kevinjqliu commented on code in PR #17336:
URL: https://github.com/apache/iceberg/pull/17336#discussion_r3659363517


##########
.github/trivyignore/spark-runtime-3.5.trivyignore:
##########
@@ -25,4 +25,3 @@
 # jackson-databind CVEs that are only fixed in jackson >= 2.18.8.
 CVE-2026-54512
 CVE-2026-54513
-GHSA-r7wm-3cxj-wff9

Review Comment:
   looks like this file is now empty, and we can either remove it completely or 
keep only a skeleton. but we should remove the lines about jackson



##########
.github/trivyignore/spark-runtime-3.5.trivyignore:
##########
@@ -22,7 +22,3 @@
 # compatibility with Spark 3.5. Newer Spark lines (4.0, 4.1) align Jackson to a
 # fixed version instead of ignoring the finding.
 #

Review Comment:
   ```suggestion
   ```
   outdated



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to