Confluent regularly performs security scans on Confluent Hub connectors, as per Confluent’s security policy. Unfortunately this connector has been flagged as having unacceptable vulnerabilities and our policy is to escalate the connector to removal stages, unless we receive confirmation that the issues are being addressed by the partner.
I have attached the vulnerability scan. Please note that we acknowledge two exceptions for vulnerabilities raised:
Partner confirms that vulnerability is a false positive
Partner confirms that the issue is valid but not exploitable
Please can you urgently acknowledge receipt of this email, and as soon as possible thereafter let us know the ScyllaDB position on these vulnerabilities.
If you require further information on any of the above, please do not hesitate to get in touch.
Closing this older issue, the reported problems were already solved (notified via email) and now we have a daily vulnerability scan in the repo (that's currently passing).
Confluent regularly performs security scans on Confluent Hub connectors, as per Confluent’s security policy. Unfortunately this connector has been flagged as having unacceptable vulnerabilities and our policy is to escalate the connector to removal stages, unless we receive confirmation that the issues are being addressed by the partner.
I have attached the vulnerability scan. Please note that we acknowledge two exceptions for vulnerabilities raised: Partner confirms that vulnerability is a false positive Partner confirms that the issue is valid but not exploitable
Please can you urgently acknowledge receipt of this email, and as soon as possible thereafter let us know the ScyllaDB position on these vulnerabilities.
If you require further information on any of the above, please do not hesitate to get in touch.
Best regards,
Confluent CCET Team
scylladb.csv