[Bug] Upgrade GRPC to 1.79 to remediate CVEs
- Dominant language
- Java
- Stars
- 22.6k
- Forks
- 12k
- Avg merge
- 2d 20h
- Merged PRs (30d)
- 26
Description
### Before Creating the Bug Report
- [x] I found a bug, not just asking a question, which should be created in [GitHub Discussions](https://github.com/apache/rocketmq/discussions).
- [x] I have searched the [GitHub Issues](https://github.com/apache/rocketmq/issues) and [GitHub Discussions](https://github.com/apache/rocketmq/discussions) of this repository and believe that this is not a duplicate.
- [x] I have confirmed that this bug belongs to the current repository, not other repositories of RocketMQ.
### Runtime platform environment
All
### RocketMQ version
develop
### JDK Version
_No response_
### Describe the Bug
Upgraded GRPC to 1.79 to remediate CVE-2023-32731, CVE-2023-32732 and CVE-2025-55163
### Steps to Reproduce
N/A
### What Did You Expect to See?
N/A
### What Did You See Instead?
N/A
### Additional Context
_No response_
Contributor guide
Research direction
The issue names no files or tests. Start by locating the RocketMQ gRPC dependency declaration and its resolved version, then verify the upgrade to gRPC 1.79 addresses CVE-2023-32731, CVE-2023-32732, and CVE-2025-55163 without breaking the build.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- grpc, java
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 65/100