[
https://issues.apache.org/jira/browse/HBASE-22728?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16912427#comment-16912427
]
Sean Busbey commented on HBASE-22728:
-------------------------------------
I'll leave a comment over there.
I think the same reasoning there is fine here [~vjasani]. Essentially, if
you're interested in doing the work of getting a branch-1.3 version landed
that's fine, but you should be aware that the current community consensus is to
not cut another release. To reverse that needs someone willing to step up to be
a release manager. It'd be easiest if that person was on the PMC and reasonably
straight forward if they're a committer. It's possible for anyone to do it in
theory.
> Upgrade jackson dependencies in branch-1
> ----------------------------------------
>
> Key: HBASE-22728
> URL: https://issues.apache.org/jira/browse/HBASE-22728
> Project: HBase
> Issue Type: Sub-task
> Affects Versions: 1.4.10, 1.3.5, 1.3.6
> Reporter: Andrew Purtell
> Assignee: Viraj Jasani
> Priority: Major
> Fix For: 1.5.0, 1.4.11
>
> Attachments: HBASE-22728-addendum.patch, HBASE-22728-addendum.patch,
> HBASE-22728.branch-1.01.patch, HBASE-22728.branch-1.02.patch,
> HBASE-22728.branch-1.04.patch, HBASE-22728.branch-1.06.patch,
> HBASE-22728.branch-1.10.patch, HBASE-22728.branch-1.11.patch,
> HBASE-22728.branch-1.12.patch, HBASE-22728.branch-1.14.patch,
> HBASE-22728.branch-1.15.patch, HBASE-22728.branch-1.16.patch,
> HBASE-22728.branch-1.18.patch, HBASE-22728.branch-1.19.patch
>
>
> Avoid Jackson versions and dependencies with known CVEs
--
This message was sent by Atlassian Jira
(v8.3.2#803003)