Skip to content

[FLINK-36767] Bumped cyclonedx-maven-plugin to 2.9.1 to resolve CVE-2024-38374 #26476

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

vivek807
Copy link

@vivek807 vivek807 commented Apr 17, 2025

What is the purpose of the change

Bumped cyclonedx-maven-plugin to 2.9.1 to resolve the vulnerability CVE-2024-38374

Brief change log

Updated cyclonedx-maven-plugin version to 2.9.1 in parent pom.xml to resolve vulnerability CVE-2024-38374.

Verifying this change

This change is a trivial rework / code cleanup without any test coverage.

Does this pull request potentially affect one of the following parts:

  • Dependencies (does it add or upgrade a dependency): yes
  • The public API, i.e., is any changed class annotated with @public(Evolving): no
  • The serializers: no
  • The runtime per-record code paths (performance sensitive): no
  • Anything that affects deployment or recovery: JobManager (and its components), Checkpointing, Kubernetes/Yarn, - - ZooKeeper: no
  • The S3 file system connector. no

Documentation

  • Does this pull request introduce a new feature? no
  • If yes, how is the feature documented? (not applicable / docs / JavaDocs / not documented)

@vivek807 vivek807 changed the title Bumped cyclonedx-maven-plugin to 2.9.1 to resolve CVE-2024-38374 [FLINK-36767] Bumped cyclonedx-maven-plugin to 2.9.1 to resolve CVE-2024-38374 Apr 17, 2025
@flinkbot
Copy link
Collaborator

flinkbot commented Apr 17, 2025

CI report:

Bot commands The @flinkbot bot supports the following commands:
  • @flinkbot run azure re-run the last Azure build

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants