Hadoop depencency CVEs

2023-03-14 Thread Michiel de Jong
Hello Hadoop Developers, When running a dependency cve scan on our project we noticed a list of dependencies in hadoop common that have some CVE. There are also several CVEs listed on https://mvnrepository.com/artifact/org.apache.hadoop/hadoop-common/3.3.4. Many of these CVEs would probably

[jira] [Created] (HADOOP-18663) DecayRpcSchedulerDetailedMetrics display name numbers incremented by 1

2023-03-14 Thread Christos Bisias (Jira)
Christos Bisias created HADOOP-18663: Summary: DecayRpcSchedulerDetailedMetrics display name numbers incremented by 1 Key: HADOOP-18663 URL: https://issues.apache.org/jira/browse/HADOOP-18663

[jira] [Created] (HADOOP-18662) ListFiles with recursive fails with FNF

2023-03-14 Thread Ayush Saxena (Jira)
Ayush Saxena created HADOOP-18662: - Summary: ListFiles with recursive fails with FNF Key: HADOOP-18662 URL: https://issues.apache.org/jira/browse/HADOOP-18662 Project: Hadoop Common Issue

Apache Hadoop qbt Report: trunk+JDK8 on Linux/x86_64

2023-03-14 Thread Apache Jenkins Server
For more details, see https://ci-hadoop.apache.org/job/hadoop-qbt-trunk-java8-linux-x86_64/1165/ [Mar 13, 2023, 4:38:04 AM] (github) HADOOP-18658. snakeyaml dependency: upgrade to v2.0 (#5467). Contributed by PJ Fanning. [Mar 13, 2023, 12:24:36 PM] (Steve Loughran) HADOOP-18661. Fix bin/hadoop

[jira] [Created] (HADOOP-18665) IOUtils.wrapWithMessage can't wrap exceptions without string constructor

2023-03-14 Thread Steve Loughran (Jira)
Steve Loughran created HADOOP-18665: --- Summary: IOUtils.wrapWithMessage can't wrap exceptions without string constructor Key: HADOOP-18665 URL: https://issues.apache.org/jira/browse/HADOOP-18665

[jira] [Created] (HADOOP-18664) you can't launch create-release --docker from a build file

2023-03-14 Thread Steve Loughran (Jira)
Steve Loughran created HADOOP-18664: --- Summary: you can't launch create-release --docker from a build file Key: HADOOP-18664 URL: https://issues.apache.org/jira/browse/HADOOP-18664 Project: Hadoop

Apache Hadoop qbt Report: branch-2.10+JDK7 on Linux/x86_64

2023-03-14 Thread Apache Jenkins Server
For more details, see https://ci-hadoop.apache.org/job/hadoop-qbt-branch-2.10-java7-linux-x86_64/966/ No changes ERROR: File 'out/email-report.txt' does not exist - To unsubscribe, e-mail:

Re: Hadoop depencency CVEs

2023-03-14 Thread Steve Loughran
hello. welcome to the hadoop CVE support team! all this stuff happens on apache JIRA; the search term is project in (HADOOP, YARN, HDFS, MAPREDUCE) AND text ~ cve ORDER BY created DESC And we are cutting the 3.3.5 RC3 today; I just need to do the preflight checks before sending the emails. in