r-sidd opened a new pull request, #1167: URL: https://github.com/apache/flink-kubernetes-operator/pull/1167
## What is the purpose of the change Bump postgresql jdbc driver version to 42.7.13 ## Brief change log The current version 42.5.6 has a direct vulnerability - CVE-2026-42198 (CVSS 7.5 HIGH). A malicious server can instruct the driver to perform SCRAM-SHA-256 authentication with a very large iteration count, causing excessive CPU usage and denial-of-service against connection pools. To remediate this, upgrade to latest 42.7.13. **Current** - Maven Repository: org.postgresql » postgresql » 42.5.6 **Latest** - Maven Repository: org.postgresql » postgresql » 42.7.13 Note: postgresql is declared `<scope>test</scope>` in `flink-autoscaler-plugin-jdbc` and is not bundled in any release artifact, so no NOTICE update is required. ## Verifying this change This change is a trivial rework / code cleanup without any test coverage. ## Does this pull request potentially affect one of the following parts: - Dependencies (does it add or upgrade a dependency): **yes** - The public API, i.e., is any changes to the `CustomResourceDescriptors`: **no** - Core observer or reconciler logic that is regularly executed: **no** ## Documentation - Does this pull request introduce a new feature? **no** - If yes, how is the feature documented? not applicable -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
