Skip to content

Conversation

@yiminc
Copy link
Member

@yiminc yiminc commented Jan 18, 2026

Summary

  • Upgrade grpcVersion from 1.58.1 to 1.75.0 to address security vulnerabilities
  • Add explicit grpc-protobuf dependency to temporal-serviceclient (no longer transitively included by grpc-services in 1.75.0)
  • Suppress deprecation warning for Guava Throwables.propagateIfPossible (deprecated in Guava 33.x brought in by grpc 1.75.0)

Security Vulnerabilities Fixed

  • CVE-2025-55163 (HIGH): MadeYouReset HTTP/2 DDoS vulnerability - allows attackers to break max concurrent streams limit, causing resource exhaustion
  • CVE-2025-24970 (HIGH, CVSS 7.5): Improper Input Validation in SSLEngine - malformed packets can cause native crash/DoS

Test plan

  • Build compiles successfully
  • All 1,341 tests pass

🤖 Generated with Claude Code

- Update grpcVersion from 1.58.1 to 1.75.0
- Add grpc-protobuf dependency to temporal-serviceclient (no longer
  transitively included by grpc-services in 1.75.0)
- Suppress deprecation warning for Guava Throwables.propagateIfPossible
  (deprecated in Guava 33.x brought in by grpc 1.75.0)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@yiminc yiminc requested a review from a team as a code owner January 18, 2026 03:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant