bjornjorgensen commented on a change in pull request #35584:
URL: https://github.com/apache/spark/pull/35584#discussion_r810962046
##########
File path: dev/deps/spark-deps-hadoop-2-hive-2.3
##########
@@ -64,11 +65,13 @@ datanucleus-core/4.1.17//datanucleus-core-4.1.17.jar
datanucleus-rdbms/4.1.19//datanucleus-rdbms-4.1.19.jar
derby/10.14.2.0//derby-10.14.2.0.jar
dropwizard-metrics-hadoop-metrics2-reporter/0.1.2//dropwizard-metrics-hadoop-metrics2-reporter-0.1.2.jar
+error_prone_annotations/2.3.4//error_prone_annotations-2.3.4.jar
+failureaccess/1.0.1//failureaccess-1.0.1.jar
flatbuffers-java/1.12.0//flatbuffers-java-1.12.0.jar
generex/1.0.2//generex-1.0.2.jar
gmetric4j/1.0.10//gmetric4j-1.0.10.jar
gson/2.2.4//gson-2.2.4.jar
-guava/14.0.1//guava-14.0.1.jar
+guava/30.0-jre//guava-30.0-jre.jar
Review comment:
Yes, this PR is just to get rid of two CVE. I do not want to destroy
existing code base. If you are a developer who needs and uses some of what is
in newer code, then I recommend that you implement this yourself when you need
it.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]