mirror of https://github.com/apache/cassandra
Merge branch 'cassandra-4.0' into cassandra-4.1
This commit is contained in:
commit
49ec0dc692
|
|
@ -50,6 +50,7 @@
|
|||
<cve>CVE-2022-41881</cve>
|
||||
<cve>CVE-2023-34462</cve>
|
||||
<cve>CVE-2023-44487</cve>
|
||||
<cve>CVE-2025-25193</cve>
|
||||
</suppress>
|
||||
<!-- https://issues.apache.org/jira/browse/CASSANDRA-17966 -->
|
||||
<suppress>
|
||||
|
|
|
|||
2
.snyk
2
.snyk
|
|
@ -52,3 +52,5 @@ ignore:
|
|||
- reason: Suppressed due to internal review, see project's .build/dependency-check-suppressions.xml
|
||||
CVE-2024-12801:
|
||||
- reason: Suppressed due to internal review, see project's .build/dependency-check-suppressions.xml
|
||||
CVE-2025-25193:
|
||||
- reason: netty's http stuff is not applicable here -- ^pkg:maven/io\.netty/netty\-all@.*$
|
||||
|
|
|
|||
|
|
@ -4,6 +4,7 @@
|
|||
* Fix SimpleClient ability to release acquired capacity (CASSANDRA-20202)
|
||||
* Fix WaitQueue.Signal.awaitUninterruptibly may block forever if invoking thread is interrupted (CASSANDRA-20084)
|
||||
Merged from 4.0:
|
||||
* Suppress CVE-2025-25193 (CASSANDRA-20504)
|
||||
* Include in source tree and build packages a Snyk policy file that lists known false positives (CASSANDRA-20319)
|
||||
* Update zstd-jni to 1.5.7-2 (CASSANDRA-20453)
|
||||
* Suppress CVE-2024-12801 (CASSANDRA-20412)
|
||||
|
|
|
|||
Loading…
Reference in New Issue