manuzhang opened a new pull request, #18358: URL: https://github.com/apache/iceberg/pull/18358
The CVE scan fails for the Kafka Connect runtime on CVE-2026-68494 (HIGH) in jackson-core 2.21.3, which is shaded into parquet-jackson 1.17.1. It is the CVE ID of GHSA-r7wm-3cxj-wff9, which the trivyignore already lists, but Trivy now reports the advisory by its CVE ID, so the GHSA entry no longer matches. This adds the CVE ID next to the GHSA ID. Test plan: the kafka-connect-runtime CVE scan on this PR should pass. It fails on [Spark 4.2: Fix view rename target namespace](https://github.com/apache/iceberg/pull/18255) with only this finding. --- **AI Disclosure** - Model: Claude Opus 5.5 - Platform/Tool: Claude Code - Human Oversight: [unknown - human to fill in] - Prompt Summary: Fix the Kafka Connect runtime CVE scan failure on CVE-2026-68494. The trivyignore entry and comment change are generated. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
