Siddharth R created FLINK-37672:
-----------------------------------
Summary: Bump protobuf-maven-plugin from 0.5.1 to 0.6.1
Key: FLINK-37672
URL: https://issues.apache.org/jira/browse/FLINK-37672
Project: Flink
Issue Type: Improvement
Reporter: Siddharth R
Bumping the plugin version would remediate the findings in the dependencies:
Package details -
[https://mvnrepository.com/artifact/org.xolstice.maven.plugins/protobuf-maven-plugin/0.6.1]
Vulnerabilities from dependencies:
[CVE-2023-2976|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2976]
[CVE-2020-8908|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8908]
[CVE-2020-15250|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15250]
[CVE-2018-10237|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10237]
--
This message was sent by Atlassian Jira
(v8.20.10#820010)