[fix][sec] Do Not Merge: Upgrade Debezium oracle connector version to avoid CVE-2023-4586 #8
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Fixes apache#22626
Motivation
Avoid CVE-2023-4586
Modifications
Upgrade debezium-oracle-connector version to 2.2.0.Final
which avoids
org.infinispan:infinispan-client-hotrod@14.0.4.Final
which has the vulnerability and usesorg.infinispan:infinispan-client-hotrod-jakarta@14.0.4.Final
instead, which has no vulnerabilities.Verifying this change
Does this pull request potentially affect one of the following parts:
If the box was checked, please highlight the changes
Documentation
doc
doc-required
doc-not-needed
doc-complete