stefanbacon opened a new pull request #968:
URL: https://github.com/apache/avro/pull/968


   dependathon doc: 
https://docs.google.com/document/d/1olZJEDXekdjGug84nOoH6uPEalUuWsDpeM_XgeBVOFE/edit
   
   - jetty 9.4.6.v20170531 -> 9.4.32.v20200930
   - commons-compress 1.13 -> 1.20
   
   fixes:
   
   CVE-2018-1324
   CVE-2017-7658
   CVE-2018-11771
   CVE-2018-12538
   CVE-2018-12536
   CVE-2017-7656
   CVE-2019-10246
   CVE-2019-10247
   CVE-2018-12545
   
   
   - [ ] TODO fix jackson vulnerability but CVE-2019-10172 1.9.13 is the latest 
jackson available


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
[email protected]


Reply via email to