Skip to content

DAOS-18603 cq: suppress CVE-2025-33042#17581

Open
grom72 wants to merge 1 commit intomasterfrom
grom72/DAOS-18603-trivy-avro-1.11.4-suppress
Open

DAOS-18603 cq: suppress CVE-2025-33042#17581
grom72 wants to merge 1 commit intomasterfrom
grom72/DAOS-18603-trivy-avro-1.11.4-suppress

Conversation

@grom72
Copy link
Contributor

@grom72 grom72 commented Feb 19, 2026

Suppress avro:1.11.4 vulnerability inherited from Hadoop as there is no new version of Hadoop

Signed-off-by: Tomasz Gromadzki tomasz.gromadzki@hpe.com

Steps for the author:

  • Commit message follows the guidelines.
  • Appropriate Features or Test-tag pragmas were used.
  • Appropriate Functional Test Stages were run.
  • At least two positive code reviews including at least one code owner from each category referenced in the PR.
  • Testing is complete. If necessary, forced-landing label added and a reason added in a comment.

After all prior steps are complete:

  • Gatekeeper requested (daos-gatekeeper added as a reviewer).

Suppress avro:1.11.4 vulnerability inherited from hadoop as there is no
new version of hadoop

Signed-off-by: Tomasz Gromadzki <tomasz.gromadzki@hpe.com>

Doc-only: true
@github-actions
Copy link

Ticket title is 'java: trivy vulnerability in avro 1.11.4'
Status is 'In Review'
Labels: 'request_for_2.6.5'
https://daosio.atlassian.net/browse/DAOS-18603

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

Comments