lhotari commented on PR #24935:
URL: https://github.com/apache/pulsar/pull/24935#issuecomment-3480733601

   > This PR addresses two medium-severity CVEs affecting the transitive 
dependency org.apache.kafka:kafka-clients used in the 
pulsar-io/kinesis-kpl-shaded module.
   
   This change seems to be unnecessary since the kafka-clients version is 
already enforced by 
https://github.com/apache/pulsar/blob/95c1dab5d15bc5cc4ba908f599c77ded892c34b2/pulsar-io/kinesis/pom.xml#L40-L49
 . The kinesis-kpl-shaded dependency isn't intended to be used externally. It's 
only used for the Kinesis IO connector.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to