[ https://issues.apache.org/jira/browse/HBASE-22728?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16892281#comment-16892281 ]
Andrew Purtell edited comment on HBASE-22728 at 7/25/19 12:13 AM: ------------------------------------------------------------------ This is what we have in branch-1 {noformat} [INFO] org.apache.hbase:hbase-common:jar:1.5.0-SNAPSHOT [INFO] +- org.apache.avro:avro:jar:1.7.7:compile [INFO] | +- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile [INFO] | +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:compile {noformat} {noformat} [INFO] org.apache.hbase:hbase-procedure:jar:1.5.0-SNAPSHOT [INFO] +- org.apache.hadoop:hadoop-common:jar:2.8.5:compile [INFO] | +- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile [INFO] | +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:compile {noformat} {noformat} [INFO] org.apache.hbase:hbase-client:jar:1.5.0-SNAPSHOT [INFO] +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:compile [INFO] | \- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile {noformat} {noformat} [INFO] org.apache.hbase:hbase-metrics-api:jar:1.5.0-SNAPSHOT [INFO] +- org.apache.hbase:hbase-common:jar:1.5.0-SNAPSHOT:compile ... (via avro) {noformat} {noformat} [INFO] org.apache.hbase:hbase-hadoop-compat:jar:1.5.0-SNAPSHOT [INFO] +- org.apache.hbase:hbase-common:jar:1.5.0-SNAPSHOT:compile .... (via avro) {noformat} {noformat} [INFO] org.apache.hbase:hbase-metrics:jar:1.5.0-SNAPSHOT [INFO] +- org.apache.hbase:hbase-common:jar:1.5.0-SNAPSHOT:compile ... (via avro) {noformat} {noformat} [INFO] org.apache.hbase:hbase-hadoop2-compat:jar:1.5.0-SNAPSHOT [INFO] +- org.apache.hadoop:hadoop-mapreduce-client-core:jar:2.8.5:compile [INFO] | +- org.apache.hadoop:hadoop-yarn-common:jar:2.8.5:compile [INFO] | | +- org.codehaus.jackson:jackson-jaxrs:jar:1.9.13:compile [INFO] | | +- org.codehaus.jackson:jackson-xc:jar:1.9.13:compile [INFO] +- org.apache.hadoop:hadoop-common:jar:2.8.5:compile [INFO] | +- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile [INFO] | +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:compile {noformat} {noformat} [INFO] org.apache.hbase:hbase-prefix-tree:jar:1.5.0-SNAPSHOT [INFO] +- org.apache.hadoop:hadoop-common:jar:2.8.5:compile [INFO] | +- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile [INFO] | +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:compile {noformat} {noformat} [INFO] org.apache.hbase:hbase-server:jar:1.5.0-SNAPSHOT [INFO] +- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile [INFO] +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:compile [INFO] +- org.codehaus.jackson:jackson-jaxrs:jar:1.9.13:compile [INFO] +- org.apache.hadoop:hadoop-common:jar:2.8.5:compile [INFO] | +- com.sun.jersey:jersey-json:jar:1.9:compile [INFO] | | \- org.codehaus.jackson:jackson-xc:jar:1.9.13:compile {noformat} {noformat} [INFO] org.apache.hbase:hbase-testing-util:jar:1.5.0-SNAPSHOT [INFO] +- org.apache.hbase:hbase-client:jar:1.5.0-SNAPSHOT:compile [INFO] | +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:compile [INFO] +- org.apache.hbase:hbase-server:jar:1.5.0-SNAPSHOT:compile [INFO] | +- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile [INFO] | +- org.codehaus.jackson:jackson-jaxrs:jar:1.9.13:compile [INFO] +- org.apache.hadoop:hadoop-common:jar:2.8.5:compile [INFO] | +- com.sun.jersey:jersey-json:jar:1.9:compile [INFO] | | \- org.codehaus.jackson:jackson-xc:jar:1.9.13:compile {noformat} {noformat} [INFO] org.apache.hbase:hbase-thrift:jar:1.5.0-SNAPSHOT [INFO] +- org.apache.hbase:hbase-client:jar:1.5.0-SNAPSHOT:compile [INFO] | +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:compile [INFO] +- org.apache.hbase:hbase-server:jar:1.5.0-SNAPSHOT:compile [INFO] | +- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile [INFO] | +- org.codehaus.jackson:jackson-jaxrs:jar:1.9.13:compile [INFO] +- org.apache.hadoop:hadoop-mapreduce-client-core:jar:2.8.5:compile [INFO] | +- org.apache.hadoop:hadoop-yarn-common:jar:2.8.5:compile [INFO] | | +- org.codehaus.jackson:jackson-xc:jar:1.9.13:compile {noformat} {noformat} [INFO] org.apache.hbase:hbase-rest:jar:1.5.0-SNAPSHOT [INFO] +- com.sun.jersey:jersey-json:jar:1.9:compile [INFO] | \- org.codehaus.jackson:jackson-xc:jar:1.9.13:compile [INFO] +- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile [INFO] +- org.codehaus.jackson:jackson-jaxrs:jar:1.9.13:compile [INFO] +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:test {noformat} {noformat} [INFO] org.apache.hbase:hbase-rsgroup:jar:1.5.0-SNAPSHOT [INFO] +- org.apache.hbase:hbase-client:jar:1.5.0-SNAPSHOT:compile [INFO] | +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:compile [INFO] +- org.apache.hbase:hbase-server:jar:1.5.0-SNAPSHOT:compile [INFO] | +- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile [INFO] | +- org.codehaus.jackson:jackson-jaxrs:jar:1.9.13:compile [INFO] +- org.apache.hadoop:hadoop-common:jar:2.8.5:compile [INFO] | | \- org.codehaus.jackson:jackson-xc:jar:1.9.13:compile {noformat} {noformat} [INFO] org.apache.hbase:hbase-shell:jar:1.5.0-SNAPSHOT [INFO] +- org.apache.hbase:hbase-client:jar:1.5.0-SNAPSHOT:compile [INFO] | +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:compile [INFO] +- org.apache.hbase:hbase-server:jar:1.5.0-SNAPSHOT:compile [INFO] | +- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile [INFO] | +- org.codehaus.jackson:jackson-jaxrs:jar:1.9.13:compile [INFO] +- org.apache.hadoop:hadoop-common:jar:2.8.5:compile [INFO] | | \- org.codehaus.jackson:jackson-xc:jar:1.9.13:compile {noformat} {noformat} [INFO] org.apache.hbase:hbase-it:jar:1.5.0-SNAPSHOT [INFO] +- org.apache.hbase:hbase-client:jar:1.5.0-SNAPSHOT:compile [INFO] | +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:compile [INFO] +- org.apache.hbase:hbase-server:jar:1.5.0-SNAPSHOT:compile [INFO] | +- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile [INFO] | +- org.codehaus.jackson:jackson-jaxrs:jar:1.9.13:compile [INFO] +- org.apache.hadoop:hadoop-mapreduce-client-core:jar:2.8.5:compile [INFO] | +- org.apache.hadoop:hadoop-yarn-common:jar:2.8.5:compile [INFO] | | +- org.codehaus.jackson:jackson-xc:jar:1.9.13:compile {noformat} {noformat} [INFO] org.apache.hbase:hbase-examples:jar:1.5.0-SNAPSHOT [INFO] +- org.apache.hbase:hbase-client:jar:1.5.0-SNAPSHOT:compile [INFO] | +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:compile [INFO] +- org.apache.hbase:hbase-server:jar:1.5.0-SNAPSHOT:compile [INFO] | +- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile [INFO] | +- org.codehaus.jackson:jackson-jaxrs:jar:1.9.13:compile [INFO] +- org.apache.hbase:hbase-rest:jar:1.5.0-SNAPSHOT:compile [INFO] | +- com.sun.jersey:jersey-json:jar:1.9:compile [INFO] | | \- org.codehaus.jackson:jackson-xc:jar:1.9.13:compile {noformat} {noformat} [INFO] org.apache.hbase:hbase-external-blockcache:jar:1.5.0-SNAPSHOT [INFO] +- org.apache.hbase:hbase-server:jar:1.5.0-SNAPSHOT:compile [INFO] | +- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile [INFO] | +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:compile [INFO] | +- org.codehaus.jackson:jackson-jaxrs:jar:1.9.13:compile [INFO] +- org.apache.hadoop:hadoop-common:jar:2.8.5:compile [INFO] | +- com.sun.jersey:jersey-json:jar:1.9:compile [INFO] | | \- org.codehaus.jackson:jackson-xc:jar:1.9.13:compile {noformat} Assembly and shaded targets excluded. was (Author: apurtell): This is what we have in branch-1 {noformat} [INFO] org.apache.hbase:hbase-common:jar:1.5.0-SNAPSHOT [INFO] +- org.apache.avro:avro:jar:1.7.7:compile [INFO] | +- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile [INFO] | +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:compile {noformat} {noformat} [INFO] org.apache.hbase:hbase-procedure:jar:1.5.0-SNAPSHOT [INFO] +- org.apache.hadoop:hadoop-common:jar:2.8.5:compile [INFO] | +- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile [INFO] | +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:compile {noformat} {noformat} [INFO] org.apache.hbase:hbase-client:jar:1.5.0-SNAPSHOT [INFO] +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:compile [INFO] | \- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile {noformat} {noformat} [INFO] org.apache.hbase:hbase-metrics-api:jar:1.5.0-SNAPSHOT [INFO] +- org.apache.hbase:hbase-common:jar:1.5.0-SNAPSHOT:compile ... (via avro) {noformat} {noformat} [INFO] org.apache.hbase:hbase-hadoop-compat:jar:1.5.0-SNAPSHOT [INFO] +- org.apache.hbase:hbase-common:jar:1.5.0-SNAPSHOT:compile .... (via avro) {noformat} {noformat} [INFO] org.apache.hbase:hbase-metrics:jar:1.5.0-SNAPSHOT [INFO] +- org.apache.hbase:hbase-common:jar:1.5.0-SNAPSHOT:compile ... (via avro) {noformat} {noformat} [INFO] org.apache.hbase:hbase-hadoop2-compat:jar:1.5.0-SNAPSHOT [INFO] +- org.apache.hadoop:hadoop-mapreduce-client-core:jar:2.8.5:compile [INFO] | +- org.apache.hadoop:hadoop-yarn-common:jar:2.8.5:compile INFO] | | +- org.codehaus.jackson:jackson-jaxrs:jar:1.9.13:compile [INFO] | | +- org.codehaus.jackson:jackson-xc:jar:1.9.13:compile [INFO] +- org.apache.hadoop:hadoop-common:jar:2.8.5:compile INFO] | +- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile [INFO] | +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:compile {noformat} {noformat} [INFO] org.apache.hbase:hbase-prefix-tree:jar:1.5.0-SNAPSHOT [INFO] +- org.apache.hadoop:hadoop-common:jar:2.8.5:compile [INFO] | +- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile [INFO] | +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:compile {noformat} {noformat} [INFO] org.apache.hbase:hbase-server:jar:1.5.0-SNAPSHOT [INFO] +- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile [INFO] +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:compile [INFO] +- org.codehaus.jackson:jackson-jaxrs:jar:1.9.13:compile [INFO] +- org.apache.hadoop:hadoop-common:jar:2.8.5:compile [INFO] | +- com.sun.jersey:jersey-json:jar:1.9:compile [INFO] | | \- org.codehaus.jackson:jackson-xc:jar:1.9.13:compile {noformat} {noformat} [INFO] org.apache.hbase:hbase-testing-util:jar:1.5.0-SNAPSHOT [INFO] +- org.apache.hbase:hbase-client:jar:1.5.0-SNAPSHOT:compile [INFO] | +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:compile [INFO] +- org.apache.hbase:hbase-server:jar:1.5.0-SNAPSHOT:compile [INFO] | +- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile [INFO] | +- org.codehaus.jackson:jackson-jaxrs:jar:1.9.13:compile [INFO] +- org.apache.hadoop:hadoop-common:jar:2.8.5:compile [INFO] | +- com.sun.jersey:jersey-json:jar:1.9:compile [INFO] | | \- org.codehaus.jackson:jackson-xc:jar:1.9.13:compile {noformat} {noformat} [INFO] org.apache.hbase:hbase-thrift:jar:1.5.0-SNAPSHOT [INFO] +- org.apache.hbase:hbase-client:jar:1.5.0-SNAPSHOT:compile [INFO] | +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:compile [INFO] +- org.apache.hbase:hbase-server:jar:1.5.0-SNAPSHOT:compile [INFO] | +- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile [INFO] | +- org.codehaus.jackson:jackson-jaxrs:jar:1.9.13:compile [INFO] +- org.apache.hadoop:hadoop-mapreduce-client-core:jar:2.8.5:compile [INFO] | +- org.apache.hadoop:hadoop-yarn-common:jar:2.8.5:compile [INFO] | | +- org.codehaus.jackson:jackson-xc:jar:1.9.13:compile {noformat} {noformat} [INFO] org.apache.hbase:hbase-rest:jar:1.5.0-SNAPSHOT [INFO] +- com.sun.jersey:jersey-json:jar:1.9:compile [INFO] | \- org.codehaus.jackson:jackson-xc:jar:1.9.13:compile INFO] +- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile [INFO] +- org.codehaus.jackson:jackson-jaxrs:jar:1.9.13:compile [INFO] +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:test {noformat} {noformat} [INFO] org.apache.hbase:hbase-rsgroup:jar:1.5.0-SNAPSHOT [INFO] +- org.apache.hbase:hbase-client:jar:1.5.0-SNAPSHOT:compile [INFO] | +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:compile [INFO] +- org.apache.hbase:hbase-server:jar:1.5.0-SNAPSHOT:compile [INFO] | +- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile [INFO] | +- org.codehaus.jackson:jackson-jaxrs:jar:1.9.13:compile [INFO] +- org.apache.hadoop:hadoop-common:jar:2.8.5:compile [INFO] | | \- org.codehaus.jackson:jackson-xc:jar:1.9.13:compile {noformat} {noformat} [INFO] org.apache.hbase:hbase-shell:jar:1.5.0-SNAPSHOT [INFO] +- org.apache.hbase:hbase-client:jar:1.5.0-SNAPSHOT:compile [INFO] | +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:compile [INFO] +- org.apache.hbase:hbase-server:jar:1.5.0-SNAPSHOT:compile [INFO] | +- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile [INFO] | +- org.codehaus.jackson:jackson-jaxrs:jar:1.9.13:compile [INFO] +- org.apache.hadoop:hadoop-common:jar:2.8.5:compile [INFO] | | \- org.codehaus.jackson:jackson-xc:jar:1.9.13:compile {noformat} {noformat} [INFO] org.apache.hbase:hbase-it:jar:1.5.0-SNAPSHOT [INFO] +- org.apache.hbase:hbase-client:jar:1.5.0-SNAPSHOT:compile [INFO] | +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:compile [INFO] +- org.apache.hbase:hbase-server:jar:1.5.0-SNAPSHOT:compile [INFO] | +- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile [INFO] | +- org.codehaus.jackson:jackson-jaxrs:jar:1.9.13:compile [INFO] +- org.apache.hadoop:hadoop-mapreduce-client-core:jar:2.8.5:compile [INFO] | +- org.apache.hadoop:hadoop-yarn-common:jar:2.8.5:compile [INFO] | | +- org.codehaus.jackson:jackson-xc:jar:1.9.13:compile {noformat} {noformat} [INFO] org.apache.hbase:hbase-examples:jar:1.5.0-SNAPSHOT [INFO] +- org.apache.hbase:hbase-client:jar:1.5.0-SNAPSHOT:compile [INFO] | +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:compile [INFO] +- org.apache.hbase:hbase-server:jar:1.5.0-SNAPSHOT:compile [INFO] | +- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile [INFO] | +- org.codehaus.jackson:jackson-jaxrs:jar:1.9.13:compile [INFO] +- org.apache.hbase:hbase-rest:jar:1.5.0-SNAPSHOT:compile [INFO] | +- com.sun.jersey:jersey-json:jar:1.9:compile [INFO] | | \- org.codehaus.jackson:jackson-xc:jar:1.9.13:compile {noformat} {noformat} [INFO] org.apache.hbase:hbase-external-blockcache:jar:1.5.0-SNAPSHOT [INFO] +- org.apache.hbase:hbase-server:jar:1.5.0-SNAPSHOT:compile [INFO] | +- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile [INFO] | +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:compile [INFO] | +- org.codehaus.jackson:jackson-jaxrs:jar:1.9.13:compile [INFO] +- org.apache.hadoop:hadoop-common:jar:2.8.5:compile [INFO] | +- com.sun.jersey:jersey-json:jar:1.9:compile [INFO] | | \- org.codehaus.jackson:jackson-xc:jar:1.9.13:compile {noformat} Assembly and shaded targets excluded. > Upgrade jackson dependencies in branch-1 > ---------------------------------------- > > Key: HBASE-22728 > URL: https://issues.apache.org/jira/browse/HBASE-22728 > Project: HBase > Issue Type: Sub-task > Affects Versions: 1.4.10, 1.3.5 > Reporter: Andrew Purtell > Priority: Major > Fix For: 1.5.0, 1.3.6, 1.4.11 > > > Avoid Jackson versions and dependencies with known CVEs -- This message was sent by Atlassian JIRA (v7.6.14#76016)