[
https://issues.apache.org/jira/browse/HADOOP-19912?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18123095#comment-18123095
]
Jose Luis López commented on HADOOP-19912:
------------------------------------------
Made some progress here: https://issues.apache.org/jira/browse/HADOOP-19970 to
set a single version of Jetty for HADOOP and here
https://issues.apache.org/jira/browse/HADOOP-19972 to perform the migration to
jetty12-ee8.
Use this first step to adapt to jetty12 changes. You can find the list in the
PR linked with HADOOP-19972. Some changes bring configuration keys and
adaptations needed to maintain backwards compatibility as much as possible.
I have tested the migration to jetty12-ee8 in small cluster, federated and HA
cases. It looks good but more testing is needed.
The change of coordinates to jakarta instead of javax proposed in 19395 needs
to be postponed until the jetty12-ee8 is merged. From there, the change to
jetty12-ee11 is also possible.
> Upgrade to Jetty 12
> -------------------
>
> Key: HADOOP-19912
> URL: https://issues.apache.org/jira/browse/HADOOP-19912
> Project: Hadoop Common
> Issue Type: Task
> Reporter: PJ Fanning
> Assignee: Jose Luis López
> Priority: Major
> Labels: pull-request-available
>
> See HADOOP-19910 - there is a CVE in Jetty but releases of 9.4 are rare and
> are 'sponsored' - Jetty 9.4 is not actively maintained. There are some
> commercial forks.
> Jetty 12 needs Java 17+.
> Will also force Jersey to upgraded to 3 or 4.
> And to replace many javax classes/jars with their jakarta equivalents.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]