[
https://issues.apache.org/jira/browse/BEAM-11227?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17294806#comment-17294806
]
Tomo Suzuki edited comment on BEAM-11227 at 3/4/21, 1:57 AM:
-------------------------------------------------------------
[~iemejia] I'm going to send email about this upgrade to [email protected].
As per https://s.apache.org/beam-release-vendored-artifacts, can I nominate you
as the release manager?
(Once I finish the [PR#14028|https://github.com/apache/beam/pull/14028]. I
would like the release manager to take over "Build a release candidate" and
voting in the doc. )
{quote}2. Update the Beam codebase to use the vendored dependency (usually a
huge but relatively straight forward PR).
...
(2) to have been tested in advance{quote}
Yes, before voting, let me think about how I can test the vendored guava. I
think inserting few commands to install the vendored artifact locally (as in
[README.md|https://github.com/apache/beam/pull/14028/files#diff-127a723f9b1317696bc8bcbc91190d0133ec55700142b019393f56c0cb2744e2R38])
for Jenkins would make it possible to confirm it without actually publishing
the artifact.
was (Author: suztomo):
[~iemejia] I'm going to send email about this upgrade to [email protected].
As per https://s.apache.org/beam-release-vendored-artifacts, can I nominate you
as the release manager?
{quote}2. Update the Beam codebase to use the vendored dependency (usually a
huge but relatively straight forward PR).
...
(2) to have been tested in advance{quote}
Yes, before voting, let me think about how I can test the vendored guava. I
think inserting few commands to install the vendored artifact locally (as in
[README.md|https://github.com/apache/beam/pull/14028/files#diff-127a723f9b1317696bc8bcbc91190d0133ec55700142b019393f56c0cb2744e2R38])
for Jenkins would make it possible to confirm it without actually publishing
the artifact.
> Upgrade beam-vendor-grpc-1_26_0-0.3 to fix CVE-2020-27216
> ---------------------------------------------------------
>
> Key: BEAM-11227
> URL: https://issues.apache.org/jira/browse/BEAM-11227
> Project: Beam
> Issue Type: Bug
> Components: build-system
> Affects Versions: 2.21.0, 2.22.0, 2.23.0, 2.24.0, 2.25.0
> Reporter: Boury Mbodj
> Priority: P1
> Labels: apache-beam, beam
> Fix For: 2.29.0
>
> Time Spent: 11h 10m
> Remaining Estimate: 0h
>
> *+Description+**:* [Apache Beam :: Vendored Dependencies :: GRPC ::
> 1.26.0|https://mvnrepository.com/artifact/org.apache.beam/beam-vendor-grpc-1_26_0]
> »
> [0.3|https://mvnrepository.com/artifact/org.apache.beam/beam-vendor-grpc-1_26_0/0.3]
> uses the dependency Eclipse Jetty (9.2.10.v20150310), which is prone to a
> privilege escalation vulnerability. This issue (CVE-2020-27216) was published
> on 23/10/2020.
> *+Affected Versions:+*
> Eclipse Jetty versions 9.4.32.v20200930 and prior, 10.0.0.beta2 and prior
> and 11.0.0.beta2 and prior.
> *+Recommendation/+* *+Update Suggestion:+*
> Update the Eclipse Jetty dependency to version 9.4.33.v20201020,
> 10.0.0.beta3, 11.0.0.beta3 or later.
>
--
This message was sent by Atlassian Jira
(v8.3.4#803005)