[jira] [Created] (HADOOP-13332) Remove jackson 1.9.13 and switch all jackson code to 2.x code line

2016-06-29 Thread PJ Fanning (JIRA)
PJ Fanning created HADOOP-13332: --- Summary: Remove jackson 1.9.13 and switch all jackson code to 2.x code line Key: HADOOP-13332 URL: https://issues.apache.org/jira/browse/HADOOP-13332 Project: Hadoop

[jira] [Comment Edited] (HADOOP-12705) Upgrade Jackson 2.2.3 to 2.5.3 or later

2016-06-29 Thread PJ Fanning (JIRA)
[ https://issues.apache.org/jira/browse/HADOOP-12705?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15355860#comment-15355860 ] PJ Fanning edited comment on HADOOP-12705 at 6/29/16 9:58 PM: -- [@aajisaka]

[jira] [Commented] (HADOOP-12705) Upgrade Jackson 2.2.3 to 2.5.3 or later

2016-06-29 Thread PJ Fanning (JIRA)
[ https://issues.apache.org/jira/browse/HADOOP-12705?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15355860#comment-15355860 ] PJ Fanning commented on HADOOP-12705: - [@akira.ajisaka]

[jira] [Updated] (HADOOP-13332) Remove jackson 1.9.13 and switch all jackson code to 2.x code line

2016-06-29 Thread PJ Fanning (JIRA)
[ https://issues.apache.org/jira/browse/HADOOP-13332?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-13332: Description: This jackson 1.9 code line is no longer maintained and has a number of issues,

[jira] [Commented] (HADOOP-12705) Upgrade Jackson 2.2.3 to 2.5.3 or later

2016-06-29 Thread PJ Fanning (JIRA)
[ https://issues.apache.org/jira/browse/HADOOP-12705?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15355804#comment-15355804 ] PJ Fanning commented on HADOOP-12705: - Can we upgrade to jackson v2.7.6 or v2.8.0 - these versions

[jira] [Comment Edited] (HADOOP-12705) Upgrade Jackson 2.2.3 to 2.5.3 or later

2016-06-29 Thread PJ Fanning (JIRA)
[ https://issues.apache.org/jira/browse/HADOOP-12705?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15355860#comment-15355860 ] PJ Fanning edited comment on HADOOP-12705 at 6/29/16 10:00 PM: ---

[jira] [Commented] (HADOOP-12705) Upgrade Jackson 2.2.3 to 2.5.3 or later

2016-11-02 Thread PJ Fanning (JIRA)
[ https://issues.apache.org/jira/browse/HADOOP-12705?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15629174#comment-15629174 ] PJ Fanning commented on HADOOP-12705: - I think only 2.7.6 and 2.8.x have the XEE fix. > Upgrade

[jira] [Created] (HADOOP-15064) hadoop-common 3.0.0-beta1 exposes a dependency on slf4j-log4j12

2017-11-22 Thread PJ Fanning (JIRA)
PJ Fanning created HADOOP-15064: --- Summary: hadoop-common 3.0.0-beta1 exposes a dependency on slf4j-log4j12 Key: HADOOP-15064 URL: https://issues.apache.org/jira/browse/HADOOP-15064 Project: Hadoop

[jira] [Updated] (HADOOP-15064) hadoop-common 3.0.0-beta1 exposes a dependency on slf4j-log4j12

2017-11-22 Thread PJ Fanning (JIRA)
[ https://issues.apache.org/jira/browse/HADOOP-15064?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-15064: Description: https://mvnrepository.com/artifact/org.apache.hadoop/hadoop-common/3.0.0-beta1

[jira] [Updated] (HADOOP-15064) hadoop-common and hadoop-auth 3.0.0-beta1 expose a dependency on slf4j-log4j12

2017-11-22 Thread PJ Fanning (JIRA)
[ https://issues.apache.org/jira/browse/HADOOP-15064?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-15064: Summary: hadoop-common and hadoop-auth 3.0.0-beta1 expose a dependency on slf4j-log4j12 (was:

