Skip to content

Conversation

janhoy
Copy link
Contributor

@janhoy janhoy commented Aug 19, 2021

This also upgrades libthrift to 0.14.1, fixing CVE-2020-13949

https://issues.apache.org/jira/browse/SOLR-15324

@janhoy janhoy requested review from CaoManhDat and dsmiley August 19, 2021 11:08
@janhoy
Copy link
Contributor Author

janhoy commented Aug 19, 2021

Test seem to pass, but I don't know if the upgrade will actually work with a live Jaeger server. Anyone who have the chance to test?

versions.lock Outdated
org.apache.tika:tika-parsers:1.24 (1 constraints: db04f730)
org.apache.tika:tika-xmp:1.24 (1 constraints: db04f730)
org.apache.tomcat:tomcat-annotations-api:8.5.46 (1 constraints: 5a1162ea)
org.apache.tomcat.embed:tomcat-embed-core:8.5.46 (1 constraints: 780c4b05)
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Would it be safe to exclude these two new tomcat dependencies or are they needed by our use of jaeger?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I excluded them and tests still pass..

Copy link
Contributor

@dsmiley dsmiley left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for minding the exclusions.

@janhoy janhoy merged commit 0a81be3 into apache:main Aug 25, 2021
@janhoy janhoy deleted the solr15324-jaeger branch August 25, 2021 08:31
epugh pushed a commit to epugh/solr that referenced this pull request Oct 22, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants