This is an automated email from the ASF dual-hosted git repository.
epugh pushed a commit to branch branch_9x
in repository https://gitbox.apache.org/repos/asf/solr.git
The following commit(s) were added to refs/heads/branch_9x by this push:
new f0e65244394 Update hadoop thirdparty jars to avoid CVEs (#3487)
f0e65244394 is described below
commit f0e65244394838b97d40faba02aafc56fe69a022
Author: Eric Pugh <[email protected]>
AuthorDate: Tue Aug 19 11:59:14 2025 -0400
Update hadoop thirdparty jars to avoid CVEs (#3487)
---
solr/licenses/hadoop-shaded-guava-1.2.0.jar.sha1 | 1 -
solr/licenses/hadoop-shaded-guava-1.3.0.jar.sha1 | 1 +
versions.lock | 2 +-
versions.props | 2 +-
4 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/solr/licenses/hadoop-shaded-guava-1.2.0.jar.sha1
b/solr/licenses/hadoop-shaded-guava-1.2.0.jar.sha1
deleted file mode 100644
index 2e3ae98fd2c..00000000000
--- a/solr/licenses/hadoop-shaded-guava-1.2.0.jar.sha1
+++ /dev/null
@@ -1 +0,0 @@
-a0a6e7aa87c838ea418fc36ed290987dd90f5f6c
diff --git a/solr/licenses/hadoop-shaded-guava-1.3.0.jar.sha1
b/solr/licenses/hadoop-shaded-guava-1.3.0.jar.sha1
new file mode 100644
index 00000000000..807b7b0f8eb
--- /dev/null
+++ b/solr/licenses/hadoop-shaded-guava-1.3.0.jar.sha1
@@ -0,0 +1 @@
+45acdc211dc81757d080ed284fdf54de866e7eaf
diff --git a/versions.lock b/versions.lock
index 5fac5375b10..92bb063ea0a 100644
--- a/versions.lock
+++ b/versions.lock
@@ -219,7 +219,7 @@ org.apache.hadoop:hadoop-auth:3.4.1 (1 constraints:
0a050736)
org.apache.hadoop:hadoop-client-api:3.4.1 (3 constraints: 1928b25e)
org.apache.hadoop:hadoop-client-runtime:3.4.1 (2 constraints: 67170843)
org.apache.hadoop:hadoop-common:3.4.1 (1 constraints: 0a050736)
-org.apache.hadoop.thirdparty:hadoop-shaded-guava:1.2.0 (1 constraints:
0505f635)
+org.apache.hadoop.thirdparty:hadoop-shaded-guava:1.3.0 (1 constraints:
0605f935)
org.apache.httpcomponents:httpclient:4.5.14 (9 constraints: 62806342)
org.apache.httpcomponents:httpcore:4.4.16 (8 constraints: 286d4917)
org.apache.httpcomponents:httpmime:4.5.14 (3 constraints: eb1bfedc)
diff --git a/versions.props b/versions.props
index 393650c2401..2e52668fdab 100644
--- a/versions.props
+++ b/versions.props
@@ -45,7 +45,7 @@ org.apache.commons:commons-exec=1.4.0
org.apache.commons:commons-lang3=3.15.0
org.apache.commons:commons-math3=3.6.1
org.apache.curator:*=5.7.0
-org.apache.hadoop.thirdparty:*=1.2.0
+org.apache.hadoop.thirdparty:*=1.3.0
org.apache.hadoop:*=3.4.1
org.apache.httpcomponents:httpclient=4.5.14
org.apache.httpcomponents:httpcore=4.4.16