Skip to content

Update hbase version to fix netty CVEs.#38241

Open
shunping wants to merge 2 commits intoapache:masterfrom
shunping:update-hbase-version
Open

Update hbase version to fix netty CVEs.#38241
shunping wants to merge 2 commits intoapache:masterfrom
shunping:update-hbase-version

Conversation

@shunping
Copy link
Copy Markdown
Collaborator

@shunping shunping commented Apr 18, 2026

Fix a long-standing netty related CVE caused by old version of modules:

  • org.apache.hbase.thirdparty:hbase-shaded-netty:4.1.11
  • org.apache.hbase:hbase-client:2.6.3-hadoop3

Internal bug: 470988049

@shunping
Copy link
Copy Markdown
Collaborator Author

r: @Abacn @ahmedabu98

@github-actions
Copy link
Copy Markdown
Contributor

Stopping reviewer notifications for this pull request: review requested by someone other than the bot, ceding control. If you'd like to restart, comment assign set of reviewers

@gemini-code-assist
Copy link
Copy Markdown
Contributor

Warning

Gemini is experiencing higher than usual traffic and was unable to create the summary. Please try again in a few hours by commenting /gemini summary.

@codecov
Copy link
Copy Markdown

codecov bot commented Apr 18, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 58.50%. Comparing base (c166bbe) to head (6d03b38).
⚠️ Report is 6 commits behind head on master.

Additional details and impacted files
@@              Coverage Diff              @@
##             master   #38241       +/-   ##
=============================================
+ Coverage     54.61%   58.50%    +3.89%     
- Complexity     1689    15424    +13735     
=============================================
  Files          1067     2851     +1784     
  Lines        168147   280072   +111925     
  Branches       1226    12333    +11107     
=============================================
+ Hits          91835   163869    +72034     
- Misses        74117   109778    +35661     
- Partials       2195     6425     +4230     
Flag Coverage Δ
java 64.58% <ø> (-2.77%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant