name: 'netty-transport-native-kqueue', version:'4.1.100.Final', classifier: 'osx-x86_64' + dependency 'io.netty:netty-transport-native-unix-common:4.1.100.Final' dependency 'io.opentelemetry:opentelemetry-api:1.24.0' dependency 'io.opentelemetry:opentelemetry-exporter-otlp:1.24.0' From c5c6ed4b91a3717e36eafdb9324bd57c542f6a7e Mon Sep 17 00:00:00 2001 From: Simon Dudley Date: Fri, 27 Oct 2023 14:45:35 +1000 Subject: [PATCH 2/5] fix verification file Signed-off-by: Simon Dudley --- gradle/verification-metadata.xml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/gradle/verification-metadata.xml b/gradle/verification-metadata.xml index aa70abab0a7..c781716e05f 100644 --- a/gradle/verification-metadata.xml +++ b/gradle/verification-metadata.xml @@ -105,6 +105,11 @@ + + + + + From 9f4b42d889b0c1763ac9e3854f21b50e7e3c55e0 Mon Sep 17 00:00:00 2001 From: Simon Dudley Date: Fri, 27 Oct 2023 14:48:57 +1000 Subject: [PATCH 3/5] changelog Signed-off-by: Simon Dudley --- CHANGELOG.md | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index cbc9246d66c..5a2079ba147 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -22,6 +22,11 @@ ### Bug fixes +- Upgrade netty to address CVE-2023-44487, CVE-2023-34462 [#6100](https://github.com/hyperledger/besu/pull/6100) +- Upgrade grpc to address CVE-2023-32731, CVE-2023-33953, CVE-2023-44487, CVE-2023-4785 [#6100](https://github.com/hyperledger/besu/pull/6100) + +--- + ### Download Links ## 23.10.1 From 8915d5757a39509f098575bbfeb280d44c7049a4 Mon Sep 17 00:00:00 2001 From: Simon Dudley Date: Fri, 27 Oct 2023 14:54:24 +1000 Subject: [PATCH 4/5] fix verification file again Signed-off-by: Simon Dudley --- gradle/verification-metadata.xml | 30 +++++++++++++++++++++++++----- 1 file changed, 25 insertions(+), 5 deletions(-) diff --git a/gradle/verification-metadata.xml b/gradle/verification-metadata.xml index c781716e05f..067752e6136 100644 --- a/gradle/verification-metadata.xml +++ b/gradle/verification-metadata.xml @@ -95,6 +95,26 @@ + + + + + + + + + + + + + + + + + + + + @@ -105,16 +125,16 @@ - - - - - + + + + + From 4ea6f284553f0c5ad97e5af6ae97194a810cd646 Mon Sep 17 00:00:00 2001 From: Simon Dudley Date: Fri, 27 Oct 2023 14:58:02 +1000 Subject: [PATCH 5/5] Fix verification file one more time Signed-off-by: Simon Dudley --- gradle/verification-metadata.xml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/gradle/verification-metadata.xml b/gradle/verification-metadata.xml index 067752e6136..b3af3b6affd 100644 --- a/gradle/verification-metadata.xml +++ b/gradle/verification-metadata.xml @@ -4622,6 +4622,9 @@ + + +