Update dependency org.apache.hive:hive-exec to v4 #61
Security Report
❗️Scan Warnings: The scan completed with warnings. The integration encountered issues with one or more projects in this repository. Consequently, there may be gaps in the coverage of open-source dependencies used in the repository.
Scan Details Report
maven
/tmp/ws-scm/flink/flink-connectors/flink-sql-connector-hbase-1.4/pom.xml
| Step | Level | Description | Details |
|---|---|---|---|
| Preparing the project for scan | ⚠Warn | One or more of the installations failed | [ERROR] Failed to execute goal on project flink-sql-connector-hbase-1.4: Could not resolve dependencies for project org.apache.flink:flink-sql-connector-hbase-1.4:jar:1.18-SNAPSHOT |
| Resolving the project | ⚠Warn | Some problems occurred while performing the resolution operation |
|
/tmp/ws-scm/flink/flink-connectors/flink-sql-connector-hbase-2.2/pom.xml
| Step | Level | Description | Details |
|---|---|---|---|
| Preparing the project for scan | ⚠Warn | One or more of the installations failed | [ERROR] Failed to execute goal on project flink-sql-connector-hbase-2.2: Could not resolve dependencies for project org.apache.flink:flink-sql-connector-hbase-2.2:jar:1.18-SNAPSHOT |
| Resolving the project | ⚠Warn | Some problems occurred while performing the resolution operation |
|
/tmp/ws-scm/flink/flink-connectors/flink-sql-connector-hive-2.3.9/pom.xml
| Step | Level | Description | Details |
|---|---|---|---|
| Preparing the project for scan | ⚠Warn | One or more of the installations failed | [ERROR] Failed to execute goal on project flink-sql-connector-hive-2.3.9_2.12: Could not resolve dependencies for project org.apache.flink:flink-sql-connector-hive-2.3.9_2.12:jar:1.18-SNAPSHOT |
| Resolving the project | ⚠Warn | Some problems occurred while performing the resolution operation |
|
/tmp/ws-scm/flink/flink-connectors/flink-sql-connector-hive-3.1.3/pom.xml
| Step | Level | Description | Details |
|---|---|---|---|
| Preparing the project for scan | ⚠Warn | One or more of the installations failed | [ERROR] Failed to execute goal on project flink-sql-connector-hive-3.1.3_2.12: Could not resolve dependencies for project org.apache.flink:flink-sql-connector-hive-3.1.3_2.12:jar:1.18-SNAPSHOT |
| Resolving the project | ⚠Warn | Some problems occurred while performing the resolution operation |
|
/tmp/ws-scm/flink/flink-connectors/flink-sql-connector-kafka/pom.xml
| Step | Level | Description | Details |
|---|---|---|---|
| Preparing the project for scan | ⚠Warn | One or more of the installations failed | [ERROR] Failed to execute goal on project flink-sql-connector-kafka: Could not resolve dependencies for project org.apache.flink:flink-sql-connector-kafka:jar:1.18-SNAPSHOT |
| Resolving the project | ⚠Warn | Some problems occurred while performing the resolution operation |
|
/tmp/ws-scm/flink/flink-formats/flink-sql-avro-confluent-registry/pom.xml
| Step | Level | Description | Details |
|---|---|---|---|
| Preparing the project for scan | ⚠Warn | One or more of the installations failed | [ERROR] Failed to execute goal on project flink-sql-avro-confluent-registry: Could not resolve dependencies for project org.apache.flink:flink-sql-avro-confluent-registry:jar:1.18-SNAPSHOT |
| Resolving the project | ⚠Warn | Some problems occurred while performing the resolution operation |
|
/tmp/ws-scm/flink/flink-formats/flink-sql-avro/pom.xml
| Step | Level | Description | Details |
|---|---|---|---|
| Preparing the project for scan | ⚠Warn | One or more of the installations failed | [ERROR] Failed to execute goal on project flink-sql-avro: Could not resolve dependencies for project org.apache.flink:flink-sql-avro:jar:1.18-SNAPSHOT |
| Resolving the project | ⚠Warn | Some problems occurred while performing the resolution operation |
|
/tmp/ws-scm/flink/flink-formats/flink-sql-csv/pom.xml
| Step | Level | Description | Details |
|---|---|---|---|
