[ 
https://issues.apache.org/jira/browse/SPARK-38061?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17486344#comment-17486344
 ] 

Hyukjin Kwon commented on SPARK-38061:
--------------------------------------

[~sujitbiswas] some changes are not backported because it is too breaking 
changes. To avoid CVEs, users should use Spark 3.3.0.
Again, we should triage instead of just listing the dependencies by the report, 
and need to resolve one by one as each has a side effect of dependency 
resolution.

> security scan issue jackson-databinding HDFS dependency library
> ---------------------------------------------------------------
>
>                 Key: SPARK-38061
>                 URL: https://issues.apache.org/jira/browse/SPARK-38061
>             Project: Spark
>          Issue Type: Bug
>          Components: Kubernetes, Security
>    Affects Versions: 3.2.0
>            Reporter: Sujit Biswas
>            Priority: Major
>         Attachments: scan-security-report-spark-3.2.0-jre-11.csv
>
>
> Hi,
> running into security scan issue with docker image built on 
> spark-3.2.0-bin-hadoop3.2, is there a way to resolve 
>  
> most issues related to https://issues.apache.org/jira/browse/HDFS-15333 
> attaching the CVE report
>  



--
This message was sent by Atlassian Jira
(v8.20.1#820001)

---------------------------------------------------------------------
To unsubscribe, e-mail: issues-unsubscr...@spark.apache.org
For additional commands, e-mail: issues-h...@spark.apache.org

Reply via email to