Github user ctubbsii commented on a diff in the pull request:

    https://github.com/apache/accumulo/pull/131#discussion_r71908487
  
    --- Diff: assemble/src/main/scripts/generate-download-script.sh ---
    @@ -0,0 +1,56 @@
    +#! /usr/bin/env bash
    +
    +# Licensed to the Apache Software Foundation (ASF) under one or more
    +# contributor license agreements.  See the NOTICE file distributed with
    +# this work for additional information regarding copyright ownership.
    +# The ASF licenses this file to You under the Apache License, Version 2.0
    +# (the "License"); you may not use this file except in compliance with
    +# the License.  You may obtain a copy of the License at
    +#
    +#     http://www.apache.org/licenses/LICENSE-2.0
    +#
    +# Unless required by applicable law or agreed to in writing, software
    +# distributed under the License is distributed on an "AS IS" BASIS,
    +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
    +# See the License for the specific language governing permissions and
    +# limitations under the License.
    +
    +# This script will generate a DEPENDENCIES listing of packaged dependencies
    +
    +in=target/dependencies.raw.txt
    +out=target/download-dependencies
    +
    +cat >"$out" <<'EOF'
    +#! /usr/bin/env bash
    +# This script downloads the following jars, identified by their maven
    +# coordinates, using the maven-dependency-plugin.
    +#
    +# DISCLAIMER: This is only one possible way to download a set of 
dependencies
    --- End diff --
    
    I don't want to mislead downstream. What I've described appears to be the 
reality of the situation, as far as I understand it. You're right that just 
because there is an update to a dependency, doesn't mean it will work with 
Accumulo. That can't be figured out without some work, and I don't want to 
communicate that false narrative. However, I also don't want to communicate 
that we are responsible for the reliability, security, and stability of all of 
our dependencies, because we're not. They each have their own open source 
communities responsible for them. Accumulo can no more take responsibility for 
a security vulnerability in jetty or commons-io than we can in Hadoop or 
ZooKeeper.
    
    What we can do is communicate what worked for us at the time, and we can 
patch to support the updated dependencies, as they are brought to our attention 
(we can also periodically check for updates ourselves, but there is some burden 
involved in updating our dependencies internally due to license/notice file 
updates, JDK compatibility, and occasional reluctance in the community to not 
test with earlier versions).
    
    Bottom line is for me: the upstream Accumulo project cannot take 
responsibility for the dependencies, but we can communicate with our downstream 
and work to support newer deps as they are patched in their respective 
communities.


---
If your project is set up for it, you can reply to this email and have your
reply appear on GitHub as well. If your project does not have this feature
enabled and wishes so, or if the feature is enabled but not working, please
contact infrastructure at [email protected] or file a JIRA ticket
with INFRA.
---

Reply via email to