Skip to content

Conversation

@rjrudin
Copy link
Contributor

@rjrudin rjrudin commented Sep 29, 2025

This only affects the tests, as the connector doesn't include zookeeper

This only affects the tests, as the connector doesn't include zookeeper
@rjrudin rjrudin requested a review from anu3990 as a code owner September 29, 2025 20:16
Copilot AI review requested due to automatic review settings September 29, 2025 20:16
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates the Apache Zookeeper dependency from version 3.9.3 to 3.9.4 to address security vulnerability CVE-2025-58457. The change adds a comprehensive dependency resolution strategy that forces the newer Zookeeper version and also updates several other dependencies (Hadoop, Janino, and Netty) to minimize CVEs.

  • Added dependency resolution strategy to force Zookeeper 3.9.4
  • Updated Hadoop from 3.4.1 to 3.4.2
  • Updated Janino to 3.1.12 and Netty to 4.1.127.Final

Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.

@github-actions
Copy link

Copyright Validation Results
Total: 2 | Passed: 0 | Failed: 0 | Skipped: 2 | at: 2025-09-29 20:16:34 UTC | commit: ac54786

⏭️ Skipped (Excluded) Files

  • build.gradle
  • marklogic-spark-connector/build.gradle

✅ All files have valid copyright headers!

@sonarqube-progress-marklogic
Copy link

Quality Gate passed Quality Gate passed

Issues
0 New issues
0 Fixed issues
0 Accepted issues

Measures
0 Security Hotspots
No data about Coverage
No data about Duplication

See analysis details on SonarQube

@rjrudin rjrudin merged commit efc271e into develop Sep 29, 2025
4 checks passed
@rjrudin rjrudin deleted the feature/24494-zoo branch September 29, 2025 23:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants