I believe `iceberg-iceberg-kafka-connect` is manually built and uploaded by
the community. We have a thread to automate the release but need to fix its
license and notice files first.
At the very least, I think we should remove dev@ from these security
notifications. I'll reach out to someone who might be able to help.

Best,
Kevin Liu

On Tue, Aug 18, 2026 at 9:40 AM confluent-hub.confluent.io via dev <
[email protected]> wrote:

> Dear Issues Team,
>
> We regularly perform security scans on Confluent Hub connectors, as per
> Confluent’s security policy. Unfortunately *iceberg-iceberg-kafka-connect*
> has been flagged as having vulnerabilities, and our policy is to escalate
> the connector to removal stages, unless we receive confirmation that the
> issues are being addressed by the partner.
>
> I have attached the vulnerability scan. Please note that we acknowledge
> two exceptions for vulnerabilities raised:
>
>    - Partner confirms that the vulnerability is a false positive
>    - Partner confirms that the issue is valid but not exploitable
>
> Please can you *acknowledge receipt of this email*, and as soon as
> possible thereafter let us know your position on these vulnerabilities.
>
> Reminder emails will be sent on a weekly basis until all vulnerabilities
> have been appropriately remediated, or the connector has been removed from
> the Confluent Hub.
>
> If you require further information on any of the above, please do not
> hesitate to get in touch.
>
> Best regards,
> CCET Team
>

Reply via email to