<a id="firebase-source-relnotes"></a>

# Changelog for Firebase Source and Sink Connector for Confluent Platform

## Version 1.2.20

* CC-43220: Bumped `com.fasterxml.jackson.core:jackson-core` to `2.22.1` to resolve GHSA-r7wm-3cxj-wff9
* CC-43136: Bumped `netty-codec` to `4.1.136-final` to resolve CVE-2026-59901

## Version 1.2.19

* CC-41445: Bumped `opentelemetry-api` to version `1.62.0` to resolve CVE-2026-45292
* CC-42305:  Bumped `jackson-databind` to version `2.21.5` to resolve CVE-2026-54518

## Version 1.2.18

* CC-40690: Bumped `log4j-core` to `2.25.4` to resolve CVE-2026-34477

## Version 1.2.17

* CC-41888: Bumped `netty-common` to `4.1.135-final` to resolve CVE-2026-45416
* CC-41680: Improved GCP credential handling to address a security weakness

## Version 1.2.16

* CC-41224: Bumped `netty-common` to `4.1.133-final` to resolve CVE-2026-42583

## Version 1.2.15

* CC-40247: Bumped `netty-common` to `4.1.132-final` to resolve CVE-2025-68161

## Version 1.2.14

* CC-39523: Bumped `com.fasterxml.jackson.core:jackson-core` to `2.21.1` to resolve GHSA-72hv-8253-57qq

## Version 1.2.13

* CC-39724: Fixed a gRPC initialization error caused by an incompatibility with Confluent Platform versions 8.1.x and later.

## Version 1.2.12

* CC-38388: Bumped `connect-ak-non-public` version to `0.72.0` to resolve CVE-2025-68161
* CC-38257: Bumped `common-plugin-parent` version to `0.9.42` to resolve CVE-2025-67735

## Version 1.2.11

* CC-38590: Bumped `common-plugin-parent` version to `0.9.40` to resolve CVE-2024-29371

## Version 1.2.10

* CC-36912: Bumped `grpc-netty-shaded` version to `1.75.0` to resolve CVE-2025-55163

## Version 1.2.9

* CC-36107: Bumped netty-common version to 4.1.125-final to resolve CVE

## Version 1.2.8

* CC-33732: Bumped connect-operation-http version to 2.5.1

## Version 1.2.7

* CC-33763: Removed usage of non public and deprecated APIs

## Version 1.2.6

* CC-32047: Bumped `netty-common` version to 4.1.118-final to resolve CVE-2025-24970

## Version 1.2.5

* CC-30413: Bumped `netty-common` version to 4.1.115-final to resolve CVE CVE-2024-47535

## Version 1.2.4

* CC-26378: Fix jos4j and netty-codec-http cve

## Version 1.2.3

* CC-24138: Filter credential file to avoid SSRF attack

## Version 1.2.2

* CC-23336: CVE fix for Jose4j
* CC-22947: CVE fix for Netty
* CC-21200: CVE fix for Firebase admin

## Version 1.2.1

* CCDB-5161: Fix CVE for jackson-databind
* CC-15890, CC-17367, CC-16851, CC-16571: Fix CVE’s
* Update Jenkinsfile Nodelabel
* CC-12525: Enable integration tests in Jenkins for Firebase
* MINOR: Update Jenkinsfile to change the slack channel
* MINOR: fix version for 1.1.x branch
* MINOR: upgrade jackson-databind and google-oauth-client
* Update docs URL path

## Version 1.2.0

* MINOR: Upgrade parent to 0.5.5 to fix commons codec CVE
* CC-12028: Google Firebase Sink CVEs
* Update pom.xml
* CC-7442: Promote Firebase connectors to PA
* MINOR: Correct module version in pom file
* MINOR: Remove prefix suffix from version in pom
* version fix(new release on 1.1.x)