| Preparing the project for scan | ⚠Warn | One or more of the installations failed | [ERROR] Failed to execute goal on project flink-sql-csv: Could not resolve dependencies for project org.apache.flink:flink-sql-csv:jar:1.18-SNAPSHOT |
| Resolving the project | ⚠Warn | Some problems occurred while performing the resolution operation |
|
/tmp/ws-scm/flink/flink-formats/flink-sql-json/pom.xml
| Step | Level | Description | Details |
|---|---|---|---|
| Preparing the project for scan | ⚠Warn | One or more of the installations failed | [ERROR] Failed to execute goal on project flink-sql-json: Could not resolve dependencies for project org.apache.flink:flink-sql-json:jar:1.18-SNAPSHOT |
| Resolving the project | ⚠Warn | Some problems occurred while performing the resolution operation |
|
/tmp/ws-scm/flink/flink-formats/flink-sql-orc/pom.xml
| Step | Level | Description | Details |
|---|---|---|---|
| Preparing the project for scan | ⚠Warn | One or more of the installations failed | [ERROR] Failed to execute goal on project flink-sql-orc: Could not resolve dependencies for project org.apache.flink:flink-sql-orc:jar:1.18-SNAPSHOT |
| Resolving the project | ⚠Warn | Some problems occurred while performing the resolution operation |
|
/tmp/ws-scm/flink/flink-formats/flink-sql-parquet/pom.xml
| Step | Level | Description | Details |
|---|---|---|---|
| Preparing the project for scan | ⚠Warn | One or more of the installations failed | [ERROR] Failed to execute goal on project flink-sql-parquet: Could not resolve dependencies for project org.apache.flink:flink-sql-parquet:jar:1.18-SNAPSHOT |
| Resolving the project | ⚠Warn | Some problems occurred while performing the resolution operation |
|
/tmp/ws-scm/flink/flink-formats/flink-sql-protobuf/pom.xml
| Step | Level | Description | Details |
|---|---|---|---|
| Preparing the project for scan | ⚠Warn | One or more of the installations failed | [ERROR] Failed to execute goal on project flink-sql-protobuf: Could not resolve dependencies for project org.apache.flink:flink-sql-protobuf:jar:1.18-SNAPSHOT |
| Resolving the project | ⚠Warn | Some problems occurred while performing the resolution operation |
|
/tmp/ws-scm/flink/flink-quickstart/flink-quickstart-java/src/main/resources/archetype-resources/pom.xml
| Step | Level | Description | Details |
|---|---|---|---|
| Preparing the project for scan | ⚠Warn | One or more of the installations failed | [ERROR] [ERROR] Some problems were encountered while processing the POMs: [WARNING] 'groupId' contains an expression but should be a constant. @ ${groupId}:${artifactId}:${version}, /tmp/ws-scm/flink/flink-quickstart/flink-quickstart-java/src/main/resources/archetype-resources/pom.xml, line 23, column 11 [WARNING] 'artifactId' contains an expression but should be a constant. @ ${groupId}:${arti... |
| Resolving the project | ⚠Warn | Some problems occurred while performing the resolution operation |
|
/tmp/ws-scm/flink/flink-walkthroughs/flink-walkthrough-datastream-java/src/main/resources/archetype-resources/pom.xml
| Step | Level | Description | Details |
|---|---|---|---|
| Preparing the project for scan | ⚠Warn | One or more of the installations failed | [ERROR] [ERROR] Some problems were encountered while processing the POMs: [WARNING] 'groupId' contains an expression but should be a constant. @ ${groupId}:${artifactId}:${version}, /tmp/ws-scm/flink/flink-walkthroughs/flink-walkthrough-datastream-java/src/main/resources/archetype-resources/pom.xml, line 23, column 11 [WARNING] 'artifactId' contains an expression but should be a constant. @ ${g... |
| Resolving the project | ⚠Warn | Some problems occurred while performing the resolution operation |
|
/tmp/ws-scm/flink/pom.xml
| Step | Level | Description | Details |
|---|---|---|---|
| Preparing the project for scan | ⚠Warn | One or more of the installations failed | [ERROR] Failed to execute goal on project flink-parent: Could not resolve dependencies for project org.apache.flink:flink-parent:pom:1.18-SNAPSHOT |
| Resolving the project | ⚠Warn | Some problems occurred while performing the resolution operation |
|
pip
/tmp/ws-scm/flink/flink-python
