[ 
https://issues.apache.org/jira/browse/HADOOP-19912?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18101335#comment-18101335
 ] 

ASF GitHub Bot commented on HADOOP-19912:
-----------------------------------------

pjfanning opened a new pull request, #8653:
URL: https://github.com/apache/hadoop/pull/8653

   <!--
     Thanks for sending a pull request!
       1. If this is your first time, please read our contributor guidelines: 
https://cwiki.apache.org/confluence/display/HADOOP/How+To+Contribute
       2. Make sure your PR title starts with JIRA issue id, e.g., 
'HADOOP-17799. Your PR title ...'.
   -->
   
   ### Description of PR
   
   Contains content generated by Claude and Xiaomi Mimo.
   
   Also updates to Jersey 3 and switches from Javax to Jakarta as these changes 
are needed for the Jetty 12 migration.
   
   Still some build issues with the 'invariant' checks at the end of the maven 
build and if anyone has some pointers that would be great.
   
   ### How was this patch tested?
   
   CI Build
   
   ### For code changes:
   
   - [x] Does the title or this PR starts with the corresponding JIRA issue id 
(e.g. 'HADOOP-17799. Your PR title ...')?
   - [ ] Object storage: have the integration tests been executed and the 
endpoint declared according to the connector-specific documentation?
   - [ ] If adding new dependencies to the code, are these dependencies 
licensed in a way that is compatible for inclusion under [ASF 
2.0](http://www.apache.org/legal/resolved.html#category-a)?
   - [x] If applicable, have you updated the `LICENSE`, `LICENSE-binary`, 
`NOTICE-binary` files?
   
   ### AI Tooling
   
   If an AI tool was used:
   
   - [x] The PR includes the phrase "Contains content generated by <tool>"
         where <tool> is the name of the AI tool used.
   - [x] My use of AI contributions follows the ASF legal policy
         https://www.apache.org/legal/generative-tooling.html




> Upgrade to Jetty 11 or 12
> -------------------------
>
>                 Key: HADOOP-19912
>                 URL: https://issues.apache.org/jira/browse/HADOOP-19912
>             Project: Hadoop Common
>          Issue Type: Task
>            Reporter: PJ Fanning
>            Priority: Major
>
> See HADOOP-19910 - there is a CVE in Jetty but releases of 9.4 are rare and 
> are 'sponsored' - Jetty 9.4 is not actively maintained. There are some 
> commercial forks.
> Jetty 12 needs Java 17+.
> Will also force Jersey to upgraded to 3 or 4.
> And to replace many javax classes/jars with their jakarta equivalents.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to