Skip to content

Conversation

@tisonkun
Copy link
Member

See CVE-2022-38752.

Documentation

  • doc-required
    (Your PR needs to update docs and you will update later)

  • doc-not-needed
    (Please explain why)

  • doc
    (Your PR contains doc changes)

  • doc-complete
    (Docs have been already added)

Matching PR in forked repository

PR in forked repository: trivial to not have one.

Signed-off-by: tison <wander4096@gmail.com>
@tisonkun
Copy link
Member Author

cc @nicoloboschi @lhotari

@github-actions github-actions bot added the doc-not-needed Your PR changes do not impact docs label Sep 21, 2022
@Jason918 Jason918 changed the title fix(sec): bump snakeyaml to 1.32 for CVE-2022-38752 [fix][sec] Bump snakeyaml to 1.32 for CVE-2022-38752 Sep 22, 2022
Copy link
Contributor

@Jason918 Jason918 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@tisonkun
Copy link
Member Author

/pulsarbot run-failure-checks

@Jason918
Copy link
Contributor

@tisonkun we need to update the "LICENSE.bin.txt" files? like #17466

@tisonkun
Copy link
Member Author

@Jason918 you're right. Let me check and update them.

Signed-off-by: tison <wander4096@gmail.com>
@tisonkun
Copy link
Member Author

Updated.

@tisonkun
Copy link
Member Author

/pulsarbot run-failure-checks

@Jason918 Jason918 merged commit ec8b586 into apache:master Sep 24, 2022
@tisonkun tisonkun deleted the fix-CVE-2022-38752 branch September 24, 2022 04:45
Jason918 pushed a commit that referenced this pull request Sep 24, 2022
nicoloboschi pushed a commit to datastax/pulsar that referenced this pull request Sep 26, 2022
@congbobo184
Copy link
Contributor

could you please cherry-pick this PR to branch-2.9? thanks.

@tisonkun
Copy link
Member Author

@congbobo184 created at #18467.

@congbobo184 congbobo184 added the cherry-picked/branch-2.9 Archived: 2.9 is end of life label Nov 15, 2022
lhotari pushed a commit that referenced this pull request Jan 3, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants