Skip to content

MLE-31396 update tika to 3.3.2 - #663

Open
RitaChen609 wants to merge 4 commits into
developfrom
MLE-31396-update-tika-version
Open

MLE-31396 update tika to 3.3.2#663
RitaChen609 wants to merge 4 commits into
developfrom
MLE-31396-update-tika-version

Conversation

@RitaChen609

Copy link
Copy Markdown

Fixed BDSA-2026-3678 / CVE-2026-23907 in Apache PDFBox v3.0.7 by upgrading Tika to 3.3.2 since tika-parser-pdf-module:3.3.2 already depends on pdfbox:3.0.8 and pdfbox-tools:3.0.8 directly.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the Gradle-managed Apache Tika version used by Flux’s CLI distribution to pick up a newer PDFBox dependency via tika-parser-pdf-module, addressing the CVE called out in the PR description.

Changes:

  • Bump tikaVersion from 3.3.1 to 3.3.2 in gradle.properties.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

rjrudin
rjrudin previously approved these changes Jul 31, 2026
Comment thread gradle.properties
janinoVersion=3.1.12
langchain4jVersion=1.17.2
tikaVersion=3.3.1
tikaVersion=3.3.2

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This needs to be done in the Spark connector too since it depends on the core Tika library.

rjdew-progress
rjdew-progress previously approved these changes Aug 3, 2026
jonmille
jonmille previously approved these changes Aug 4, 2026
@RitaChen609
RitaChen609 dismissed stale reviews from jonmille and rjdew-progress via f22022a August 4, 2026 18:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants