amahussein opened a new pull request #3398: URL: https://github.com/apache/hadoop/pull/3398
### Description of PR HADOOP-17898 . BouncyCastle to 1.69 - CVEs are reported for releases lower than 1.66 [CVE-2020-26939](https://nvd.nist.gov/vuln/detail/CVE-2020-26939) moderate severity [CVE-2020-15522](https://nvd.nist.gov/vuln/detail/CVE-2020-15522) moderate severity ### How was this patch tested? - build locally succeeded - `mvn dependency:tree` - Looked into linked Jiras of HADOOP-15832 and reviewed the dependencies affected by the upgrade - I verified that they have no class errors as reported in YARN-8919 and YARN-8899 ```bash mvn test -Dtest=TestFileArgs,TestMultipleCachefiles,TestStreamingBadRecords,\ TestSymLink,TestMultipleArchiveFiles,TestGridmixSubmission,TestDistCacheEmulation,\ TestLoadJob,TestSleepJob,TestDistCh,TestCleanupAfterKIll ### For code changes: - [X] the title or this PR starts with the corresponding JIRA issue id - [X] updated `LICENSE-binary` -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
