Skip to content

Possibility to exclude Netty dependencies #2047

Description

@dcolazin

Is your feature request related to a problem? Please describe.

Since version 5.27.0 (#1663), this project has Netty dependencies. Those dependencies cannot currently be safely excluded from this client version, even when blocking IO is selected, as ConnectionFactory eagerly initializes:

private final NettyConfiguration nettyConf = new NettyConfiguration(this);

and NettyConfiguration directly references Netty classes, so class loading fails before selection of blocking IO (the default), NIO (deprecated) or Netty.

This creates additional burdens on downstream projects as they might need to update dependencies when vulnerabilities are discovered on Netty.

Describe the solution you'd like

Do not always instantiate NettyConfiguration during ConnectionFactory creation, but only when Netty is activated.

Describe alternatives you've considered

No response

Additional context

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions