basapuram-kumar opened a new pull request, #5597:
URL: https://github.com/apache/hive/pull/5597

   
   ### What changes were proposed in this pull request?
   Upgrading the Atlas to 2.4.0, details are in-detailed at 
[HIVE-28693](https://issues.apache.org/jira/browse/HIVE-28693)
   
   
   ### Why are the changes needed?
   This change will fix the 
[CVE-2023-20863](https://nvd.nist.gov/vuln/detail/CVE-2023-20863).
   And 
   Upgrading to Apache Atlas 2.4.0 will not only resolve the vulnerability but 
also ensure alignment of spriongframework  with Apache Hive, which uses Spring 
Framework 5.3.39. This version of Spring Framework is included transitively by 
Hive.
   
   
   ### Does this PR introduce _any_ user-facing change?
   No
   
   ### Is the change a dependency upgrade?
   No
   
   ### How was this patch tested?
   Tested on local lab cluster by building packages with this atlas version 
change, works as expcted.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: gitbox-unsubscr...@hive.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org


---------------------------------------------------------------------
To unsubscribe, e-mail: gitbox-unsubscr...@hive.apache.org
For additional commands, e-mail: gitbox-h...@hive.apache.org

Reply via email to