Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade avro to 1.11.3 due CVE-2023-39410 #23142

Merged

Conversation

denodo-research-labs
Copy link
Contributor

@denodo-research-labs denodo-research-labs commented Jul 8, 2024

Motivation and Context

Solve CVE of severity HIGH.

Contributor checklist

Release Notes

Please follow release notes guidelines and fill in the release notes below.

== RELEASE NOTES ==

General Changes
* Upgrade avro to 1.11.3 due CVE-2023-39410 :pr:`23142`


hantangwangd
hantangwangd previously approved these changes Jul 8, 2024
@steveburnett
Copy link
Contributor

Nit, suggest adding PR # in the release note entry:

== RELEASE NOTES ==

General Changes
* Upgrade avro to 1.11.3 due to CVE-2023-39410 :pr:`23142`

@tdcmeehan tdcmeehan self-assigned this Jul 24, 2024
@tdcmeehan
Copy link
Contributor

tdcmeehan commented Jul 24, 2024

Please rebase to fix the merge conflict. Let's also see if this addresses the test failures.

@denodo-research-labs
Copy link
Contributor Author

Please rebase to fix the merge conflict. Let's also see if this addresses the test failures.

Done, but the 2 failing checks seem to be unrelated with this PR.

@steveburnett
Copy link
Contributor

The merge conflict and the test failures seem to be addressed.

@tdcmeehan tdcmeehan merged commit 768efa3 into prestodb:master Aug 6, 2024
56 checks passed
@tdcmeehan tdcmeehan mentioned this pull request Aug 23, 2024
34 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants