Skip to content

Suppress dependency-check alert of hadoop-client-runtime#17885

Merged
cryptoe merged 2 commits intoapache:masterfrom
kgyrtkirk:hadoop-cve-1
Apr 7, 2025
Merged

Suppress dependency-check alert of hadoop-client-runtime#17885
cryptoe merged 2 commits intoapache:masterfrom
kgyrtkirk:hadoop-cve-1

Conversation

@kgyrtkirk
Copy link
Copy Markdown
Member

@kgyrtkirk kgyrtkirk commented Apr 7, 2025

  • jetty 9.4.53.v20231009 is build into hadoop-client-runtime-3.3.6
  • none of the current releases (3.4.0/3.41) have a more recent version
  • disables dependency-checker / .net assembly scan

@kgyrtkirk kgyrtkirk changed the title Suppress hadoop-client-runtime warning Suppress hadoop-client-runtime Apr 7, 2025
@kgyrtkirk kgyrtkirk changed the title Suppress hadoop-client-runtime Suppress dependency-check alert of hadoop-client-runtime Apr 7, 2025
@kgyrtkirk kgyrtkirk added this to the 33.0.0 milestone Apr 7, 2025
@cryptoe cryptoe merged commit 3a8a97e into apache:master Apr 7, 2025
82 checks passed
kgyrtkirk added a commit to kgyrtkirk/druid that referenced this pull request Apr 7, 2025
* Add cve supression

* disable .net assembly scan
kgyrtkirk added a commit that referenced this pull request Apr 7, 2025
* Add cve supression

* disable .net assembly scan

(cherry picked from commit 3a8a97e)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants