Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[AMBARI-23881] Remove dependency on marked.js 0.3.2 in Ambari Web #1306

Merged
merged 1 commit into from May 17, 2018

Conversation

aBabiichuk
Copy link
Contributor

What changes were proposed in this pull request?

Remove dependency on marked.js 0.3.2 in Ambari Web due to security concerns. See

[root@host ~]# ambari-server --version
2.7.0.0-519
[root@host ~]# find /usr/lib -name marked.js
/usr/lib/ambari-server/web/api-docs/lib/marked.js

Recommendation is to remove the dependency or upgrade to version 0.3.2-1 or the latest version, if possible.

How was this patch tested?

Tested manually

@aBabiichuk aBabiichuk added the web client Ambari WebUI Client label May 17, 2018
@aBabiichuk aBabiichuk self-assigned this May 17, 2018
@aBabiichuk aBabiichuk requested a review from atkach May 17, 2018 15:37
@asfgit
Copy link

asfgit commented May 17, 2018

Refer to this link for build results (access rights to CI server needed):
https://builds.apache.org/job/Ambari-Github-PullRequest-Builder/2344/
Test PASSed.

@aBabiichuk aBabiichuk merged commit 0460f44 into apache:trunk May 17, 2018
@aBabiichuk aBabiichuk deleted the AMBARI-23881-trunk branch May 17, 2018 16:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
web client Ambari WebUI Client
Projects
None yet
3 participants