Skip to content

DAOS-18603 cq: suppress CVE-2025-33042#17582

Merged
mchaarawi merged 1 commit intorelease/2.6from
grom72/DAOS-18603-trivy-avro-1.11.4-suppress-2.6
Feb 20, 2026
Merged

DAOS-18603 cq: suppress CVE-2025-33042#17582
mchaarawi merged 1 commit intorelease/2.6from
grom72/DAOS-18603-trivy-avro-1.11.4-suppress-2.6

Conversation

@grom72
Copy link
Contributor

@grom72 grom72 commented Feb 19, 2026

Suppress avro:1.11.4 vulnerability inherited from Hadoop as there is no new version of HadoopI

Signed-off-by: Tomasz Gromadzki tomasz.gromadzki@hpe.com

Steps for the author:

  • Commit message follows the guidelines.
  • Appropriate Features or Test-tag pragmas were used.
  • Appropriate Functional Test Stages were run.
  • At least two positive code reviews including at least one code owner from each category referenced in the PR.
  • Testing is complete. If necessary, forced-landing label added and a reason added in a comment.

After all prior steps are complete:

  • Gatekeeper requested (daos-gatekeeper added as a reviewer).

Suppress avro:1.11.4 vulnerability inherited from Hadoop as there is no
new version of HadoopI

Signed-off-by: Tomasz Gromadzki <tomasz.gromadzki@hpe.com>

Doc-only: true
@github-actions
Copy link

Ticket title is 'java: trivy vulnerability in avro 1.11.4'
Status is 'In Review'
Labels: 'request_for_2.6.5'
https://daosio.atlassian.net/browse/DAOS-18603

@grom72 grom72 requested a review from a team February 20, 2026 09:47
@mchaarawi mchaarawi merged commit e5171ce into release/2.6 Feb 20, 2026
34 checks passed
@mchaarawi mchaarawi deleted the grom72/DAOS-18603-trivy-avro-1.11.4-suppress-2.6 branch February 20, 2026 12:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

Comments