[jira] [Updated] (HADOOP-15064) hadoop-common 3.0.0-beta1 exposes a dependency on slf4j-log4j12

2017-11-22 Thread PJ Fanning (JIRA)
[ https://issues.apache.org/jira/browse/HADOOP-15064?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-15064: Affects Version/s: 3.0.0-beta1 > hadoop-common 3.0.0-beta1 exposes a dependency on slf4j-log4j12

[jira] [Updated] (HADOOP-15064) hadoop-common 3.0.0-beta1 exposes a dependency on slf4j-log4j12

2017-11-22 Thread PJ Fanning (JIRA)
[ https://issues.apache.org/jira/browse/HADOOP-15064?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-15064: Environment: (was:

[jira] [Updated] (HADOOP-15064) hadoop-common 3.0.0-beta1 exposes a dependency on slf4j-log4j12

2017-11-22 Thread PJ Fanning (JIRA)
[ https://issues.apache.org/jira/browse/HADOOP-15064?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-15064: Description: https://mvnrepository.com/artifact/org.apache.hadoop/hadoop-common/3.0.0-beta1 One

[jira] [Updated] (HADOOP-15054) upgrade hadoop dependency on commons-codec to 1.11

2017-11-20 Thread PJ Fanning (JIRA)
[ https://issues.apache.org/jira/browse/HADOOP-15054?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-15054: Summary: upgrade hadoop dependency on commons-codec to 1.11 (was: upgrade hadoop-auth dependency

[jira] [Updated] (HADOOP-15054) upgrade hadoop dependency on commons-codec to 1.11

2017-11-20 Thread PJ Fanning (JIRA)
[ https://issues.apache.org/jira/browse/HADOOP-15054?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-15054: Description: https://mvnrepository.com/artifact/org.apache.hadoop/hadoop-auth/3.0.0-beta1

[jira] [Created] (HADOOP-15054) upgrade hadoop-auth dependency on commons-codec to 1.11

2017-11-20 Thread PJ Fanning (JIRA)
PJ Fanning created HADOOP-15054: --- Summary: upgrade hadoop-auth dependency on commons-codec to 1.11 Key: HADOOP-15054 URL: https://issues.apache.org/jira/browse/HADOOP-15054 Project: Hadoop Common

[jira] [Updated] (HADOOP-15804) upgrade to commons-compress 1.18

2018-09-29 Thread PJ Fanning (JIRA)
[ https://issues.apache.org/jira/browse/HADOOP-15804?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-15804: Description: [https://github.com/apache/commons-compress/blob/master/RELEASE-NOTES.txt] Some

[jira] [Created] (HADOOP-15804) upgrade to commons-compress 1.18

2018-09-29 Thread PJ Fanning (JIRA)
PJ Fanning created HADOOP-15804: --- Summary: upgrade to commons-compress 1.18 Key: HADOOP-15804 URL: https://issues.apache.org/jira/browse/HADOOP-15804 Project: Hadoop Common Issue Type:

[jira] [Updated] (HADOOP-15804) upgrade to commons-compress 1.18

2018-09-29 Thread PJ Fanning (JIRA)
[ https://issues.apache.org/jira/browse/HADOOP-15804?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-15804: Description: [https://github.com/apache/commons-compress/blob/master/RELEASE-NOTES.txt] Some

[jira] [Updated] (HADOOP-18126) junit-vintage tests seem to be failing

2022-02-15 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18126?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-18126: Description: {code:java} Feb 11, 2022 11:31:43 AM

[jira] [Created] (HADOOP-18126) junit-vintage tests seem to be failing

2022-02-15 Thread PJ Fanning (Jira)
PJ Fanning created HADOOP-18126: --- Summary: junit-vintage tests seem to be failing Key: HADOOP-18126 URL: https://issues.apache.org/jira/browse/HADOOP-18126 Project: Hadoop Common Issue Type:

[jira] [Commented] (HADOOP-15983) Remove the usage of jersey-json to remove jackson 1.x dependency.

2022-02-13 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-15983?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17491706#comment-17491706 ] PJ Fanning commented on HADOOP-15983: - [~aajisaka] the repo with my changes is at

[jira] [Commented] (HADOOP-13386) Upgrade Avro to 1.8.x or later

2022-02-11 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-13386?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17491102#comment-17491102 ] PJ Fanning commented on HADOOP-13386: - Can this issue be reconsidered? Avro 1.7.7 brings a

[jira] [Commented] (HADOOP-15983) Remove the usage of jersey-json to remove jackson 1.x dependency.

2022-02-14 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-15983?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17492159#comment-17492159 ] PJ Fanning commented on HADOOP-15983: - [~aajisaka] the javee jersey-jackson uses jackson1 in many

[jira] [Commented] (HADOOP-15983) Remove the usage of jersey-json to remove jackson 1.x dependency.

2022-02-11 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-15983?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17491084#comment-17491084 ] PJ Fanning commented on HADOOP-15983: - I created

[jira] [Commented] (HADOOP-15983) Remove the usage of jersey-json to remove jackson 1.x dependency.

2022-02-11 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-15983?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17491103#comment-17491103 ] PJ Fanning commented on HADOOP-15983: - HADOOP-13386 is also needed to get rid of jackson 1 >

[jira] [Created] (HADOOP-18165) hadoop-yarn-ui has a number of insecure dependencies

2022-03-19 Thread PJ Fanning (Jira)
PJ Fanning created HADOOP-18165: --- Summary: hadoop-yarn-ui has a number of insecure dependencies Key: HADOOP-18165 URL: https://issues.apache.org/jira/browse/HADOOP-18165 Project: Hadoop Common

[jira] [Created] (HADOOP-18178) upgrade jackson-databind to 2.13.2.1 due to cve

2022-03-26 Thread PJ Fanning (Jira)
PJ Fanning created HADOOP-18178: --- Summary: upgrade jackson-databind to 2.13.2.1 due to cve Key: HADOOP-18178 URL: https://issues.apache.org/jira/browse/HADOOP-18178 Project: Hadoop Common

[jira] [Commented] (HADOOP-18180) Remove use of scala jar twitter util-core

2022-03-28 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18180?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17513433#comment-17513433 ] PJ Fanning commented on HADOOP-18180: - [~ste...@apache.org] thanks for checking this. I'm not

[jira] [Created] (HADOOP-18180) Remove use of scala jar twitter util-core

2022-03-28 Thread PJ Fanning (Jira)
PJ Fanning created HADOOP-18180: --- Summary: Remove use of scala jar twitter util-core Key: HADOOP-18180 URL: https://issues.apache.org/jira/browse/HADOOP-18180 Project: Hadoop Common Issue

[jira] [Commented] (HADOOP-18180) Remove use of scala jar twitter util-core

2022-03-28 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18180?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17513380#comment-17513380 ] PJ Fanning commented on HADOOP-18180: - Added https://github.com/apache/hadoop/pull/4115 > Remove

[jira] [Comment Edited] (HADOOP-18028) High performance S3A input stream with prefetching & caching

2022-03-30 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18028?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17514996#comment-17514996 ] PJ Fanning edited comment on HADOOP-18028 at 3/31/22, 12:36 AM: Would

[jira] [Commented] (HADOOP-18028) High performance S3A input stream with prefetching & caching

2022-03-30 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18028?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17514996#comment-17514996 ] PJ Fanning commented on HADOOP-18028: - Would it be possible to consider switching the AWS v2 SDK

[jira] [Commented] (HADOOP-15983) Remove the usage of jersey-json to remove jackson 1.x dependency.

2022-02-10 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-15983?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17490610#comment-17490610 ] PJ Fanning commented on HADOOP-15983: - I guess that this issue should be renamed to reflect that

[jira] [Commented] (HADOOP-15983) Remove the usage of jersey-json to remove jackson 1.x dependency.

2022-02-11 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-15983?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17490883#comment-17490883 ] PJ Fanning commented on HADOOP-15983: - [~aajisaka] I had a look at jersey-json 1.19.4 and looks

[jira] [Created] (HADOOP-18195) make jackson v1 a runtime scope dependency

2022-04-07 Thread PJ Fanning (Jira)
PJ Fanning created HADOOP-18195: --- Summary: make jackson v1 a runtime scope dependency Key: HADOOP-18195 URL: https://issues.apache.org/jira/browse/HADOOP-18195 Project: Hadoop Common Issue

[jira] [Updated] (HADOOP-18195) make jackson v1 a runtime scope dependency

2022-04-07 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18195?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-18195: Description: In trunk, jackson v1 is only needed as a transitive dependency of jersey-json

[jira] [Updated] (HADOOP-18178) upgrade jackson-databind to 2.13.2.2 due to cve

2022-04-06 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18178?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-18178: Summary: upgrade jackson-databind to 2.13.2.2 due to cve (was: upgrade jackson-databind to

[jira] [Updated] (HADOOP-18895) upgrade to commons-compress 1.24.0 due to CVE

2023-09-14 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18895?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-18895: Description: Includes some important bug fixes including

[jira] [Updated] (HADOOP-18895) upgrade to commons-compress 1.24.0 due to CVE

2023-09-14 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18895?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-18895: Summary: upgrade to commons-compress 1.24.0 due to CVE (was: upgrade to commons-compress

[jira] [Created] (HADOOP-18890) remove okhttp usage

2023-09-12 Thread PJ Fanning (Jira)
PJ Fanning created HADOOP-18890: --- Summary: remove okhttp usage Key: HADOOP-18890 URL: https://issues.apache.org/jira/browse/HADOOP-18890 Project: Hadoop Common Issue Type: Bug

[jira] [Commented] (HADOOP-18890) remove okhttp usage

2023-09-12 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18890?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17764306#comment-17764306 ] PJ Fanning commented on HADOOP-18890: - It seems to be used in a few places - notably

[jira] [Created] (HADOOP-18894) upgrade sshd-core due to CVEs

2023-09-13 Thread PJ Fanning (Jira)
PJ Fanning created HADOOP-18894: --- Summary: upgrade sshd-core due to CVEs Key: HADOOP-18894 URL: https://issues.apache.org/jira/browse/HADOOP-18894 Project: Hadoop Common Issue Type: Bug

[jira] [Updated] (HADOOP-18894) upgrade sshd-core due to CVEs

2023-09-13 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18894?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-18894: Description: https://mvnrepository.com/artifact/org.apache.sshd/sshd-core hadoop currently uses

[jira] [Created] (HADOOP-18895) upgrade to commons-compress 1.24.0

2023-09-13 Thread PJ Fanning (Jira)
PJ Fanning created HADOOP-18895: --- Summary: upgrade to commons-compress 1.24.0 Key: HADOOP-18895 URL: https://issues.apache.org/jira/browse/HADOOP-18895 Project: Hadoop Common Issue Type:

[jira] [Updated] (HADOOP-18895) upgrade to commons-compress 1.24.0 due to CVE

2023-09-14 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18895?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-18895: Description: Includes some important bug fixes including

[jira] [Created] (HADOOP-18933) upgrade netty to 4.1.100 due to CVE

2023-10-11 Thread PJ Fanning (Jira)
PJ Fanning created HADOOP-18933: --- Summary: upgrade netty to 4.1.100 due to CVE Key: HADOOP-18933 URL: https://issues.apache.org/jira/browse/HADOOP-18933 Project: Hadoop Common Issue Type:

[jira] [Created] (HADOOP-18957) Use StandardCharsets.UTF_8 constant

2023-10-27 Thread PJ Fanning (Jira)
PJ Fanning created HADOOP-18957: --- Summary: Use StandardCharsets.UTF_8 constant Key: HADOOP-18957 URL: https://issues.apache.org/jira/browse/HADOOP-18957 Project: Hadoop Common Issue Type:

[jira] [Updated] (HADOOP-18957) Use StandardCharsets.UTF_8 constant

2023-10-27 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18957?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-18957: Description: * there are some places in the code that have to check for

[jira] [Created] (HADOOP-18949) upgrade maven dependency plugin due to security issue

2023-10-23 Thread PJ Fanning (Jira)
PJ Fanning created HADOOP-18949: --- Summary: upgrade maven dependency plugin due to security issue Key: HADOOP-18949 URL: https://issues.apache.org/jira/browse/HADOOP-18949 Project: Hadoop Common

[jira] [Commented] (HADOOP-18936) Upgrade to jetty 9.4.53

2023-10-30 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18936?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17781027#comment-17781027 ] PJ Fanning commented on HADOOP-18936: - [~coheigea] [~ayushtkn] I created

[jira] [Created] (HADOOP-18912) upgrade snappy-java to 1.1.10.4 due to CVE

2023-09-25 Thread PJ Fanning (Jira)
PJ Fanning created HADOOP-18912: --- Summary: upgrade snappy-java to 1.1.10.4 due to CVE Key: HADOOP-18912 URL: https://issues.apache.org/jira/browse/HADOOP-18912 Project: Hadoop Common Issue

[jira] [Created] (HADOOP-18916) module-info classes from external dependencies appearing in uber jars

2023-09-30 Thread PJ Fanning (Jira)
PJ Fanning created HADOOP-18916: --- Summary: module-info classes from external dependencies appearing in uber jars Key: HADOOP-18916 URL: https://issues.apache.org/jira/browse/HADOOP-18916 Project:

[jira] [Commented] (HADOOP-17225) Update jackson-mapper-asl-1.9.13 to atlassian version to mitigate: CVE-2019-10172

2023-09-30 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-17225?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17770690#comment-17770690 ] PJ Fanning commented on HADOOP-17225: - This can probably be closed because latest hadoop 3.3

[jira] [Updated] (HADOOP-18916) module-info classes from external dependencies appearing in uber jars

2023-09-30 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18916?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-18916: Description: hadoop-client-minicluster and hadoop-client-runtime try unsuccessfully to exclude

[jira] [Created] (HADOOP-18917) upgrade to commons-io 2.14.0

2023-09-30 Thread PJ Fanning (Jira)
PJ Fanning created HADOOP-18917: --- Summary: upgrade to commons-io 2.14.0 Key: HADOOP-18917 URL: https://issues.apache.org/jira/browse/HADOOP-18917 Project: Hadoop Common Issue Type: Improvement

[jira] [Created] (HADOOP-18921) upgrade avro in hadoop-thirdparty to 1.11.3

2023-10-04 Thread PJ Fanning (Jira)
PJ Fanning created HADOOP-18921: --- Summary: upgrade avro in hadoop-thirdparty to 1.11.3 Key: HADOOP-18921 URL: https://issues.apache.org/jira/browse/HADOOP-18921 Project: Hadoop Common Issue

[jira] [Created] (HADOOP-18924) upgrade grpc jars to v1.53.0 due to CVEs

2023-10-09 Thread PJ Fanning (Jira)
PJ Fanning created HADOOP-18924: --- Summary: upgrade grpc jars to v1.53.0 due to CVEs Key: HADOOP-18924 URL: https://issues.apache.org/jira/browse/HADOOP-18924 Project: Hadoop Common Issue Type:

[jira] [Updated] (HADOOP-18936) upgrade jetty to 9.4.53 due to CVEs

2023-10-12 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18936?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-18936: Description: 2 CVE fixes in

[jira] [Created] (HADOOP-18936) upgrade jetty to 9.4.53 due to CVEs

2023-10-12 Thread PJ Fanning (Jira)
PJ Fanning created HADOOP-18936: --- Summary: upgrade jetty to 9.4.53 due to CVEs Key: HADOOP-18936 URL: https://issues.apache.org/jira/browse/HADOOP-18936 Project: Hadoop Common Issue Type:

[jira] [Commented] (HADOOP-18359) Update commons-cli from 1.2 to 1.5.

2023-10-19 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18359?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=1299#comment-1299 ] PJ Fanning commented on HADOOP-18359: - [~coheigea] I have not been involved with this issue. I am

[jira] [Commented] (HADOOP-18929) Build failure while trying to create apache 3.3.7 release locally.

2023-10-10 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18929?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17773810#comment-17773810 ] PJ Fanning commented on HADOOP-18929: - It looks like commons-compress 1.24.0 is the 1st

[jira] [Commented] (HADOOP-18929) Build failure while trying to create apache 3.3.7 release locally.

2023-10-10 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18929?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17773818#comment-17773818 ] PJ Fanning commented on HADOOP-18929: - https://github.com/apache/hadoop/pull/6169 > Build failure

[jira] [Updated] (HADOOP-18332) remove rs-api dependency

2022-07-11 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18332?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-18332: Description: This jsr311-api jar seems to conflict with newly added rs-api jar dependency -

[jira] [Commented] (HADOOP-18033) Upgrade fasterxml Jackson to 2.13.0

2022-07-11 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18033?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17565050#comment-17565050 ] PJ Fanning commented on HADOOP-18033: - So the Tez issue seems (possibly) to be caused by

[jira] [Updated] (HADOOP-18332) remove rs-api dependency

2022-07-11 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18332?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-18332: Description: This jsr311-api jar seems to conflict with newly added rs-api jar dependency -

[jira] [Updated] (HADOOP-18332) remove rs-api dependency (needs jackson downgrade to 2.12.7)

2022-07-11 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18332?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-18332: Summary: remove rs-api dependency (needs jackson downgrade to 2.12.7) (was: remove rs-api

[jira] [Updated] (HADOOP-18165) hadoop-yarn-ui has a number of insecure dependencies

2022-07-12 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18165?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-18165: Description: Many of these are rates as critical or high risk vulnerabilities. This list is the

[jira] [Created] (HADOOP-18332) remove jsr311-api dependency

2022-07-11 Thread PJ Fanning (Jira)
PJ Fanning created HADOOP-18332: --- Summary: remove jsr311-api dependency Key: HADOOP-18332 URL: https://issues.apache.org/jira/browse/HADOOP-18332 Project: Hadoop Common Issue Type: Improvement

[jira] [Commented] (HADOOP-18033) Upgrade fasterxml Jackson to 2.13.0

2022-07-11 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18033?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17564966#comment-17564966 ] PJ Fanning commented on HADOOP-18033: - [~ayushtkn] would

[jira] [Commented] (HADOOP-18180) Remove use of scala jar twitter util-core with java futures in S3A prefetching stream

2022-06-29 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18180?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17560627#comment-17560627 ] PJ Fanning commented on HADOOP-18180: - [~ahmarsu] Feel free to remove the ExecutorServicePool and

[jira] [Commented] (HADOOP-18033) Upgrade fasterxml Jackson to 2.13.0

2022-07-12 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18033?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17565978#comment-17565978 ] PJ Fanning commented on HADOOP-18033: - [~ste...@apache.org] I've had to make a change to

[jira] [Created] (HADOOP-18342) Upgrade to Avro 1.11.0

2022-07-18 Thread PJ Fanning (Jira)
PJ Fanning created HADOOP-18342: --- Summary: Upgrade to Avro 1.11.0 Key: HADOOP-18342 URL: https://issues.apache.org/jira/browse/HADOOP-18342 Project: Hadoop Common Issue Type: Improvement

[jira] [Updated] (HADOOP-18342) Upgrade to Avro 1.11.0

2022-07-18 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18342?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-18342: Description: Latest version of Avro. Aimed only at trunk as there is no security concern

