confluentinc / kafka-connect-storage-common

Shared software among connectors that target distributed filesystems and cloud storage.
Other
73 stars 154 forks source link

CC-22820, CC-22998, CC-23052: Fix avro and snappy CVEs #339

Closed sambhav-jain-16 closed 5 months ago

sambhav-jain-16 commented 5 months ago

Problem

https://confluentinc.atlassian.net/browse/CC-22820 https://confluentinc.atlassian.net/browse/CC-22998 https://confluentinc.atlassian.net/browse/CC-23052

Solution

Bump common

Does this solution apply anywhere else?
If yes, where?

Test Strategy

Testing done:

Release Plan

venkatteki commented 5 months ago

@sambhav-jain-16 dont we need these fixes in older feature branches?

sambhav-jain-16 commented 5 months ago

@venkatteki CVEs were only for master branch

venkatteki commented 5 months ago

@venkatteki CVEs were only for master branch

Some connectors might be using storage-commons right? Don't we need a new release for this repo to update in the connector repos?