openzipkin / brave

Java distributed tracing implementation compatible with Zipkin backend services.
Apache License 2.0
2.36k stars 713 forks source link

fix(sec): upgrade org.apache.kafka:kafka-clients to 3.2.3 #1366

Closed W0lfier closed 1 year ago

W0lfier commented 1 year ago

What happened?

There are 1 security vulnerabilities found in org.apache.kafka:kafka-clients 3.2.1

What did I do?

Upgrade org.apache.kafka:kafka-clients from 3.2.1 to 3.4.0 for vulnerability fix

What did you expect to happen?

Ideally, no insecure libs should be used.

The specification of the pull request

PR Specification from OSCS

jcchavezs commented 1 year ago

Ping @jeqo

On Thu, 16 Mar 2023, 21:26 W0lfier, @.***> wrote:

What happened?

There are 1 security vulnerabilities found in org.apache.kafka:kafka-clients 3.2.1

What did I do?

Upgrade org.apache.kafka:kafka-clients from 3.2.1 to 3.4.0 for vulnerability fix What did you expect to happen?

Ideally, no insecure libs should be used. The specification of the pull request

PR Specification https://www.oscs1024.com/docs/pr-specification/ from OSCS

You can view, comment on, or merge this pull request online at:

https://github.com/openzipkin/brave/pull/1366 Commit Summary

File Changes

(1 file https://github.com/openzipkin/brave/pull/1366/files)

Patch Links:

— Reply to this email directly, view it on GitHub https://github.com/openzipkin/brave/pull/1366, or unsubscribe https://github.com/notifications/unsubscribe-auth/AAXOYAXO7Y6NJLO3DCVOHB3W4NZRFANCNFSM6AAAAAAV5WMLNQ . You are receiving this because you are subscribed to this thread.Message ID: @.***>

shakuzen commented 1 year ago

I updated the PR title and release notes since the merged change was an update to 3.2.3 rather than 3.4.0.