9 hours ago
selenium

Nightly

Commits

  • 9846631: [js][bidi] Add vendor specific class generation (#18125) (Puja Jagani) #18125
  • e431cc8: [build] Automated Browser Version Update (#18107) (Selenium CI Bot) #18107
  • af9e5cf: [java] assert setFiles uploads reach the server in SetFilesCommandTest (#18058) (Yash Pardeshi) #18058
  • ceec8bf: [java][bidi] Decode nested RemoteValues from the parsed tree instead of re-serializing each subtree (#18095) (Yash Pardeshi) #18095
  • 788fcf3: [rb] type a field-less synthetic map record as a validated map (#18121) (Augustin Gottlieb) #18121
  • e420863: [java] remove guava from client bindings #12737 (#13739) (joerg1985) #13739
  • e0c56c9: [rb] update test guard for different bidi error in Chrome beta (Titus Fortner)
  • 5026a72: [build] clean up IntelliJ project files and align .editorconfig with formatters (#18119) (Titus Fortner) #18119
  • b5aacd7: [build] SM production release skips debug jobs and builds Mac binaries in parallel (Titus Fortner)
  • 4961c4f: [javascript] Create @seleniumhq/atoms npm package from TypeScript atoms (#17459) (David Burns) #17459
  • 229a802: [java][bidi] Add BiDi code generator (#17777) (Puja Jagani) #17777
  • 13920ed: [java][bidi] Export the generated protocol classes from selenium-remote-driver (Titus Fortner)
  • 21e7241: [build] download prebuilt SBOM tools instead of compiling them for Selenium Manager releases (Titus Fortner)
  • 6fcc54c: [rust] bump the crate version in Cargo.lock directly instead of repinning through Bazel (Titus Fortner)
19 hours ago
Activiti
21 hours ago
netty

netty-4.1.139.Final

Security

Note that Netty 4.1 will be End-of-Life on July 1st, 2027.

We strongly recommend upgrading to this version to get the following security fixes:

  • CVE-2026-XXXXX : parser desync in io.netty:netty-codec-haproxy
  • CVE-2026-XXXXX : improper CRLF neutralization (request/response smuggling) in io.netty:netty-codec-http
  • CVE-2026-XXXXX : origin validation error in io.netty:netty-codec-http
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-http2
  • CVE-2026-XXXXX : request/response smuggling in io.netty:netty-codec-http
  • CVE-2026-XXXXX : time-of-check/time-of-use error in io.netty:netty-handler-ssl-ocsp
  • CVE-2026-XXXXX : SNI routing bypass in io.netty:netty-handler
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-xml
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-base
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-http
  • CVE-2026-XXXXX : input misinterpretation in io.netty:netty-codec-socks
  • CVE-2026-XXXXX : improper access control in io.netty:netty-handler
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-dns

Note that due to overwhelming strain on the CVE infrastructure, we have not gotten a single CVE number assigned to these reports in time for our release. The advisories will be published without.

Specific changes worth calling out:

Validation in FileUpload.setContentType. Previously, the FileUpload.setContentType methods did not validate their inputs. They now throw an IllegaalArgumentException if the given string is not formatted as a plausible MIME content type.

What's Changed

New Contributors

Full Changelog: https://github.com/netty/netty/compare/netty-4.1.138.Final...netty-4.1.139.Final

21 hours ago
netty

netty-4.2.19.Final

Security

Note that Netty 4.1 will be End-of-Life on July 1st, 2027.

We strongly recommend upgrading to this version to get the following security fixes:

  • CVE-2026-XXXXX : parser desync in io.netty:netty-codec-haproxy
  • CVE-2026-XXXXX : improper CRLF neutralization (request/response smuggling) in io.netty:netty-codec-http
  • CVE-2026-XXXXX : origin validation error in io.netty:netty-codec-http
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-http2
  • CVE-2026-XXXXX : request/response smuggling in io.netty:netty-codec-http
  • CVE-2026-XXXXX : time-of-check/time-of-use error in io.netty:netty-handler-ssl-ocsp
  • CVE-2026-XXXXX : SNI routing bypass in io.netty:netty-handler
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-xml
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-base
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-http
  • CVE-2026-XXXXX : input misinterpretation in io.netty:netty-codec-socks
  • CVE-2026-XXXXX : improper access control in io.netty:netty-handler
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-dns
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-http3
  • CVE-2026-XXXXX : use-after-free in io.netty:netty-transport-classes-io_uring
  • CVE-2026-XXXXX : memory leak in io.netty:netty-transport-native-io_uring

Note that due to overwhelming strain on the CVE infrastructure, we have not gotten a single CVE number assigned to these reports in time for our release. The advisories will be published without.

Specific changes worth calling out:

Validation in FileUpload.setContentType. Previously, the FileUpload.setContentType methods did not validate their inputs. They now throw an IllegaalArgumentException if the given string is not formatted as a plausible MIME content type.

What's Changed

New Contributors

Full Changelog: https://github.com/netty/netty/compare/netty-4.2.18.Final...netty-4.2.19.Final

1 days ago
Activiti
1 days ago
selenium

Nightly

Commits

  • 8ba36d4: [build] Automated Dependency Update (#18124) (Selenium CI Bot) #18124
  • 77e3a5f: [build] Automated Selenium Manager Update (Selenium CI Bot)
  • 9fc36cc: [dotnet] [build] Escape macOS Edge browser path (#18126) (Nikolay Borisenko) #18126