| Step | Level | Description | Details |
|---|---|---|---|
| Resolving the project | ⚠Warn | Some problems occurred while performing the resolution operation |
|
/tmp/ws-scm/flink/flink-python/apache-flink-libraries
| Step | Level | Description | Details |
|---|---|---|---|
| Resolving the project | ⚠Warn | Some problems occurred while performing the resolution operation |
|
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|---|
CVE-2024-52338Path to dependency file: /flink-python/dev/dev-requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225220351_UBCIAK/python_ZCRQPL/20260225220351/pyarrow-8.0.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl Dependency Hierarchy: -> ❌ pyarrow-8.0.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
9.8 | Direct pyarrow-8.0.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
pyarrow-8.0.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | 17.0.0 | None | ||
CVE-2023-47248Path to dependency file: /flink-python/dev/dev-requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225220351_UBCIAK/python_ZCRQPL/20260225220351/pyarrow-8.0.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl Dependency Hierarchy: -> ❌ pyarrow-8.0.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
9.8 | Direct pyarrow-8.0.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
pyarrow-8.0.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | 14.0.1 | None | ||
CVE-2026-0994Path to dependency file: /flink-python/dev/dev-requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225220351_UBCIAK/python_ZCRQPL/20260225220351/protobuf-3.20.3-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl Dependency Hierarchy: -> ❌ protobuf-3.20.3-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl (Vulnerable Library) |
8.6 | Direct protobuf-3.20.3-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl |
protobuf-3.20.3-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl | None | |||
CVE-2025-4565Path to dependency file: /flink-python/dev/dev-requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225220351_UBCIAK/python_ZCRQPL/20260225220351/protobuf-3.20.3-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl Dependency Hierarchy: -> ❌ protobuf-3.20.3-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl (Vulnerable Library) |
7.5 | Direct protobuf-3.20.3-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl |
protobuf-3.20.3-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl | 4.25.8 | None | ||
CVE-2023-33953Path to dependency file: /flink-python/dev/dev-requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225220351_UBCIAK/python_ZCRQPL/20260225220351/grpcio-1.46.3-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl Dependency Hierarchy: -> ❌ grpcio-1.46.3-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
7.5 | Direct grpcio-1.46.3-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
grpcio-1.46.3-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | grpc - 1.53.2,grpcio - 1.54.3,grpcio - 1.56.2,grpcio - 1.53.2,grpc - 1.54.3,grpc - 1.56.2 | None | ||
CVE-2023-1428Path to dependency file: /flink-python/dev/dev-requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225220351_UBCIAK/python_ZCRQPL/20260225220351/grpcio-1.46.3-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl Dependency Hierarchy: -> ❌ grpcio-1.46.3-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
7.5 | Direct grpcio-1.46.3-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
grpcio-1.46.3-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | 1.53.0 | None | ||
CVE-2023-32731Path to dependency file: /flink-python/dev/dev-requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225220351_UBCIAK/python_ZCRQPL/20260225220351/grpcio-1.46.3-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl Dependency Hierarchy: -> ❌ grpcio-1.46.3-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
7.4 | Direct grpcio-1.46.3-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
grpcio-1.46.3-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | 1.53.0 | None | ||
