Skip to content

HADOOP-19786 dependcy-check-version update#8404

Open
edwardcapriolo wants to merge 1 commit intoapache:trunkfrom
edwardcapriolo:HADOOP-19786-a
Open

HADOOP-19786 dependcy-check-version update#8404
edwardcapriolo wants to merge 1 commit intoapache:trunkfrom
edwardcapriolo:HADOOP-19786-a

Conversation

@edwardcapriolo
Copy link
Copy Markdown
Contributor

@edwardcapriolo edwardcapriolo commented Apr 2, 2026

Description of PR

How was this patch tested?

$ mvn org.owasp:dependency-check-maven:check
[INFO] Writing HTML report to: /home/edward/hadoop/hadoop-common-project/hadoop-common/target/dependency-check-report.html
[WARNING]

One or more dependencies were identified with known vulnerabilities in Apache Hadoop Common:

jetty-io-9.4.58.v20250814.jar (pkg:maven/org.eclipse.jetty/jetty-io@9.4.58.v20250814, cpe:2.3:a:eclipse:jetty:9.4.58:20250814::::::, cpe:2.3:a:jetty:jetty:9.4.58:20250814::::::, cpe:2.3:a:mortbay_jetty:jetty:9.4.58:20250814::::::) : CVE-2025-11143
jetty-server-9.4.58.v20250814.jar (pkg:maven/org.eclipse.jetty/jetty-server@9.4.58.v20250814, cpe:2.3:a:eclipse:jetty:9.4.58:20250814::::::, cpe:2.3:a:jetty:jetty:9.4.58:20250814::::::, cpe:2.3:a:jetty:jetty_http_server:9.4.58:20250814::::::, cpe:2.3:a:mortbay_jetty:jetty:9.4.58:20250814::::::) : CVE-2025-11143
netty-transport-4.1.130.Final.jar (pkg:maven/io.netty/netty-transport@4.1.130.Final, cpe:2.3:a:netty:netty:4.1.130:::::::) : CVE-2026-33871, CVE-2026-33870
protobuf-java-2.5.0.jar (pkg:maven/com.google.protobuf/protobuf-java@2.5.0, cpe:2.3:a:google:protobuf-java:2.5.0:
::::::) : CVE-2024-7254, CVE-2022-3171, CVE-2021-22569

See the dependency-check report for more details.

For code changes:

  • Does the title or this PR starts with the corresponding JIRA issue id (e.g. 'HADOOP-17799. Your PR title ...')?
  • Object storage: have the integration tests been executed and the endpoint declared according to the connector-specific documentation?
  • If adding new dependencies to the code, are these dependencies licensed in a way that is compatible for inclusion under ASF 2.0?
  • If applicable, have you updated the LICENSE, LICENSE-binary, NOTICE-binary files?

AI Tooling

If an AI tool was used:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant