You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The dependency version info can be lifted up into this pom.xml, but we already have commons-compress at 1.21 in ksqldb, schema-registry, connect-replicator, control-center, etc. I think that has also been backported to all supported versions.
A version upgrade for Avro needs to be handled carefully as we'd need to check for any incompatibilities, especially in backporting to earlier versions. Given the issue is already addressed by pinning the commons-compress version, I'm not sure we'd want to do more here other than updating master to the new version after evaluating any potential compatibility issues.
It seems the avro version was upgraded: a4eed43
Which release will contain this change?
Is there any place where we can check the planned releases? (time and contained features/fixes)
Thanks
The 1.10.2 Avro version has several vulnerabilities AVRO-3227 which are fixed in the 1.11.0 version AVRO-3215.
The text was updated successfully, but these errors were encountered: