Siddharth R created FLINK-37672: ----------------------------------- Summary: Bump protobuf-maven-plugin from 0.5.1 to 0.6.1 Key: FLINK-37672 URL: https://issues.apache.org/jira/browse/FLINK-37672 Project: Flink Issue Type: Improvement Reporter: Siddharth R
Bumping the plugin version would remediate the findings in the dependencies: Package details - [https://mvnrepository.com/artifact/org.xolstice.maven.plugins/protobuf-maven-plugin/0.6.1] Vulnerabilities from dependencies: [CVE-2023-2976|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2976] [CVE-2020-8908|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8908] [CVE-2020-15250|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15250] [CVE-2018-10237|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10237] -- This message was sent by Atlassian Jira (v8.20.10#820010)