I believe `iceberg-iceberg-kafka-connect` is manually built and uploaded by the community. We have a thread to automate the release but need to fix its license and notice files first. At the very least, I think we should remove dev@ from these security notifications. I'll reach out to someone who might be able to help.
Best, Kevin Liu On Tue, Aug 18, 2026 at 9:40 AM confluent-hub.confluent.io via dev < [email protected]> wrote: > Dear Issues Team, > > We regularly perform security scans on Confluent Hub connectors, as per > Confluent’s security policy. Unfortunately *iceberg-iceberg-kafka-connect* > has been flagged as having vulnerabilities, and our policy is to escalate > the connector to removal stages, unless we receive confirmation that the > issues are being addressed by the partner. > > I have attached the vulnerability scan. Please note that we acknowledge > two exceptions for vulnerabilities raised: > > - Partner confirms that the vulnerability is a false positive > - Partner confirms that the issue is valid but not exploitable > > Please can you *acknowledge receipt of this email*, and as soon as > possible thereafter let us know your position on these vulnerabilities. > > Reminder emails will be sent on a weekly basis until all vulnerabilities > have been appropriately remediated, or the connector has been removed from > the Confluent Hub. > > If you require further information on any of the above, please do not > hesitate to get in touch. > > Best regards, > CCET Team >
