Skip to content

Upgrade avro to 1.11.3 due CVE-2023-39410#23142

Merged
tdcmeehan merged 1 commit intoprestodb:masterfrom
denodo-research-labs:cve_2023_39410_avro
Aug 6, 2024
Merged

Upgrade avro to 1.11.3 due CVE-2023-39410#23142
tdcmeehan merged 1 commit intoprestodb:masterfrom
denodo-research-labs:cve_2023_39410_avro

Conversation

@denodo-research-labs
Copy link
Contributor

@denodo-research-labs denodo-research-labs commented Jul 8, 2024

Motivation and Context

Solve CVE of severity HIGH.

Contributor checklist

Release Notes

Please follow release notes guidelines and fill in the release notes below.

== RELEASE NOTES ==

General Changes
* Upgrade avro to 1.11.3 due CVE-2023-39410 :pr:`23142`


hantangwangd
hantangwangd previously approved these changes Jul 8, 2024
@steveburnett
Copy link
Contributor

Nit, suggest adding PR # in the release note entry:

== RELEASE NOTES ==

General Changes
* Upgrade avro to 1.11.3 due to CVE-2023-39410 :pr:`23142`

@tdcmeehan tdcmeehan self-assigned this Jul 24, 2024
@tdcmeehan
Copy link
Contributor

tdcmeehan commented Jul 24, 2024

Please rebase to fix the merge conflict. Let's also see if this addresses the test failures.

@denodo-research-labs
Copy link
Contributor Author

Please rebase to fix the merge conflict. Let's also see if this addresses the test failures.

Done, but the 2 failing checks seem to be unrelated with this PR.

@steveburnett
Copy link
Contributor

The merge conflict and the test failures seem to be addressed.

@tdcmeehan tdcmeehan merged commit 768efa3 into prestodb:master Aug 6, 2024
@tdcmeehan tdcmeehan mentioned this pull request Aug 23, 2024
34 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants