logstash-plugins / logstash-codec-avro

A logstash codec plugin for decoding and encoding Avro records
Apache License 2.0
15 stars 63 forks source link

Bump avro to 1.11.3 to fix cve #45

Open skumarp7 opened 6 months ago

skumarp7 commented 3 months ago

Hi @roaksoax @andsel ,

I understand that there are few compatibility issues with ruby 2.6 and avro gem. Is it not possible to merge the fix in logstash 8.x alone?

andsel commented 3 months ago

Hi @skumarp7 please send an email to security@elastic.co communicating which CVE this PR is trying to fix, in the email please specify to communicate with the Logstash team 🙏