[ 
https://issues.apache.org/jira/browse/YARN-11389?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17645417#comment-17645417
 ] 

ASF GitHub Bot commented on YARN-11389:
---------------------------------------

brahmareddybattula commented on PR #5192:
URL: https://github.com/apache/hadoop/pull/5192#issuecomment-1344585442

   HI @steveloughran  
   As @dmmkr mentioned updated maven plugin doesn't fixed this and as handle on 
#421 this change should be ok.
   Approach looks good to me now.
   Please let me know your thoughts.




> Upgrade spring-core to 5.3.20 in wro4j-maven-plugin 
> ----------------------------------------------------
>
>                 Key: YARN-11389
>                 URL: https://issues.apache.org/jira/browse/YARN-11389
>             Project: Hadoop YARN
>          Issue Type: Improvement
>          Components: build, yarn-ui-v2
>    Affects Versions: 3.4.0
>            Reporter: D M Murali Krishna Reddy
>            Assignee: D M Murali Krishna Reddy
>            Priority: Minor
>              Labels: pull-request-available, transitive-cve
>
> Currently during yarn-ui build we are using vulnerable version of 
> spring-core-3.1.1.RELEASE.jar which has serveral critical and high 
> vulnerablilites, we need to upgrade to a version 5.3.20+



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to