[Snyk] Security upgrade org.apache.kafka:connect-api from 3.9.1 to 4.2.0#128
[Snyk] Security upgrade org.apache.kafka:connect-api from 3.9.1 to 4.2.0#128
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-ORGLZ4-14151788 - https://snyk.io/vuln/SNYK-JAVA-ORGLZ4-14219384
|
This major version upgrade from a 3.x version to a 4.x version of Apache Kafka represents a significant architectural shift with substantial breaking changes. The provided versions Key Breaking Changes in Apache Kafka 4.0:
Recommendation: This upgrade cannot be performed as a simple dependency bump. It requires a planned and careful migration of your entire Kafka cluster from a ZooKeeper-based architecture to the new KRaft-based architecture. You must review the official Apache Kafka upgrade and migration guides for version 4.0 before proceeding. Source: Apache Kafka 4.0 Release Announcement, ZooKeeper to KRaft Migration Guide
|
Snyk has created this PR to fix 2 vulnerabilities in the maven dependencies of this project.
Snyk changed the following file(s):
pom.xmlVulnerabilities that will be fixed with an upgrade:
SNYK-JAVA-ORGLZ4-14151788
3.9.1->4.2.0Major version upgradeNo Known ExploitSNYK-JAVA-ORGLZ4-14219384
3.9.1->4.2.0Major version upgradeNo Known ExploitBreaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Out-of-bounds Read