confluentinc / kafka-connect-datagen

Connector that generates data for demos
Apache License 2.0
20 stars 87 forks source link

Fix Avro CVE #136

Closed srishti-saraswat closed 1 year ago

srishti-saraswat commented 1 year ago

Problem

https://confluentinc.atlassian.net/browse/CC-22818 https://confluentinc.atlassian.net/browse/SECOPS-15591

Solution

Update common version and remove unused pinned avro version. Fix schema for transaction.avro

Does this solution apply anywhere else?
If yes, where?

Test Strategy

mvn dependency:tree | grep org.apache.avro       
[INFO] |  +- org.apache.avro:avro:jar:1.11.3:compile
Testing done:

Release Plan

srishti-saraswat commented 1 year ago

Build - https://jenkins.confluent.io/job/Confluent%20Public%20Repo%20PR%20builder/job/kafka-connect-datagen/view/change-requests/job/PR-136/4/

srishti-saraswat commented 1 year ago

Build - https://jenkins.confluent.io/job/Confluent%20Public%20Repo%20PR%20builder/job/kafka-connect-datagen/view/change-requests/job/PR-136/5/