Skip to content

Commit c6d04a0

Browse files
authored
feat(celeborn-0.5): update advisory for GHSA-h46c-h94j-95f3 (#20776)
Signed-off-by: Francesco Bartolini <[email protected]>
1 parent f81ea81 commit c6d04a0

File tree

1 file changed

+4
-0
lines changed

1 file changed

+4
-0
lines changed

celeborn-0.5.advisories.yaml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -153,6 +153,10 @@ advisories:
153153
componentType: java-archive
154154
componentLocation: /usr/share/java/celeborn/jars/hadoop-client-runtime-3.4.1.jar
155155
scanner: grype
156+
- timestamp: 2025-07-01T16:30:33Z
157+
type: pending-upstream-fix
158+
data:
159+
note: The vuln comes from the Hadoop dependency. Jackson-core is pinned at 2.12.7 in Hadoop 3.4.1. Once Hadoop updates it and also upstream update Hadoop to the fixed version, we can update and fix the package too.
156160

157161
- id: CGA-xvv2-g55w-6g8w
158162
aliases:

0 commit comments

Comments
 (0)