Skip to content

fix: bump opennlp-tools to 2.5.9#7178

Merged
chillleader merged 1 commit into
stable/8.9from
cve-2026-42440-opennlp-8.9
May 12, 2026
Merged

fix: bump opennlp-tools to 2.5.9#7178
chillleader merged 1 commit into
stable/8.9from
cve-2026-42440-opennlp-8.9

Conversation

@chillleader
Copy link
Copy Markdown
Member

Summary

Bumps org.apache.opennlp:opennlp-tools from 2.5.4 to 2.5.9 via an explicit dependencyManagement override in parent/pom.xml. The artifact is pulled in transitively through Apache Tika in the embeddings-vector-database connector.

Security fix. Details in the internal tracking issue: camunda/team-connectors#1214

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@chillleader chillleader merged commit f31a8bb into stable/8.9 May 12, 2026
27 checks passed
@chillleader chillleader deleted the cve-2026-42440-opennlp-8.9 branch May 12, 2026 09:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants