[Snyk] Security upgrade org.apache.kafka:connect-json from 3.9.1 to 4.0.2#134
[Snyk] Security upgrade org.apache.kafka:connect-json from 3.9.1 to 4.0.2#134
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924
|
This major version upgrade to Apache Kafka 4.0.x introduces significant and mandatory architectural changes that require careful planning and environment updates before upgrading. Key Breaking Changes:
Recommendation: Do not merge this upgrade without a comprehensive migration plan. The Kafka cluster must first be successfully migrated to KRaft mode, and the Connect worker environment must be upgraded to Java 17. Due to the scale of these prerequisite changes, this upgrade should be handled as a major project. Source: Apache Kafka 4.0 Release Announcement, Upgrade Guide
|
Snyk has created this PR to fix 1 vulnerabilities in the maven dependencies of this project.
Snyk changed the following file(s):
pom.xmlVulnerabilities that will be fixed with an upgrade:
SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924
3.9.1->4.0.2Major version upgradeProof of ConceptBreaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Allocation of Resources Without Limits or Throttling