Hello, I am writing to inquire about the maintenance state of the 1.11.x branch regarding a dependency vulnerability security scan.
We are currently pinned to avro-compiler version 1.11.5. Our security scanners are flagging a transitive vulnerability brought in via Apache Velocity Engine. The version of Velocity Engine (2.3) pulled in by Avro 1.11.5 triggers these alerts. Could you please clarify if the community intends to release Avro 1.11.6 specifically to bump the underlying Velocity Engine dependency to version 2.4.1? Thank you, Pratham
