[improve][broker] Upgrade avro version to 1.12.0 (#24617)
[improve][broker] Upgrade bookkeeper to 4.17.2/commons-configuration to 2.x/grpc to 1.72.0 and enable ZooKeeper client to establish connection in read-only mode (#24468)
[fix][sec] Bump commons-io version to 2.18.0 (#23684)
[fix][sec] Mitigate CVE-2024-53990 by disabling AsyncHttpClient CookieStore (#23725)
[fix][sec] Remove dependency on out-dated commons-configuration 1.x (#24562)
[fix][sec] Replace bcprov-jdk15on dependency with bcprov-jdk18-on (#23532)
[fix][sec] Upgrade async-http-client to 2.12.4 to address CVE-2024-53990 (#23732)
[fix][sec] Upgrade bouncycastle bcpkix-fips version to 1.79 to address CVE-2025-8916 (#24650)
[fix][sec] Upgrade golang.org/x/crypto from 0.21.0 to 0.31.0 in pulsar-function-go (#23743)
[fix][sec] Upgrade Jetty to 9.4.57.v20241219 to mitigate CVE-2024-6763 (#24232)
[fix][sec] Upgrade jwt/v5 to 5.2.2 to address CVE-2025-30204 (#24140)
[fix][sec] Upgrade Kafka connector and clients version to 3.9.1 to address CVE-2025-27818 (#24564)
[fix][sec] Upgrade pulsar-function-go dependencies to address CVE-2025-22868 (#24547)
[fix][sec] Upgrade to Netty 4.1.115.Final to address CVE-2024-47535 (#23596)