[Bug] Upgrade GRPC to 1.79 to remediate CVEs

Open Beginner friendly
#10,099 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
65/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Active
Tech stack
grpc, java
Domain
security

Research direction

The issue names no files or tests. Start by locating the RocketMQ gRPC dependency declaration and its resolved version, then verify the upgrade to gRPC 1.79 addresses CVE-2023-32731, CVE-2023-32732, and CVE-2025-55163 without breaking the build.

Written by the indexing model from the issue text.

Description

Before Creating the Bug Report
  • I found a bug, not just asking a question, which should be created in GitHub Discussions.

  • I have searched the GitHub Issues and GitHub Discussions of this repository and believe that this is not a duplicate.

  • I have confirmed that this bug belongs to the current repository, not other repositories of RocketMQ.

Runtime platform environment

All

RocketMQ version

develop

JDK Version

No response

Describe the Bug

Upgraded GRPC to 1.79 to remediate CVE-2023-32731, CVE-2023-32732 and CVE-2025-55163

Steps to Reproduce

N/A

What Did You Expect to See?

N/A

What Did You See Instead?

N/A

Additional Context

No response

Dominant language
Java
Stars
22.6k
Forks
12k
Avg merge
3d 12h
Merged PRs (30d)
25

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from apache/rocketmq

All issues in apache/rocketmq

Similar issues

More Java issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.