Skip to content

Upgrade java 21#51

Merged
ninhomilton merged 2 commits into
ExpediaGroup:Java_21_Migrationfrom
ninhomilton:Upgrade_Java_21
Mar 16, 2026
Merged

Upgrade java 21#51
ninhomilton merged 2 commits into
ExpediaGroup:Java_21_Migrationfrom
ninhomilton:Upgrade_Java_21

Conversation

@ninhomilton
Copy link
Copy Markdown
Collaborator

📝 Description

🔗 Related Issues

Milton Ortegon and others added 2 commits March 16, 2026 11:04
Upgrading hadoop-client-runtime from 3.3.6 to 3.4.2 resolves vulnerable
libraries bundled inside the shaded JAR that Maven exclusions cannot reach:
- Avro 1.7.7 → 1.11.3 (CVE-2023-39410, bundled via HADOOP-18880)
- Kerby 1.0.1 → 2.0.3 (CVE-2023-25613, bundled via HADOOP-18956)

Also removes the now-unnecessary explicit avro/kerb-admin dependency
declarations and exclusions that were working around the same issue.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@ninhomilton ninhomilton requested a review from a team as a code owner March 16, 2026 20:13
@ninhomilton ninhomilton merged commit aefac35 into ExpediaGroup:Java_21_Migration Mar 16, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant