[GitHub] [hadoop] steveloughran commented on pull request #4491: HADOOP-18311. Upgrade dependencies to address several CVEs

2022-07-18 Thread GitBox
steveloughran commented on PR #4491: URL: https://github.com/apache/hadoop/pull/4491#issuecomment-1187077914 this patch includes another aws sdk update in a9c174b7d3e69b6eee1e271. steve, this merits a whole new jira with full qualification. as now it is very, very late to get it into

[GitHub] [hadoop] steveloughran commented on pull request #4491: HADOOP-18311. Upgrade dependencies to address several CVEs

2022-06-27 Thread GitBox
steveloughran commented on PR #4491: URL: https://github.com/apache/hadoop/pull/4491#issuecomment-1167721883 1. I've cherrypicked the aws sdk update we'd had in branch-3.3. 2. the jquery stuff should all be good now. 3. if htrace is still visible then that's a problem across the

[GitHub] [hadoop] steveloughran commented on pull request #4491: HADOOP-18311. Upgrade dependencies to address several CVEs

2022-06-25 Thread GitBox
steveloughran commented on PR #4491: URL: https://github.com/apache/hadoop/pull/4491#issuecomment-1166263641 oh, and -1. like I said, sorry. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

[GitHub] [hadoop] steveloughran commented on pull request #4491: HADOOP-18311. Upgrade dependencies to address several CVEs

2022-06-24 Thread GitBox
steveloughran commented on PR #4491: URL: https://github.com/apache/hadoop/pull/4491#issuecomment-1165578340 I have done the aws sdk update with followup patch, run the ITests with only an expected failure (marker tool and the landsat bucket). not going to do the others. however,

[GitHub] [hadoop] steveloughran commented on pull request #4491: HADOOP-18311. Upgrade dependencies to address several CVEs

2022-06-23 Thread GitBox
steveloughran commented on PR #4491: URL: https://github.com/apache/hadoop/pull/4491#issuecomment-1164763274 sorry, i confused jetty with jersey. don't know how jetty is on branch 3.3. it is not quite as bad as that jersey thing. -- This is an automated message from the Apache Git

[GitHub] [hadoop] steveloughran commented on pull request #4491: HADOOP-18311. Upgrade dependencies to address several CVEs

2022-06-23 Thread GitBox
steveloughran commented on PR #4491: URL: https://github.com/apache/hadoop/pull/4491#issuecomment-1164417288 (you are going to hate me here. sorry) First, please let's not have "update a few dependency" patches. Is it not a useful title and by updating multiple dependencies