Skip to content

fix: bump opennlp-tools to 2.5.9#7179

Merged
chillleader merged 1 commit into
stable/8.8from
cve-2026-42440-opennlp-8.8
May 12, 2026
Merged

fix: bump opennlp-tools to 2.5.9#7179
chillleader merged 1 commit into
stable/8.8from
cve-2026-42440-opennlp-8.8

Conversation

@chillleader
Copy link
Copy Markdown
Member

Summary

Bumps org.apache.opennlp:opennlp-tools from 2.5.4 to 2.5.9 via an explicit dependencyManagement override in parent/pom.xml. The artifact is pulled in transitively through Apache Tika in the embeddings-vector-database connector.

Security fix. Details in the internal tracking issue: camunda/team-connectors#1214

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@chillleader chillleader merged commit a4ae29b into stable/8.8 May 12, 2026
24 checks passed
@chillleader chillleader deleted the cve-2026-42440-opennlp-8.8 branch May 12, 2026 09:02
@github-actions
Copy link
Copy Markdown
Contributor

🎉 This pull request has been included in release 8.8.12!

Thank you for your contribution! 🚀

@github-actions github-actions Bot added the version:8.8.12 Released in version 8.8.12 label May 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

version:8.8.12 Released in version 8.8.12

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants