Skip to content

Comments

MLE-27155 : (CVE) MLCP - Apache Avro 1.11.4 - 7.3 HIGH#566

Merged
abika5 merged 1 commit intomarklogic:develop-11.3from
abika5:develop-11.3
Feb 17, 2026
Merged

MLE-27155 : (CVE) MLCP - Apache Avro 1.11.4 - 7.3 HIGH#566
abika5 merged 1 commit intomarklogic:develop-11.3from
abika5:develop-11.3

Conversation

@abika5
Copy link
Contributor

@abika5 abika5 commented Feb 16, 2026

I have upgraded the Avro version to a safer version suggested in CVE.

The following tests run successfully.

  1. MLCP unit tests
  2. 06mlcp,mlcp-semantics,mlcp-redaction,mlcp-bitemporal test suites

Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR upgrades Apache Avro from version 1.11.4 to 1.11.5 to address a high-severity CVE (CVE with 7.3 HIGH rating) in the MarkLogic Content Pump (MLCP) project. This is consistent with the project's ongoing practice of proactively addressing security vulnerabilities through dependency updates, as evidenced by similar upgrades in recent releases documented in the README.

Changes:

  • Upgraded Apache Avro dependency from 1.11.4 to 1.11.5 in pom.xml to mitigate security vulnerability

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Copy link
Contributor

@DarrenJAN DarrenJAN left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me. Thanks

@abika5 abika5 merged commit 5305841 into marklogic:develop-11.3 Feb 17, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants