Hi Apoorv grype on 4.2 shows these dependency CVEs not yet on the 4.2.2 plan:
jline 3.30.4 -> 3.30.14 CVE-2026-56740/56741 jetty 12.0.34 -> 12.0.37 CVE-2026-10050/10051/8384/6790 lz4-java 1.10.1 -> 1.11.2 CVE-2026-59949 Should we fix them for 4.2.2? Best, Chia-Ping Chia-Ping Tsai <[email protected]> 於 2026年9月2日週三 下午10:18寫道: > Hi Apoorv > > thanks for the plan. It is great! > > typo: Septmber > > > Bill Bejeck <[email protected]> 於 2026年9月2日週三 下午9:46寫道: > >> Thanks for volunteering Apoorv! >> >> It's +1 from me for the release plan. >> >> -Bill >> >> On Tue, Sep 1, 2026 at 11:08 AM Apoorv Mittal <[email protected]> >> wrote: >> >> > Hi all, >> > >> > I’ll be the release manager for the 4.2.2 bug fix release. >> > >> > Here's the 4.2.2 release plan >> > < >> > >> > >> https://cwiki.apache.org/confluence/spaces/KAFKA/pages/451971202/Release+Plan+4.2.2 >> > >. >> > >> > The code freeze date will be on Tuesday 15 September 2026 (I kept it 2 >> > weeks from now as there is only 1 outstanding issue currently to be >> > resolved and 4.3.2 release to follow shortly as well). >> > >> > The first release candidate will follow shortly after that. >> > >> > Please let me know if you have any concerns about the schedule. >> > >> > Regards, >> > Apoorv Mittal >> > >> >
