Skip to content

Fix reported CVEs#14882

Merged
abhishekagarwal87 merged 9 commits intoapache:masterfrom
tejaswini-imply:suppress-cves
Aug 24, 2023
Merged

Fix reported CVEs#14882
abhishekagarwal87 merged 9 commits intoapache:masterfrom
tejaswini-imply:suppress-cves

Conversation

@tejaswini-imply
Copy link
Member

@tejaswini-imply tejaswini-imply commented Aug 21, 2023

drop druid-iceberg-extensions module,
upgrade grpc-netty-shaded version
]]></notes>
<cve>CVE-2022-45855</cve>
<cve>CVE-2022-42009</cve>
<!-- Suppress hadoop CVEs that not applicable to hadoop-annotations -->
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we should add a comment as to why these are not applicable to hadoop-annotations.

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated it! Thanks, @abhishekagarwal87

Comment on lines -451 to -452
<argument>-c</argument>
<argument>org.apache.druid.extensions:druid-iceberg-extensions</argument>
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

why are you removing this? This profile is bundle-contrib-exts which is supposed to package all contrib extensions in the bundle.

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reverted this! Thanks for pointing it out.

@abhishekagarwal87 abhishekagarwal87 merged commit 388d5ec into apache:master Aug 24, 2023
@LakshSingla LakshSingla added this to the 28.0 milestone Oct 12, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants