Upgrade the CouchDB used to v3.3.3 as per CVE-2023-45725. #4595
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Type of change
Description
Move to CouchDB v3.3.3. There's a security vulnerability with CouchDB v3.3.2. I think this only impacts the testing that happens to Fabric, but this PR is a good way to be sure.
Additional details
I have tested that CouchDB v3.3.3 is not majorly functionally different than CouchDB v3.3.2. (See its Release Notes). There have been no breaking API changes in v3.3.3, only bug fixes and security patches.
I would suggest backporting this to Fabric v2.5.x because it's only a CouchDB Patch.
Related issues
Tracked by #4594