SSerguey Asael Shinder
Java coding notes: the JVM, and writing software that lasts

Serguey Asael Shinder: Micronaut 5.2.15, 4.10.31 and 3.10.15 ship this week's Netty fixes

· by Serguey Asael Shinder / Serguey Shinder

Micronaut released patch versions on three lines on 7 and 8 October, and the common thread is Netty. The 4.2.19.Final and 4.1.139.Final releases of 6 October carried sixteen advisories published without CVE numbers (covered here on 7 October). A Micronaut application does not pick those up by itself: Micronaut manages its Netty version, so the fix reaches you when the framework moves.

What each line got.

Serguey Asael Shinder: Micronaut 5.2.15, 4.10.31 and 3.10.15 ship this week's Netty fixes
Micronaut 5.2.15, 4.10.31 and 3.10.15 ship this week's Netty fixes — Serguey Asael Shinder

Why the short releases matter most. For 4.10.x and 3.10.x the release notes are one or two dependency lines. That is easy to skim past as housekeeping; here it is the security update. A team on 3.10 — still on Netty 4.1 — gets the 4.1-line fixes without changing frameworks.

What to do. Upgrade within your line: 5.2.14 → 5.2.15, 4.10.30 → 4.10.31, 3.10.14 → 3.10.15. If your build overrides Micronaut's managed Netty version (a BOM override or an explicit io.netty dependency), the framework upgrade will not move it for you — check the resolved version with ./gradlew dependencies or mvn dependency:tree after upgrading, and look for 4.2.19.Final or 4.1.139.Final.

Release contents are quoted from the three GitHub release pages; the Netty advisories themselves are linked from Netty's release notes.