Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upload connector to Confluent Hub #183

Open
ddonaghy-c opened this issue Dec 14, 2023 · 1 comment
Open

Upload connector to Confluent Hub #183

ddonaghy-c opened this issue Dec 14, 2023 · 1 comment

Comments

@ddonaghy-c
Copy link

Hey all

Congratulations on your recent new release. I'm just reaching out to see if you are interested in uploading this connector to a listing on the Confluent Hub; as I work with connector listings to the hub. If you are interested in having a listing I would advise the current released version has two HIGH level CVEs present:

GHSA-xpw8-rcwv-8f8p
https://avd.aquasec.com/nvd/cve-2023-1370

and as such Confluent security policy does not allow the upload of Critical or High CVEs to the hub. If these can be remediated with fixes as outlined in links above; or these vulnerabilities signed off as a false positive or valid but non exploitable within code we can upload this for you.

If you have any questions please let me know
Confluent Integrations Team

@berndruecker
Copy link
Collaborator

Hi @ddonaghy-c - thanks for reaching out pro-actively! Good to see the experience around the hub improved 👍

I am interested in updating out listing - and happy to tackle the CVE first. This is already patched in the zeebe-java-client 8.4.0-alpha, and we will see a release beginning of January. Once this is there I will update the dependency and do a new release, then the CVE should be gone (I also added the project to our internal Snyk scanning so I can check violations myself first). We can keep this issue open and use it for the update.

Quick question: Is there some way to see user data around the connector? The last time I asked I got a rough number checked manually by somebody - can I either get an update on it or probably some more in-depth data (ideally via Email)?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants