[ 
https://issues.apache.org/jira/browse/HBASE-27148?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Duo Zhang updated HBASE-27148:
------------------------------
    Release Note: 
Bump the minimum hadoop 3 dependency to 3.2.3.

Also upgrade apache-avro to 1.11.0 and exclude all jackson 1.x dependencies 
since all jackson 1.x versions have vulnerabilities.

Notice that for hadoop 2 dependency we will need to include jackson 1.x because 
hadoop directly depend on it.

> Move minimum hadoop 3  support version to 3.2.3
> -----------------------------------------------
>
>                 Key: HBASE-27148
>                 URL: https://issues.apache.org/jira/browse/HBASE-27148
>             Project: HBase
>          Issue Type: Task
>          Components: dependencies, hadoop3, security
>            Reporter: Duo Zhang
>            Assignee: Duo Zhang
>            Priority: Major
>             Fix For: 2.5.0, 3.0.0-alpha-4
>
>
> Seems the hadoop community will not make newer 3.1.x release so let's move 
> the minimun hadoop 3 versions to 3.2.3, due to security issues.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to