build(crypto,rpc,http,event): bump bundled libs for security fixes#6747
build(crypto,rpc,http,event): bump bundled libs for security fixes#6747lvs0075 merged 1 commit intotronprotocol:developfrom
Conversation
1. bump bcprov-jdk18on from 1.79 to 1.84 fix CVE-2026-5598 2. bump jetty from 9.4.57 to 9.4.58 fix CVE-2025-5115 3. bump pf4j from 3.10.0 to 3.14.1 fix CVE-2025-70952 4. bump grpc-java from 1.75 to 1.81 fix CVE-2026-33871
|
Thanks for the upgrade. One concern worth flagging:
Future Jetty CVEs will keep landing in the same state. Worth opening a separate discussion to evaluate a longer-term replacement path. No objection to merging this PR — it still closes CVE-2025-5115. |
|
@0xbigapple Regarding the JDK upgrade, the current state is that |
Upgrade bundled libraries in crypto, RPC, HTTP, and event/plugin-related components to newer patched versions to address known security vulnerabilities.
Changes:
Impact: