jerqi commented on PR #464: URL: https://github.com/apache/incubator-uniffle/pull/464#issuecomment-1377239280
> > > Does this mean we are getting rid of `log4j:1.2.17`? > > > When I was working on spark code, I noticed spark still depends on `log4j:1.2.17`. > > > > > > Will it be a problem? > > if we cannot get rid of `log4j:1.2.17`, the CVE issues doesn't go away? Thus maybe this PR is not that urgent? > > P.S: I have no objection for merging this PR. We can't control the Spark. We only need to guarantee that rss service don't have the danger. And Uniffle can be used for multiple frameworks. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
