manuzhang opened a new pull request, #18346: URL: https://github.com/apache/iceberg/pull/18346
The CVE scan now fails on every PR that runs it: Trivy reports CVE-2026-89407 and CVE-2026-89425 (HIGH) in jackson-core 2.21.3 in the Kafka Connect runtime. That copy is shaded into parquet-jackson 1.17.1; the runtime's own jackson-core is already 2.22.3. Like the other parquet-jackson findings, it cannot be upgraded independently of Apache Parquet, so this adds both CVEs to the Kafka Connect runtime trivyignore. Note that Parquet 1.18.1 bundles jackson 2.22.2, which does not fix these two, so the Parquet bump alone will not remove them. Test plan: the kafka-connect-runtime CVE scan on this PR should pass. It fails on [Spark 4.2: Fix view rename target namespace](https://github.com/apache/iceberg/pull/18255) with only these two findings, and the other distributions pass there. --- **AI Disclosure** - Model: Claude Opus 5.5 - Platform/Tool: Claude Code - Human Oversight: [unknown - human to fill in] - Prompt Summary: Fix the CVE scan failure in the Kafka Connect runtime. The trivyignore entries and their comment are generated. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
