Unsubscribe

On Thu, Oct 8, 2026, 10:33 Pratham Kumar P via user <[email protected]>
wrote:

> Hello,
>
>
>
> I am writing to inquire about the maintenance state of the 1.11.x branch
> regarding a dependency vulnerability security scan.
>
>
>
> We are currently pinned to *avro-compiler* version 1.11.5. Our security
> scanners are flagging a transitive vulnerability brought in via *Apache
> Velocity Engine*. The version of Velocity Engine (2.3) pulled in by Avro
> 1.11.5 triggers these alerts.
>
>
>
> Could you please clarify if the community intends to release *Avro 1.11.6*
> specifically to bump the underlying Velocity Engine dependency to version
> 2.4.1?
>
>
>
> Thank you,
>
> Pratham
>

Reply via email to