[GitHub] [tez] pjfanning commented on pull request #231: TEZ-4435: use jackson v2 - jackson v1 is EOL and full of security issues

2022-08-01 Thread GitBox
pjfanning commented on PR #231: URL: https://github.com/apache/tez/pull/231#issuecomment-1201417070 @abstractdog @ayushtkn would it be possible to get this merged? -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the

[GitHub] [tez] pjfanning commented on pull request #231: TEZ-4435: use jackson v2 - jackson v1 is EOL and full of security issues

2022-07-21 Thread GitBox
pjfanning commented on PR #231: URL: https://github.com/apache/tez/pull/231#issuecomment-1191370908 @ayushtkn I think I have the enforcement rule working now - the inherited=false flag seems to have stopped the rule being enforced in sub-modules. The 'restrictImports' XML tag seems to work

[GitHub] [tez] pjfanning commented on pull request #231: TEZ-4435: use jackson v2 - jackson v1 is EOL and full of security issues

2022-07-21 Thread GitBox
pjfanning commented on PR #231: URL: https://github.com/apache/tez/pull/231#issuecomment-1191353059 @ayushtkn looks like Hadoop is wrong according to the plugin's release notes -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub

[GitHub] [tez] pjfanning commented on pull request #231: TEZ-4435: use jackson v2 - jackson v1 is EOL and full of security issues

2022-07-21 Thread GitBox
pjfanning commented on PR #231: URL: https://github.com/apache/tez/pull/231#issuecomment-1191347179 @ayushtkn I've never used that plugin before. I checked its docs and the docs don't match what Hadoop has. In https://github.com/skuzzle/restrict-imports-enforcer-rule - the XML element is