[jira] [Created] (HADOOP-18343) upgrade to jetty 9.4.47 due to CVE

2022-07-18 Thread PJ Fanning (Jira)
PJ Fanning created HADOOP-18343: --- Summary: upgrade to jetty 9.4.47 due to CVE Key: HADOOP-18343 URL: https://issues.apache.org/jira/browse/HADOOP-18343 Project: Hadoop Common Issue Type:

[jira] [Updated] (HADOOP-18341) upgrade to commons-configuration2 2.8.0

2022-07-18 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18341?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-18341: Description: Current version 2.1.1 has no CVEs but all higher versions have CVEs except for the

[jira] [Commented] (HADOOP-18342) Upgrade to Avro 1.11.0

2022-07-18 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18342?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17567945#comment-17567945 ] PJ Fanning commented on HADOOP-18342: - [~ste...@apache.org] this is not a high priority. I found a

[jira] [Created] (HADOOP-18341) upgrade to commons-configuration2 2.8.0

2022-07-18 Thread PJ Fanning (Jira)
PJ Fanning created HADOOP-18341: --- Summary: upgrade to commons-configuration2 2.8.0 Key: HADOOP-18341 URL: https://issues.apache.org/jira/browse/HADOOP-18341 Project: Hadoop Common Issue Type:

[jira] [Commented] (HADOOP-18343) upgrade to jetty 9.4.48 due to CVE

2022-07-18 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18343?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17567933#comment-17567933 ] PJ Fanning commented on HADOOP-18343: - Apologies [~groot], I missed that issue - thanks for closing

[jira] [Commented] (HADOOP-18333) hadoop-client-runtime impact by CVE-2022-2047 due to shaded jetty

2022-07-18 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18333?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17567946#comment-17567946 ] PJ Fanning commented on HADOOP-18333: - [~ste...@apache.org] Is this a change that could be

[jira] [Updated] (HADOOP-18343) upgrade to jetty 9.4.48 due to CVE

2022-07-18 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18343?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-18343: Description: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2047 Use 9.4.48 (latest

[jira] [Created] (HADOOP-18354) upgrade reload4j due to XXE vulnerability

2022-07-21 Thread PJ Fanning (Jira)
PJ Fanning created HADOOP-18354: --- Summary: upgrade reload4j due to XXE vulnerability Key: HADOOP-18354 URL: https://issues.apache.org/jira/browse/HADOOP-18354 Project: Hadoop Common Issue

[jira] [Updated] (HADOOP-18342) Upgrade to Avro 1.11.1

2022-08-30 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18342?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-18342: Summary: Upgrade to Avro 1.11.1 (was: Upgrade to Avro 1.11.0) > Upgrade to Avro 1.11.1 >

[jira] [Commented] (HADOOP-18342) Upgrade to Avro 1.11.1

2022-09-01 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18342?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17599131#comment-17599131 ] PJ Fanning commented on HADOOP-18342: - [~ste...@apache.org] does

[jira] [Created] (HADOOP-18441) remove org.apache.hadoop.maven.plugin.shade.resource.ServicesResourceTransformer

2022-09-04 Thread PJ Fanning (Jira)
PJ Fanning created HADOOP-18441: --- Summary: remove org.apache.hadoop.maven.plugin.shade.resource.ServicesResourceTransformer Key: HADOOP-18441 URL: https://issues.apache.org/jira/browse/HADOOP-18441

[jira] [Updated] (HADOOP-18342) Upgrade to Avro 1.11.1

2022-08-31 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18342?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-18342: Labels: (was: pull-request-available) > Upgrade to Avro 1.11.1 > -- > >

[jira] [Updated] (HADOOP-18469) Add XMLUtils methods to centralise code that creates secure XML parsers

2022-09-27 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18469?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-18469: Summary: Add XMLUtils methods to centralise code that creates secure XML parsers (was: Add an

