This is an automated email from the ASF dual-hosted git repository.
lhotari pushed a change to branch branch-3.0
in repository https://gitbox.apache.org/repos/asf/pulsar.git
from e0a10a44538 [fix][io] Restore lz4 compression with Kafka IO connector
after #25198 exclusion
new 6de69534a15 [fix][sec] Override kafka-clients in kinesis-kpl-shaded to
remediate CVE-2024-31141 and CVE-2025-27817 (#24935)
new d7a4814e603 [fix][sec] Exclude org.lz4:lz4-java and standardize on
at.yawk.lz4-java to remediate CVE-2025-12183 and CVE-2025-66566 (#25198)
The 2 revisions listed above as "new" are entirely new to this
repository and will be described in separate emails. The revisions
listed as "add" were already present in the repository and have only
been added to this reference.
Summary of changes:
pom.xml | 7 +++++++
pulsar-common/pom.xml | 3 +--
pulsar-io/debezium/core/pom.xml | 4 ++++
pulsar-io/kafka-connect-adaptor/pom.xml | 4 ++++
pulsar-io/kafka/pom.xml | 4 ++++
pulsar-io/kinesis-kpl-shaded/pom.xml | 12 ++++++++++++
pulsar-io/kinesis/pom.xml | 6 ++++++
7 files changed, 38 insertions(+), 2 deletions(-)