[ 
https://issues.apache.org/jira/browse/FLINK-10007?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Flink Jira Bot updated FLINK-10007:
-----------------------------------
      Labels: auto-deprioritized-critical auto-deprioritized-major 
auto-deprioritized-minor  (was: auto-deprioritized-critical 
auto-deprioritized-major stale-minor)
    Priority: Not a Priority  (was: Minor)

This issue was labeled "stale-minor" 7 days ago and has not received any 
updates so it is being deprioritized. If this ticket is actually Minor, please 
raise the priority and ask a committer to assign you the issue or revive the 
public discussion.


> Security vulnerability in website build infrastructure
> ------------------------------------------------------
>
>                 Key: FLINK-10007
>                 URL: https://issues.apache.org/jira/browse/FLINK-10007
>             Project: Flink
>          Issue Type: Bug
>          Components: Project Website
>            Reporter: Fabian Hueske
>            Priority: Not a Priority
>              Labels: auto-deprioritized-critical, auto-deprioritized-major, 
> auto-deprioritized-minor
>
> We've got a notification from Apache INFRA about a potential security 
> vulnerability:
> {quote}
> We found a potential security vulnerability in a repository for which you 
> have been granted security alert access.
> @apache       apache/flink-web
> Known high severity security vulnerability detected in yajl-ruby < 1.3.1 
> defined in Gemfile.
> Gemfile update suggested: yajl-ruby ~> 1.3.1. 
> {quote}
> This is a problem with the build environment of the website, i.e., this 
> dependency is not distributed or executed with Flink but only run when the 
> website is updated.
> Nonetheless, we should of course update the dependency.



--
This message was sent by Atlassian Jira
(v8.20.1#820001)

Reply via email to