Skip to content

[Backport 2.12] Updates several dependencies to address CVEs#5923

Merged
dlvenable merged 1 commit into2.12from
backport/backport-5914-to-2.12
Jul 30, 2025
Merged

[Backport 2.12] Updates several dependencies to address CVEs#5923
dlvenable merged 1 commit into2.12from
backport/backport-5914-to-2.12

Conversation

@opensearch-trigger-bot
Copy link
Copy Markdown
Contributor

Backport c8f66fa from #5914

Updates several dependencies to address CVEs

* CVE-2025-46762 - Parquet 1.15.2
* CVE-2025-48734 - commons-beanutils 1.11.0 and Checkstyle 10.26.1
* CVE-2024-57699 - json-smart 2.5.2
* CVE-2025-24970 - Netty 4.1.123
* CVE-2025-27817 - Apache Kafka 3.9.1 and Confluent Kafka 7.9.1

Also, removes some broken code related to the kafka-client in unused Kafka tests.

Signed-off-by: David Venable <dlv@amazon.com>
(cherry picked from commit c8f66fa)
@github-actions
Copy link
Copy Markdown

github-actions bot commented Jul 30, 2025

Unit Test Results

  3 828 files   - 1    3 828 suites   - 1   1h 45m 4s ⏱️ +35s
11 760 tests ±0  11 754 ✔️ ±0    6 💤 ±0  0 ±0 
32 835 runs  ±0  32 817 ✔️ ±0  18 💤 ±0  0 ±0 

Results for commit 6a79091. ± Comparison against base commit 8345a8e.

♻️ This comment has been updated with latest results.

@dlvenable dlvenable merged commit ff4d849 into 2.12 Jul 30, 2025
85 of 94 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant