Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CC-26342: Pin numbus-jose-jwt to fix CVE #696

Merged
merged 2 commits into from
May 18, 2024
Merged

CC-26342: Pin numbus-jose-jwt to fix CVE #696

merged 2 commits into from
May 18, 2024

Conversation

vbalani002
Copy link
Contributor

Problem

Solution

Does this solution apply anywhere else?
  • yes
  • no
If yes, where?

Test Strategy

Testing done:
  • Unit tests
  • Integration tests
  • System tests
  • Manual tests

Release Plan

@vbalani002 vbalani002 requested a review from a team as a code owner May 13, 2024 09:21
@sonarqube-confluent
Copy link

Passed

Analysis Details

0 Issues

  • Bug 0 Bugs
  • Vulnerability 0 Vulnerabilities
  • Code Smell 0 Code Smells

Coverage and Duplications

  • Coverage No coverage information (72.70% Estimated after merge)
  • Duplications No duplication information (1.50% Estimated after merge)

Project ID: kafka-connect-hdfs

View in SonarQube

@vbalani002 vbalani002 merged commit dbd43bf into CC-26341 May 18, 2024
1 check passed
@vbalani002 vbalani002 deleted the CC-26342 branch May 18, 2024 07:54
vbalani002 added a commit that referenced this pull request May 19, 2024
…#693)

* Upgrade kafka-connect-storage-common version

* Bump storage common version

* CC-27071: Fix CVEs in avatica-core by pinning the dependency + Updating calcite-core to latest supported version (#698)

* CC-26343: Exclude commons-httpclient to fix CVE (#697)

* CC-26342: Pin numbus-jose-jwt to fix CVE (#696)

* CC-26345: Pin okio version to fix CVE (#694)

* Fix non-parsable pom

* Pin nimbus-jose-jwt
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant