<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Databricks JDBC Driver 2.6.36 includes dependencies in pom.properties with vulnerabilities in Get Started Discussions</title>
    <link>https://community.databricks.com/t5/get-started-discussions/databricks-jdbc-driver-2-6-36-includes-dependencies-in-pom/m-p/55553#M2031</link>
    <description>&lt;P&gt;I didn't find where to open an issue (GitHub or Jira). Please, let me know if I need to report it somewhere else.&lt;/P&gt;</description>
    <pubDate>Wed, 20 Dec 2023 11:45:25 GMT</pubDate>
    <dc:creator>Oleksandr</dc:creator>
    <dc:date>2023-12-20T11:45:25Z</dc:date>
    <item>
      <title>Databricks JDBC Driver 2.6.36 includes dependencies in pom.properties with vulnerabilities</title>
      <link>https://community.databricks.com/t5/get-started-discussions/databricks-jdbc-driver-2-6-36-includes-dependencies-in-pom/m-p/55552#M2030</link>
      <description>&lt;P&gt;Starting from&amp;nbsp;Databricks JDBC Driver 2.6.36 we've got Trivy security report with vulnerabilities from pom.properties.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;2.6.36 adds org.apache.commons.commons-compress:1.20 and&amp;nbsp;ch.qos.logback.logback-classic:1.2.3.&lt;BR /&gt;2.6.34 doesn't include such dependencies.&lt;BR /&gt;I'm wondering why we added it. I don't see any transitive dependencies and those jars are not in classpath but&amp;nbsp;META-INF/pom.propetries are still present.&lt;/P&gt;&lt;P&gt;I don't think it's a vulnerability but such&amp;nbsp;pom.propetries should be cleaned up or updated. Not sure why such changes were added to a path version. Also, I see that&amp;nbsp;2.6.35 is missing, so it might be some problems with the build process&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 11:44:10 GMT</pubDate>
      <guid>https://community.databricks.com/t5/get-started-discussions/databricks-jdbc-driver-2-6-36-includes-dependencies-in-pom/m-p/55552#M2030</guid>
      <dc:creator>Oleksandr</dc:creator>
      <dc:date>2023-12-20T11:44:10Z</dc:date>
    </item>
    <item>
      <title>Re: Databricks JDBC Driver 2.6.36 includes dependencies in pom.properties with vulnerabilities</title>
      <link>https://community.databricks.com/t5/get-started-discussions/databricks-jdbc-driver-2-6-36-includes-dependencies-in-pom/m-p/55553#M2031</link>
      <description>&lt;P&gt;I didn't find where to open an issue (GitHub or Jira). Please, let me know if I need to report it somewhere else.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 11:45:25 GMT</pubDate>
      <guid>https://community.databricks.com/t5/get-started-discussions/databricks-jdbc-driver-2-6-36-includes-dependencies-in-pom/m-p/55553#M2031</guid>
      <dc:creator>Oleksandr</dc:creator>
      <dc:date>2023-12-20T11:45:25Z</dc:date>
    </item>
  </channel>
</rss>

