Skip to content

chore(deps): bump io.netty:netty-codec-http from 4.2.5.Final to 4.2.13.Final#70

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/io.netty-netty-codec-http-4.2.13.Final
Closed

chore(deps): bump io.netty:netty-codec-http from 4.2.5.Final to 4.2.13.Final#70
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/io.netty-netty-codec-http-4.2.13.Final

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 25, 2026

Copy link
Copy Markdown
Contributor

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Bumps io.netty:netty-codec-http from 4.2.5.Final to 4.2.13.Final.

Release notes

Sourced from io.netty:netty-codec-http's releases.

netty-4.2.13.Final

CVEs Fixed

Breaking Changes

The patch for CVE-2026-42581 prohibits HTTP/1.1 requests containing both the Transfer-Encoding and Content-Length headers, in line with RFC 9112. Previous versions of HTTP/1.1 (RFC 7230) permitted this combination. You can restore the old behavior with the -Dio.netty.handler.codec.http.rfc9112TransferEncoding=false system property or with HttpDecoderConfig. Note that disabling this check may lead to request smuggling vulnerabilities.

What's Changed

... (truncated)

Commits
  • b3844c8 [maven-release-plugin] prepare release netty-4.2.13.Final
  • 82f47fa Merge commit from fork
  • ada0999 Merge commit from fork
  • b4051e2 Fix BrotliDecoder not forwarding all decompressed chunks
  • 67207c1 Merge commit from fork
  • 541ca7c Merge commit from fork
  • 943edb3 Fix codec-dns tests
  • 6459a28 Merge commit from fork
  • b4ba61b Fix checkstyle in HttpObjectDecoder
  • 977661f Merge commit from fork
  • Additional commits viewable in compare view

@dependabot @github

dependabot Bot commented on behalf of github May 25, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot force-pushed the dependabot/maven/io.netty-netty-codec-http-4.2.13.Final branch from 6001454 to 4b89d1f Compare May 26, 2026 01:16
Bumps [io.netty:netty-codec-http](https://github.com/netty/netty) from 4.2.5.Final to 4.2.13.Final.
- [Release notes](https://github.com/netty/netty/releases)
- [Commits](netty/netty@netty-4.2.5.Final...netty-4.2.13.Final)

---
updated-dependencies:
- dependency-name: io.netty:netty-codec-http
  dependency-version: 4.2.13.Final
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/maven/io.netty-netty-codec-http-4.2.13.Final branch from 4b89d1f to da3e5e4 Compare June 12, 2026 12:13
@nficano

nficano commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

Superseded: the maven-dependencies group bump (#73) pinned all netty artifacts at 4.2.15.Final on main, which covers this update.

@nficano nficano closed this Jun 12, 2026
@dependabot @github

dependabot Bot commented on behalf of github Jun 12, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot Bot deleted the dependabot/maven/io.netty-netty-codec-http-4.2.13.Final branch June 12, 2026 12:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant