-
Notifications
You must be signed in to change notification settings - Fork 1.8k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Dependencies] Update dependencies with CVEs. #646
Comments
We also need to upgrade the Hadoop version used in the #645 incorrectly updated the So we should upgrade the Hadoop version to 2.10.1 instead. For more details see https://bugzilla.redhat.com/show_bug.cgi?id=1883549 In addition to the above, we also need to upgrade the following dependencies,
Reopening the issue and adding |
Need to update the following dependencies as well:
|
Resolving the issue as all related CVE PRs are merged. |
|
Describe the bug
The hdfs-fixture used for integration tests has the following dependency.
org.apache.hadoop:hadoop-minicluster:2.8.5
The above version of
hadoop-minicluster
brings in some other dependencies that are reported to have potential security vulnerabilities.We need to update the
hadoop-minicluster
to the latest version3.3.0
The text was updated successfully, but these errors were encountered: