Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

upgrade protobuf-java dependencies due to CVEs #222

Closed
pjfanning opened this issue Aug 12, 2023 · 2 comments
Closed

upgrade protobuf-java dependencies due to CVEs #222

pjfanning opened this issue Aug 12, 2023 · 2 comments
Milestone

Comments

@pjfanning
Copy link
Contributor

pjfanning commented Aug 12, 2023

The Google BigQuery Storage and Google Pub/Sub gRPC connectors use protobuf-java due to the gRPC libs they use. The version of the gRPC libs we use is a bit old and defaults to protobuf-java 3.21.1. This version has CVEs. Let's use 3.21.12 instead (latest 3.21.x release as of Aug 2023).

@pjfanning pjfanning added this to the 1.0.0 milestone Aug 12, 2023
@pjfanning pjfanning changed the title review protobuf-java dependencies upgrade protobuf-java dependencies due to CVEs Aug 20, 2023
@rafalmag
Copy link

rafalmag commented Sep 5, 2023

Thanks @pjfanning for working on Pekko connectors. I see #230 PR is merged, thus can this issue be closed? As it is the last open issue for 1.0.0 milestone, when could we expect the connectors release to maven repo?

@pjfanning
Copy link
Contributor Author

closing as #230 is done

@rafalmag Releases in the ASF take a while because they require votes. This is best followed at https://lists.apache.org/list.html?dev@pekko.apache.org

The TLDR is that the Pekko Connectors release could happen tonight but it should happen soon.

See in particular, these mail threads:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
No open projects
Development

No branches or pull requests

2 participants