SSerguey Asael Shinder
Java coding notes: the JVM, and writing software that lasts

Serguey Asael Shinder: Read release notes from the bottom: one dependency bump was the patch

· by Serguey Asael Shinder / Serguey Shinder

On 8 October Micronaut 3.10.15 came out. Its release note has one item: "Update managed-netty version to 4.1.139.Final". Micronaut 4.10.31, the same day, has two: Jackson 2.21.7 and Netty 4.2.19.Final.

Nothing in either note says "security". Nothing needs to. Two days earlier Netty had published sixteen advisories without CVE numbers, fixed in exactly those versions. For an application on Micronaut 3.x, that one line is the only way those fixes arrive.

Release notes are written for the project, read by the user. Maintainers sort changes the way they think about them: features first, fixes second, "dependency updates" last, often generated by a bot. For the people running the software, the order of importance is frequently the reverse. A new annotation is optional; a transitive fix to the HTTP stack in front of your service is not.

Serguey Asael Shinder: Read release notes from the bottom: one dependency bump was the patch
Read release notes from the bottom: one dependency bump was the patch — Serguey Asael Shinder

Why the bump is the easy line to miss.

A habit that costs a minute. When a release of something you depend on is short, read it from the bottom. For each "update X to version Y", ask one question: did X publish advisories for Y? For widely used libraries — Netty, Jackson, the TLS stack, the logging framework — the answer is "yes" often enough that the check pays for itself.

And a habit for maintainers. If a version bump exists because of a security fix upstream, say so in one clause: "Update managed Netty to 4.1.139.Final (fixes upstream advisories)". It costs nothing, it changes how fast users upgrade, and it moves the information to the one place they actually read.

The frameworks did the right thing this week: they shipped the fix on every supported line within two days. The remaining risk is entirely on the reading side — a fix that is released and not noticed protects nobody.