NIFI-10347 Upgrade Metrics-graphite to 4.2.10#6291
NIFI-10347 Upgrade Metrics-graphite to 4.2.10#6291UcanInfosec wants to merge 2 commits intoapache:mainfrom UcanInfosec:main
Conversation
|
This does resolve CVE CVE-2016-4000 |
|
Thanks for the vulnerability reference @mr1716. CVE-2016-4000 applies to Jython, which is a test dependency of |
exceptionfactory
left a comment
There was a problem hiding this comment.
@UcanInfosec The Dropwizard Metrics project maintains both the 4.1 and 4.2 releases. Although this may be a compatible upgrade, several other modules depend on metrics-core from the 4.1 series, so it seems better to use the latest 4.1 version instead of upgrading to 4.2 in this particular module.
|
@exceptionfactory thanks. It was changed to 4.1.33. |
exceptionfactory
left a comment
There was a problem hiding this comment.
Thanks for making the adjustment to stay with the 4.1 series @UcanInfosec, this looks good. +1 merging
This closes apache#6291 Signed-off-by: David Handermann <exceptionfactory@apache.org>
Summary
NIFI-10347
Tracking
Please complete the following tracking steps prior to pull request creation.
Issue Tracking
Pull Request Tracking
NIFI-00000NIFI-00000Pull Request Formatting
mainbranchVerification
Please indicate the verification steps performed prior to pull request creation.
Build
mvn clean install -P contrib-checkLicensing
LICENSEandNOTICEfilesDocumentation