manuzhang opened a new pull request, #18358:
URL: https://github.com/apache/iceberg/pull/18358

   The CVE scan fails for the Kafka Connect runtime on CVE-2026-68494 (HIGH) in 
jackson-core 2.21.3, which is shaded into parquet-jackson 1.17.1. It is the CVE 
ID of GHSA-r7wm-3cxj-wff9, which the trivyignore already lists, but Trivy now 
reports the advisory by its CVE ID, so the GHSA entry no longer matches. This 
adds the CVE ID next to the GHSA ID.
   
   Test plan: the kafka-connect-runtime CVE scan on this PR should pass. It 
fails on [Spark 4.2: Fix view rename target 
namespace](https://github.com/apache/iceberg/pull/18255) with only this finding.
   
   ---
   **AI Disclosure**
   - Model: Claude Opus 5.5
   - Platform/Tool: Claude Code
   - Human Oversight: [unknown - human to fill in]
   - Prompt Summary: Fix the Kafka Connect runtime CVE scan failure on 
CVE-2026-68494. The trivyignore entry and comment change are generated.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to