[jira] [Updated] (HADOOP-18469) Add an XMLUtils method to centralise code that creates secure XML parsers

2022-09-27 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18469?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-18469: Summary: Add an XMLUtils method to centralise code that creates secure XML parsers (was: Add an

[jira] [Created] (HADOOP-18469) Add an XMLUtils class to centralise code that creates secure XML parsers

2022-09-27 Thread PJ Fanning (Jira)
PJ Fanning created HADOOP-18469: --- Summary: Add an XMLUtils class to centralise code that creates secure XML parsers Key: HADOOP-18469 URL: https://issues.apache.org/jira/browse/HADOOP-18469 Project:

[jira] [Commented] (HADOOP-18497) Upgrade commons-text version to fix CVE-2022-42889

2022-10-18 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18497?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17619609#comment-17619609 ] PJ Fanning commented on HADOOP-18497: - This CVE is starting to get a lot of press and social media

[jira] [Commented] (HADOOP-15983) Use jersey-json that is built to use jackson2

2022-10-19 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-15983?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17620662#comment-17620662 ] PJ Fanning commented on HADOOP-15983: - [~ste...@apache.org] I can look at doing a PR for the 3.3

[jira] [Commented] (HADOOP-18512) upgrade woodstox-core to 5.4.0 for security fix

2022-10-28 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18512?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17625587#comment-17625587 ] PJ Fanning commented on HADOOP-18512: - Not likely to be something that can be exploited but to keep

[jira] [Comment Edited] (HADOOP-18443) Upgrade snakeyaml to 1.32

2022-09-19 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18443?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17606797#comment-17606797 ] PJ Fanning edited comment on HADOOP-18443 at 9/19/22 11:43 PM: --- [~groot]

[jira] [Commented] (HADOOP-18443) Upgrade snakeyaml to 1.32

2022-09-19 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18443?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17606797#comment-17606797 ] PJ Fanning commented on HADOOP-18443: - [~groot] it looks like snakeyaml now limits the size of the

[jira] [Comment Edited] (HADOOP-18443) Upgrade snakeyaml to 1.32

2022-09-19 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18443?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17606797#comment-17606797 ] PJ Fanning edited comment on HADOOP-18443 at 9/20/22 12:17 AM: --- [~groot]

[jira] [Commented] (HADOOP-18443) Upgrade snakeyaml to 1.31 to mitigate CVE-2022-25857

2022-09-18 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18443?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17606265#comment-17606265 ] PJ Fanning commented on HADOOP-18443: - v1.32 was released and added another security fix - would it

[jira] [Created] (HADOOP-18468) upgrade jettison json jar due to security issue

2022-09-25 Thread PJ Fanning (Jira)
PJ Fanning created HADOOP-18468: --- Summary: upgrade jettison json jar due to security issue Key: HADOOP-18468 URL: https://issues.apache.org/jira/browse/HADOOP-18468 Project: Hadoop Common

[jira] [Updated] (HADOOP-18468) upgrade jettison json jar due to security issue

2022-09-25 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18468?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] PJ Fanning updated HADOOP-18468: Description: A fix for [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-40149]  

[jira] [Created] (HADOOP-18472) Upgrade to snakeyaml 1.33

2022-10-01 Thread PJ Fanning (Jira)
PJ Fanning created HADOOP-18472: --- Summary: Upgrade to snakeyaml 1.33 Key: HADOOP-18472 URL: https://issues.apache.org/jira/browse/HADOOP-18472 Project: Hadoop Common Issue Type: Improvement

[jira] [Created] (HADOOP-18492) upgrade commons-text to 1.10.0

2022-10-12 Thread PJ Fanning (Jira)
PJ Fanning created HADOOP-18492: --- Summary: upgrade commons-text to 1.10.0 Key: HADOOP-18492 URL: https://issues.apache.org/jira/browse/HADOOP-18492 Project: Hadoop Common Issue Type:

  1   2   >