Unsubscribe On Thu, Oct 8, 2026, 10:33 Pratham Kumar P via user <[email protected]> wrote:
> Hello, > > > > I am writing to inquire about the maintenance state of the 1.11.x branch > regarding a dependency vulnerability security scan. > > > > We are currently pinned to *avro-compiler* version 1.11.5. Our security > scanners are flagging a transitive vulnerability brought in via *Apache > Velocity Engine*. The version of Velocity Engine (2.3) pulled in by Avro > 1.11.5 triggers these alerts. > > > > Could you please clarify if the community intends to release *Avro 1.11.6* > specifically to bump the underlying Velocity Engine dependency to version > 2.4.1? > > > > Thank you, > > Pratham >