CVE-2021-41496Path to dependency file: /flink-python/dev/dev-requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225220351_UBCIAK/python_ZCRQPL/20260225220351/numpy-1.21.6-cp39-cp39-manylinux_2_12_x86_64.manylinux2010_x86_64.whl Dependency Hierarchy: -> ❌ numpy-1.21.6-cp39-cp39-manylinux_2_12_x86_64.manylinux2010_x86_64.whl (Vulnerable Library) |
5.5 | Direct numpy-1.21.6-cp39-cp39-manylinux_2_12_x86_64.manylinux2010_x86_64.whl |
numpy-1.21.6-cp39-cp39-manylinux_2_12_x86_64.manylinux2010_x86_64.whl | https://github.com/numpy/numpy.git - no_fix | None | ||
CVE-2023-32732Path to dependency file: /flink-python/dev/dev-requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225220351_UBCIAK/python_ZCRQPL/20260225220351/grpcio-1.46.3-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl Dependency Hierarchy: -> ❌ grpcio-1.46.3-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
5.3 | Direct grpcio-1.46.3-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
grpcio-1.46.3-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | grpc - 1.53.0,grpc - 1.53.0 | None | ||
CVE-2021-41495Path to dependency file: /flink-python/dev/dev-requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225220351_UBCIAK/python_ZCRQPL/20260225220351/numpy-1.21.6-cp39-cp39-manylinux_2_12_x86_64.manylinux2010_x86_64.whl Dependency Hierarchy: -> ❌ numpy-1.21.6-cp39-cp39-manylinux_2_12_x86_64.manylinux2010_x86_64.whl (Vulnerable Library) |
5.3 | Direct numpy-1.21.6-cp39-cp39-manylinux_2_12_x86_64.manylinux2010_x86_64.whl |
numpy-1.21.6-cp39-cp39-manylinux_2_12_x86_64.manylinux2010_x86_64.whl | https://github.com/numpy/numpy.git - no_fix | None | ||
CVE-2024-5629Path to dependency file: /flink-python/dev/dev-requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225220351_UBCIAK/python_ZCRQPL/20260225220351/pymongo-3.13.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl Dependency Hierarchy: -> apache_beam-2.43.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Root Library) -> ❌ pymongo-3.13.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
4.7 | Transitive pymongo-3.13.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
apache_beam-2.43.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | Transitive 4.6.3 |
None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| GHSA-36jr-mh4h-2g58 | d3-color-1.4.1.tgz |
| CVE-2026-0994 | protobuf-3.20.3-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.whl |
| CVE-2021-41496 | numpy-1.21.6-cp37-cp37m-manylinux_2_12_x86_64.manylinux2010_x86_64.whl |
| CVE-2025-4565 | protobuf-3.20.3-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.whl |
| CVE-2023-47248 | pyarrow-8.0.0-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2025-66471 | urllib3-2.0.7-py3-none-any.whl |
| CVE-2020-8908 | guava-27.0.1-jre.jar |
| CVE-2021-41495 | numpy-1.21.6-cp37-cp37m-manylinux_2_12_x86_64.manylinux2010_x86_64.whl |
| CVE-2024-37891 | pip-24.0-py3-none-any.whl |
| CVE-2023-1428 | grpcio-1.46.3-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2025-50181 | urllib3-2.0.7-py3-none-any.whl |
| CVE-2026-21441 | urllib3-2.0.7-py3-none-any.whl |
| CVE-2024-27454 | orjson-3.9.7-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2025-47273 | setuptools-68.0.0-py3-none-any.whl |
| CVE-2024-47081 | requests-2.31.0-py3-none-any.whl |
| CVE-2025-50182 | urllib3-2.0.7-py3-none-any.whl |
| CVE-2024-5629 | pymongo-3.13.0-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2026-24049 | wheel-0.42.0-py3-none-any.whl |
| CVE-2024-52338 | pyarrow-8.0.0-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2024-5569 | zipp-3.15.0-py3-none-any.whl |
| CVE-2023-33953 | grpcio-1.46.3-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2023-32732 | grpcio-1.46.3-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2023-32731 | grpcio-1.46.3-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
Base branch total remaining vulnerabilities: 49
Base branch commit: a9b113119f373a0311e02e140a1342e959059bdf
Total libraries scanned: 213
Scan token: 718b76a37fea402ca1440bcfd9ef31de