Hi Apoorv

grype on 4.2 shows these dependency CVEs not yet on the 4.2.2 plan:

jline 3.30.4 -> 3.30.14 CVE-2026-56740/56741
jetty 12.0.34 -> 12.0.37 CVE-2026-10050/10051/8384/6790
lz4-java 1.10.1 -> 1.11.2 CVE-2026-59949

Should we fix them for 4.2.2?

Best,
Chia-Ping


Chia-Ping Tsai <[email protected]> 於 2026年9月2日週三 下午10:18寫道:

> Hi Apoorv
>
> thanks for the plan. It is great!
>
> typo: Septmber
>
>
> Bill Bejeck <[email protected]> 於 2026年9月2日週三 下午9:46寫道:
>
>> Thanks for volunteering Apoorv!
>>
>> It's +1 from me for the release plan.
>>
>> -Bill
>>
>> On Tue, Sep 1, 2026 at 11:08 AM Apoorv Mittal <[email protected]>
>> wrote:
>>
>> > Hi all,
>> >
>> > I’ll be the release manager for the 4.2.2 bug fix release.
>> >
>> > Here's the 4.2.2 release plan
>> > <
>> >
>> >
>> https://cwiki.apache.org/confluence/spaces/KAFKA/pages/451971202/Release+Plan+4.2.2
>> > >.
>> >
>> > The code freeze date will be on Tuesday 15 September 2026 (I kept it 2
>> > weeks from now as there is only 1 outstanding issue currently to be
>> > resolved and 4.3.2 release to follow shortly as well).
>> >
>> > The first release candidate will follow shortly after that.
>> >
>> > Please let me know if you have any concerns about the schedule.
>> >
>> > Regards,
>> > Apoorv Mittal
>> >
>>
>

Reply via email to