RE: Dependencies used by Drill contain known vulnerabilities

2019-10-18 Thread Bradley Parker
ZOg=hsBDWgqUN16IByrh81JE1VQ3XJqGyuoBQmD8uAV4Rng=H9jTPsQZwIWD4ceIRB0dLwxapVuh3uL9ZJZE6101xLg=WA1z2Z2XlMfr9fX247y4RD4Q3QmXmN0nE1xWr4dwinA= >) and start the discussion. Thanks, -- C > On Oct 17, 2019, at 3:40 PM, Bradley Parker wrote: > > Hello Apache Drill Devs, > > We are looking to make use of Apach

Dependencies used by Drill contain known vulnerabilities

2019-10-17 Thread Bradley Parker
Hello Apache Drill Devs, We are looking to make use of Apache Drill for a project, as a member of our product security team I was asked to perform a dependency analysis of Drill. I identified 24 dependencies with known vulnerabilities using OWASP Dependency Scan. I found this in the archives