steveloughran commented on PR #5192:
URL: https://github.com/apache/hadoop/pull/5192#issuecomment-1342536481

   i think the maven plugin itself should be upgraded, rather than trying to 
add new dependencies (and do the old ones get excluded? how do you guarantee 
the new ones get picked up?). what happens later when an upgrade does take 
place? will we remember to remove what may then be older dependencies
   
   this is a compile time issue only, no cve in any redistributables, so hard 
to justify creating classpath/version hell for. 


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: common-issues-unsubscr...@hadoop.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org


---------------------------------------------------------------------
To unsubscribe, e-mail: common-issues-unsubscr...@hadoop.apache.org
For additional commands, e-mail: common-issues-h...@hadoop.apache.org

Reply via email to