amahussein opened a new pull request #3398:
URL: https://github.com/apache/hadoop/pull/3398


   ### Description of PR
   
   HADOOP-17898 . BouncyCastle to 1.69
   
   - CVEs are reported for releases lower than 1.66 
   [CVE-2020-26939](https://nvd.nist.gov/vuln/detail/CVE-2020-26939) moderate 
severity
   [CVE-2020-15522](https://nvd.nist.gov/vuln/detail/CVE-2020-15522) moderate 
severity 
   
   ### How was this patch tested?
   
   - build locally succeeded
   - `mvn dependency:tree`
   - Looked into linked Jiras of HADOOP-15832 and reviewed the dependencies 
affected by the upgrade
   -  I verified that they have no class errors as reported in YARN-8919 and 
YARN-8899
   ```bash
   mvn test -Dtest=TestFileArgs,TestMultipleCachefiles,TestStreamingBadRecords,\
   
TestSymLink,TestMultipleArchiveFiles,TestGridmixSubmission,TestDistCacheEmulation,\
   TestLoadJob,TestSleepJob,TestDistCh,TestCleanupAfterKIll
   
   ### For code changes:
   
   - [X] the title or this PR starts with the corresponding JIRA issue id
   - [X] updated `LICENSE-binary`
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]



---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to