Skip to content

Comments

update jar deps to fix snyk vulns#17

Merged
burnerlee merged 1 commit intodevfrom
burnerlee/fix-sec-vulns-23feb
Feb 23, 2026
Merged

update jar deps to fix snyk vulns#17
burnerlee merged 1 commit intodevfrom
burnerlee/fix-sec-vulns-23feb

Conversation

@burnerlee
Copy link

Build fix

  • Exclude transitive Confluent artifacts not in public repos: apiserver-client, telemetry-client, telemetry-api (fixes Could not find ... apiserver-client-0.5199.0.jar and related resolution failures).

/close ISS-240045 ISS-240046 ISS-247913 ISS-250337

Security dependency upgrades (Snyk)

  • logback (logback-core, logback-classic): 1.5.19 → 1.5.25 (SNYK-JAVA-CHQOSLOGBACK-15062482)
  • netty-codec-http: 4.1.125.Final → 4.1.129.Final (SNYK-JAVA-IONETTY-14423947)
  • vertx-core: 4.4.8 → 4.5.24 (SNYK-JAVA-IOVERTX-14988768)
  • log4j (log4j-api, log4j-core): 2.24.3/2.25.2 → 2.25.3 (SNYK-JAVA-ORGAPACHELOGGINGLOG4J-14532782)

Resolution strategy forces and test deps updated accordingly.

@burnerlee burnerlee merged commit 4d30bdf into dev Feb 23, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants