[ https://issues.apache.org/jira/browse/SPARK-38061?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17486344#comment-17486344 ]
Hyukjin Kwon commented on SPARK-38061: -------------------------------------- [~sujitbiswas] some changes are not backported because it is too breaking changes. To avoid CVEs, users should use Spark 3.3.0. Again, we should triage instead of just listing the dependencies by the report, and need to resolve one by one as each has a side effect of dependency resolution. > security scan issue jackson-databinding HDFS dependency library > --------------------------------------------------------------- > > Key: SPARK-38061 > URL: https://issues.apache.org/jira/browse/SPARK-38061 > Project: Spark > Issue Type: Bug > Components: Kubernetes, Security > Affects Versions: 3.2.0 > Reporter: Sujit Biswas > Priority: Major > Attachments: scan-security-report-spark-3.2.0-jre-11.csv > > > Hi, > running into security scan issue with docker image built on > spark-3.2.0-bin-hadoop3.2, is there a way to resolve > > most issues related to https://issues.apache.org/jira/browse/HDFS-15333 > attaching the CVE report > -- This message was sent by Atlassian Jira (v8.20.1#820001) --------------------------------------------------------------------- To unsubscribe, e-mail: issues-unsubscr...@spark.apache.org For additional commands, e-mail: issues-h...@spark.apache.org