guptas6est commented on PR #24935:
URL: https://github.com/apache/pulsar/pull/24935#issuecomment-3480779740

   Thanks for the clarification, @lhotari. I made this change because the Trivy 
scan showed two CVEs in org.apache.kafka:kafka-clients under the 
pulsar-io/kinesis-kpl-shaded module.
   
   I added the same version override here to make sure the CVEs were fixed, as 
it looked like the version from pulsar-io/kinesis wasn’t being applied to 
kinesis-kpl-shaded. This was mainly to keep the versions consistent and clear 
the security warnings.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to