Skip to content

Conversation

@kokosing
Copy link
Contributor

Remove usage of htrace-core4

This project is retired. Since it was not updated for a long time it
contains plenty of old dependencies (shaded) that are marked by security
scanners as source of vulnerabilities.

This project is retired. Since it was not updated for a long time it
contains plenty of old dependencies (shaded) that are marked by security
scanners as source of vulnerabilities.
@kokosing
Copy link
Contributor Author

@mneethiraj it looks like htrace is having a shaded dependency for jackson which is outdated and have plenty of CVEs. I am not sure how it was used in Ranger from my short investigation it looks like is either not used or there is missing infrastructure part in tests. Since htrace is no longer supported I think it should be removed from Ranger and potentially if needed I would recommend using opentelemetry.

Would you like to help me to contribute this change? Also our scanners flagged other CVEs related issues, if this contribution is successful I would be very happy to update other libraries.

@mneethiraj mneethiraj changed the title Remove usage of htrace-core4 RANGER-4858: Remove usage of htrace-core4 Jul 15, 2024
mneethiraj pushed a commit that referenced this pull request Jul 15, 2024
Signed-off-by: Madhan Neethiraj <madhan@apache.org>
mneethiraj pushed a commit that referenced this pull request Jul 15, 2024
Signed-off-by: Madhan Neethiraj <madhan@apache.org>
(cherry picked from commit bc091c5)
@mneethiraj
Copy link
Contributor

[~kokosing] - thank you for the contribution. The patch is merged in master and ranger-2.5 branches.

@mneethiraj mneethiraj closed this Jul 15, 2024
@kokosing kokosing deleted the origin/master/001_htrace branch July 15, 2024 20:37
@kokosing
Copy link
Contributor Author

Thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants