[ https://issues.apache.org/jira/browse/FLINK-37672?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
ASF GitHub Bot updated FLINK-37672: ----------------------------------- Labels: pull-request-available (was: ) > Bump protobuf-maven-plugin from 0.5.1 to 0.6.1 > ---------------------------------------------- > > Key: FLINK-37672 > URL: https://issues.apache.org/jira/browse/FLINK-37672 > Project: Flink > Issue Type: Improvement > Reporter: Siddharth R > Priority: Major > Labels: pull-request-available > > Bumping the plugin version would remediate the findings in the dependencies: > Package details - > [https://mvnrepository.com/artifact/org.xolstice.maven.plugins/protobuf-maven-plugin/0.6.1] > > Vulnerabilities from dependencies: > [CVE-2023-2976|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2976] > [CVE-2020-8908|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8908] > [CVE-2020-15250|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15250] > [CVE-2018-10237|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10237] -- This message was sent by Atlassian Jira (v8.20.10#820010)