From a0b867d40a083fb66c825a9b034cbea8d4a628fb Mon Sep 17 00:00:00 2001 From: Gabriel Fukushima Date: Mon, 21 Aug 2023 10:35:01 +1000 Subject: [PATCH 1/3] update grpc library Signed-off-by: Gabriel Fukushima --- gradle/versions.gradle | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/gradle/versions.gradle b/gradle/versions.gradle index 10af5c48..009d518d 100644 --- a/gradle/versions.gradle +++ b/gradle/versions.gradle @@ -106,7 +106,7 @@ dependencyManagement { entry 'protobuf-java' entry 'protobuf-java-util' } - dependencySet(group: 'io.grpc', version: '1.56.0') { + dependencySet(group: 'io.grpc', version: '1.57.2') { entry 'grpc-api' entry 'grpc-context' entry 'grpc-core' From 44b9a0d6cabf1603c908786fee92a659c89465d7 Mon Sep 17 00:00:00 2001 From: Gabriel Fukushima Date: Mon, 21 Aug 2023 10:40:12 +1000 Subject: [PATCH 2/3] add changelog Signed-off-by: Gabriel Fukushima --- CHANGELOG.md | 3 +++ 1 file changed, 3 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 22e8c4c1..f48c377a 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,6 +5,9 @@ ## Features Added - Updated Docker image to use the latest Ubuntu LTS image +### Bugs Fixed +- Update grpc to version 1.57.2 to fix CVE-2023-33953[#524](https://github.com/Consensys/ethsigner/pull/524) + ## 23.6.0 As part of our ongoing commitment to deliver the best remote signing solutions, we are announcing a change in our product offerings. From 21ad588e252fc4b7b070b0388364235a2bd44b47 Mon Sep 17 00:00:00 2001 From: Gabriel Fukushima Date: Mon, 21 Aug 2023 10:41:07 +1000 Subject: [PATCH 3/3] add changelog Signed-off-by: Gabriel Fukushima --- CHANGELOG.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index f48c377a..063823fa 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,7 +6,7 @@ - Updated Docker image to use the latest Ubuntu LTS image ### Bugs Fixed -- Update grpc to version 1.57.2 to fix CVE-2023-33953[#524](https://github.com/Consensys/ethsigner/pull/524) +- Update grpc to version 1.57.2 to fix CVE-2023-33953 ## 23.6.0