Merge branch 'cassandra-4.1' into cassandra-5.0

This commit is contained in:
Stefan Miklosovic 2025-04-02 12:06:09 +02:00
commit 7076623ac7
No known key found for this signature in database
GPG Key ID: 32F35CB2F546D93E
3 changed files with 9 additions and 0 deletions

View File

@ -38,6 +38,12 @@
<cve>CVE-2023-44487</cve>
</suppress>
<!-- https://issues.apache.org/jira/browse/CASSANDRA-20504 -->
<suppress>
<packageUrl regex="true">^pkg:maven/io\.netty/netty\-.*@.*$</packageUrl>
<cve>CVE-2025-25193</cve>
</suppress>
<!-- https://issues.apache.org/jira/browse/CASSANDRA-17966 -->
<suppress>
<packageUrl regex="true">^pkg:maven/com\.fasterxml\.jackson\.core/jackson\-databind@.*$</packageUrl>

2
.snyk
View File

@ -34,3 +34,5 @@ ignore:
- reason: Suppressed due to internal review, see project's .build/dependency-check-suppressions.xml
CVE-2024-45772:
- reason: https://issues.apache.org/jira/browse/CASSANDRA-20024 -- ^pkg:maven/org\.apache\.lucene/lucene\-.*@9.7.0$
CVE-2025-25193:
- reason: https://issues.apache.org/jira/browse/CASSANDRA-20504 -- ^pkg:maven/io\.netty/netty\-.*@.*$

View File

@ -22,6 +22,7 @@ Merged from 4.1:
* Fix SimpleClient ability to release acquired capacity (CASSANDRA-20202)
* Fix WaitQueue.Signal.awaitUninterruptibly may block forever if invoking thread is interrupted (CASSANDRA-20084)
Merged from 4.0:
* Suppress CVE-2025-25193 (CASSANDRA-20504)
* Include in source tree and build packages a Snyk policy file that lists known false positives (CASSANDRA-20319)
* Update zstd-jni to 1.5.7-2 (CASSANDRA-20453)
* Suppress CVE-2024-12801 (CASSANDRA-20412)