Skip to content

[Security] Upgrade Zookeeper to 3.6.3#10852

Merged
merlimat merged 1 commit intoapache:masterfrom
lhotari:lh-upgrade-zk-3.6.3
Jun 7, 2021
Merged

[Security] Upgrade Zookeeper to 3.6.3#10852
merlimat merged 1 commit intoapache:masterfrom
lhotari:lh-upgrade-zk-3.6.3

Conversation

@lhotari
Copy link
Member

@lhotari lhotari commented Jun 7, 2021

Motivation

Modifications

  • Upgrade Zookeeper to 3.6.3 which uses Netty 4.1.63.Final

- Zookeeper 3.6.2 gets flagged as vulnerable
  https://ossindex.sonatype.org/component/pkg:maven/org.apache.zookeeper/zookeeper@3.6.2
  because of using vulnerable Netty version
@lhotari lhotari added this to the 2.9.0 milestone Jun 7, 2021
@lhotari lhotari requested a review from eolivelli June 7, 2021 09:56
Copy link
Contributor

@eolivelli eolivelli left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@eolivelli eolivelli requested a review from codelipenghui June 7, 2021 10:01
@eolivelli eolivelli added the area/dependency Pull requests that update a dependency file label Jun 7, 2021
@eolivelli
Copy link
Contributor

I would move to ZooKeeper 3.7.0 on master branch (2.9.0) and to 3.6.3 in branch-2.8

@lhotari
Copy link
Member Author

lhotari commented Jun 7, 2021

I would move to ZooKeeper 3.7.0 on master branch (2.9.0) and to 3.6.3 in branch-2.8

@eolivelli Can we first go to 3.6.3 on master with this PR so that we can cherry-pick it to branch-2.8?

@merlimat
Copy link
Contributor

merlimat commented Jun 7, 2021

@eolivelli Can we first go to 3.6.3 on master with this PR so that we can cherry-pick it to branch-2.8?

Yes, that's a good point.

@eolivelli
Copy link
Contributor

Yes. Very good point!
I totally agree

@merlimat merlimat merged commit aa36eb8 into apache:master Jun 7, 2021
lhotari added a commit to lhotari/pulsar that referenced this pull request Jun 9, 2021
@codelipenghui codelipenghui modified the milestones: 2.9.0, 2.8.0 Jun 12, 2021
codelipenghui pushed a commit that referenced this pull request Jun 12, 2021
- Zookeeper 3.6.2 gets flagged as vulnerable
  https://ossindex.sonatype.org/component/pkg:maven/org.apache.zookeeper/zookeeper@3.6.2
  because of using vulnerable Netty version

(cherry picked from commit aa36eb8)
eolivelli pushed a commit to datastax/pulsar that referenced this pull request Jun 14, 2021
- Zookeeper 3.6.2 gets flagged as vulnerable
  https://ossindex.sonatype.org/component/pkg:maven/org.apache.zookeeper/zookeeper@3.6.2
  because of using vulnerable Netty version

(cherry picked from commit aa36eb8)
(cherry picked from commit 0929015)
yangl pushed a commit to yangl/pulsar that referenced this pull request Jun 23, 2021
bharanic-dev pushed a commit to bharanic-dev/pulsar that referenced this pull request Mar 18, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/dependency Pull requests that update a dependency file area/security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants