[
https://issues.apache.org/jira/browse/HDDS-4980?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Siyao Meng updated HDDS-4980:
-----------------------------
Summary: Bump libthrift to 0.14.1 for jaeger-client / jaeger-thrift (was:
Bump dependency jaeger-client version to 1.5.0 (from 1.2.0))
> Bump libthrift to 0.14.1 for jaeger-client / jaeger-thrift
> ----------------------------------------------------------
>
> Key: HDDS-4980
> URL: https://issues.apache.org/jira/browse/HDDS-4980
> Project: Apache Ozone
> Issue Type: Task
> Reporter: Siyao Meng
> Assignee: Siyao Meng
> Priority: Major
> Labels: pull-request-available
>
> -Bumping jaeger-client to hopefully upgrade the libthrift version-
> Apparently latest jaeger-client as of now 1.5.0 still doesn't include
> libthrift with the CVE fix:
> {code}
> [INFO] +- io.jaegertracing:jaeger-client:jar:1.2.0:compile
> [INFO] | +- io.jaegertracing:jaeger-thrift:jar:1.2.0:compile
> [INFO] | | +- org.apache.thrift:libthrift:jar:0.13.0:compile
> {code}
> not until https://github.com/jaegertracing/jaeger-client-java/pull/768 is
> merged and a new version released.
> Including libthrift 0.14.1 manually.
--
This message was sent by Atlassian Jira
(v8.3.4#803005)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]