apache / apache/amoro

[Improvement]: Fix some high CVEs

Open
#3,971 2 comments 0 reactions 1 assignee Claimed by @zhangwl9 View on GitHub
good first issue type:improvement
Dominant language
Java
Stars
1.2k
Forks
395
Avg merge
4d 10h
Merged PRs (30d)
33

Description

### Search before asking

- [x] I have searched in the [issues](https://github.com/apache/amoro/issues?q=is%3Aissue) and found no similar issues.

### What would you like to be improved?

There are currently some high-level vulnerabilities in Amoro that need to be fixed, for example:
- CVE-2024-51504: maven / org.apache.zookeeper/zookeeper / 3.9.1
- CVE-2025-52999: maven / com.fasterxml.jackson.core/jackson-core / 2.13.4, maven / com.fasterxml.jackson.core/jackson-core / 2.14.3
- CVE-2023-34455: maven / org.xerial.snappy/snappy-java / 1.1.8.4
- etc.

### How should we improve?

_No response_

### Are you willing to submit PR?

- [ ] Yes I am willing to submit a PR!

### Subtasks

_No response_

### Code of Conduct

- [x] I agree to follow this project's [Code of Conduct](https://www.apache.org/foundation/policies/conduct)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.