[
https://issues.apache.org/jira/browse/YARN-5433?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15596734#comment-15596734
]
Sangjin Lee commented on YARN-5433:
-----------------------------------
I also see the servlet API and the jsp API included from jetty:
{noformat}
(CDDL 1.0) Glassfish Jasper (org.mortbay.jetty:jsp-2.1:6.1.14 -
http://jetty.mortbay.org/project/modules/jsp-2.1)
(CDDL 1.0) Servlet Specification 2.5 API
(org.mortbay.jetty:servlet-api-2.5:6.1.14 -
http://jetty.mortbay.org/project/modules/servlet-api-2.5)
{noformat}
I'm not sure if they have been analyzed and addressed already.
> Audit dependencies for Category-X
> ---------------------------------
>
> Key: YARN-5433
> URL: https://issues.apache.org/jira/browse/YARN-5433
> Project: Hadoop YARN
> Issue Type: Bug
> Components: timelineserver
> Affects Versions: 3.0.0-alpha1
> Reporter: Sean Busbey
> Assignee: Sangjin Lee
> Priority: Blocker
>
> Recently phoenix has found some category-x dependencies in their build
> (PHOENIX-3084, PHOENIX-3091), which also showed some problems in HBase
> (HBASE-16260).
> Since the Timeline Server work brought in both of these as dependencies, we
> should make sure we don't have any cat-x dependencies either. From what I've
> seen in those projects, our choice of HBase version shouldn't be impacted but
> our Phoenix one is.
> Greping our current dependency list for the timeline server component shows
> some LGPL:
> {code}
> ...
> [INFO] net.sourceforge.findbugs:annotations:jar:1.3.2:compile
> ...
> {code}
> I haven't checked the rest of the dependencies that have changed since
> HADOOP-12893 went in, so ATM I've filed this against YARN since that's where
> this one example came in.
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]