[ https://issues.apache.org/jira/browse/HBASE-28249?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17802393#comment-17802393 ]
Hudson commented on HBASE-28249: -------------------------------- Results for branch branch-2.6 [build #20 on builds.a.o|https://ci-hbase.apache.org/job/HBase%20Nightly/job/branch-2.6/20/]: (x) *{color:red}-1 overall{color}* ---- details (if available): (/) {color:green}+1 general checks{color} -- For more information [see general report|https://ci-hbase.apache.org/job/HBase%20Nightly/job/branch-2.6/20/General_20Nightly_20Build_20Report/] (/) {color:green}+1 jdk8 hadoop2 checks{color} -- For more information [see jdk8 (hadoop2) report|https://ci-hbase.apache.org/job/HBase%20Nightly/job/branch-2.6/20/JDK8_20Nightly_20Build_20Report_20_28Hadoop2_29/] (x) {color:red}-1 jdk8 hadoop3 checks{color} -- For more information [see jdk8 (hadoop3) report|https://ci-hbase.apache.org/job/HBase%20Nightly/job/branch-2.6/20/JDK8_20Nightly_20Build_20Report_20_28Hadoop3_29/] (/) {color:green}+1 jdk11 hadoop3 checks{color} -- For more information [see jdk11 report|https://ci-hbase.apache.org/job/HBase%20Nightly/job/branch-2.6/20/JDK11_20Nightly_20Build_20Report_20_28Hadoop3_29/] (x) {color:red}-1 source release artifact{color} -- See build output for details. (x) {color:red}-1 client integration test{color} -- Something went wrong with this stage, [check relevant console output|https://ci-hbase.apache.org/job/HBase%20Nightly/job/branch-2.6/20//console]. > Bump jruby to 9.3.13.0 and related joni and jcodings to 2.2.1 and 1.0.58 > respectively > ------------------------------------------------------------------------------------- > > Key: HBASE-28249 > URL: https://issues.apache.org/jira/browse/HBASE-28249 > Project: HBase > Issue Type: Task > Components: jruby, security, shell > Reporter: Nihal Jain > Assignee: Nihal Jain > Priority: Major > Fix For: 2.6.0, 3.0.0-beta-2 > > > Given branch-2 including branch-2.6 is already on 9.3.9.0, we should bump to > at least 9.3.13.0. This will fix the bundled *org.bouncycastle : > bcprov-jdk18on : 1.71* having > [CVE-2023-33201|https://nvd.nist.gov/vuln/detail/CVE-2023-33201] from our > classpath for the least. > As a follow up can try to bump to latest 9.4.x line. Otherwise I can try to > work directly on HBASE-28250 as well, although this may not be straight > forward and would require some good testing. > Please let me know what others think. -- This message was sent by Atlassian Jira (v8.20.10#820010)