Skip to content

Commit 204b239

Browse files
authored
feat(druid): update advisory for GHSA-h46c-h94j-95f3 (#20789)
* feat(druid): update advisory for GHSA-h46c-h94j-95f3 Signed-off-by: Francesco Bartolini <[email protected]> * fix: typo Signed-off-by: Francesco Bartolini <[email protected]> --------- Signed-off-by: Francesco Bartolini <[email protected]>
1 parent 8b9cdde commit 204b239

File tree

1 file changed

+4
-0
lines changed

1 file changed

+4
-0
lines changed

druid.advisories.yaml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1115,6 +1115,10 @@ advisories:
11151115
componentType: java-archive
11161116
componentLocation: /usr/share/java/druid/extensions/druid-deltalake-extensions/hadoop-client-runtime-3.3.4.jar
11171117
scanner: grype
1118+
- timestamp: 2025-07-02T10:09:06Z
1119+
type: pending-upstream-fix
1120+
data:
1121+
note: 'Jackson-core is pinned at 2.12.7 for this Druid tagged version: https://github.com/apache/druid/blob/druid-33.0.0/licenses.yaml#L226. We need to wait for upstream to bump it in order to fix this vulnerability.'
11181122

11191123
- id: CGA-w2gp-wc62-wqxq
11201124
aliases:

0 commit comments

Comments
 (0)