Skip to content

Commit c829d7a

Browse files
[FLINK-33238][Formats/Avro] Upgrade used AVRO version to 1.11.3. This closes #59
* [FLINK-33238][Formats/Avro] Upgrade used AVRO version to 1.11.3 to mitigate scanners flagging Flink or the Flink Kafka connector as vulnerable for CVE-2023-39410 * [FLINK-33238][Formats/Avro] Pin transitive dependency org.apache.commons:commons-compress to 1.22 to address dependency convergence
1 parent bd260f1 commit c829d7a

File tree

1 file changed

+8
-1
lines changed

1 file changed

+8
-1
lines changed

pom.xml

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -68,7 +68,7 @@ under the License.
6868
<scala-reflect.version>2.12.7</scala-reflect.version>
6969
<scala-library.version>2.12.7</scala-library.version>
7070
<snappy-java.version>1.1.10.5</snappy-java.version>
71-
<avro.version>1.11.1</avro.version>
71+
<avro.version>1.11.3</avro.version>
7272

7373
<japicmp.skip>false</japicmp.skip>
7474
<japicmp.referenceVersion>1.17.0</japicmp.referenceVersion>
@@ -405,6 +405,13 @@ under the License.
405405
<version>2.1</version>
406406
</dependency>
407407

408+
<!-- For dependency convergence -->
409+
<dependency>
410+
<groupId>org.apache.commons</groupId>
411+
<artifactId>commons-compress</artifactId>
412+
<version>1.22</version>
413+
</dependency>
414+
408415
<dependency>
409416
<groupId>org.testcontainers</groupId>
410417
<artifactId>testcontainers-bom</artifactId>

0 commit comments

Comments
 (0)