We've just made a new release of the Apache HBase Thirdparty project. This project is used by the Apache HBase project to encapsulate a number of core dependencies that HBase relies upon ensuring that they are properly isolated from HBase downstream users, e.g. Google Protocol Buffers, Google Guava, and a few others.
4.1.7 is a regular release with some dependencies update. We bump netty to 4.1.108.Final for addressing CVE-2024-29025. A bump protobuf to 4.26.1, which has some incompatible changes, see HBASE-28493 and the discussion thread[1] for more details. The release is available as source at https://downloads.apache.org/[2] and as artifacts up in Maven central[3]. Release notes and Changes can be found at [2]. The release was tagged rel/4.1.7. All artifacts are signed with my key 9AD2AE49 which can be found here: https://downloads.apache.org/hbase/KEYS - Your Release Manager [1] https://lists.apache.org/thread/qwhnsoj1wosn10qz90rwjom5hlkgmk8q [2] https://downloads.apache.org/hbase/hbase-thirdparty-4.1.7 [3] https://repository.apache.org/service/local/repositories/releases/content/org/apache/hbase/thirdparty/hbase-thirdparty/4.1.7/