manuzhang opened a new pull request, #18346:
URL: https://github.com/apache/iceberg/pull/18346

   The CVE scan now fails on every PR that runs it: Trivy reports 
CVE-2026-89407 and CVE-2026-89425 (HIGH) in jackson-core 2.21.3 in the Kafka 
Connect runtime. That copy is shaded into parquet-jackson 1.17.1; the runtime's 
own jackson-core is already 2.22.3. Like the other parquet-jackson findings, it 
cannot be upgraded independently of Apache Parquet, so this adds both CVEs to 
the Kafka Connect runtime trivyignore. Note that Parquet 1.18.1 bundles jackson 
2.22.2, which does not fix these two, so the Parquet bump alone will not remove 
them.
   
   Test plan: the kafka-connect-runtime CVE scan on this PR should pass. It 
fails on [Spark 4.2: Fix view rename target 
namespace](https://github.com/apache/iceberg/pull/18255) with only these two 
findings, and the other distributions pass there.
   
   ---
   **AI Disclosure**
   - Model: Claude Opus 5.5
   - Platform/Tool: Claude Code
   - Human Oversight: [unknown - human to fill in]
   - Prompt Summary: Fix the CVE scan failure in the Kafka Connect runtime. The 
trivyignore entries and their comment are generated.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to