steveloughran opened a new pull request, #19:
URL: https://github.com/apache/hadoop-thirdparty/pull/19

   
   This patch bumps up the protobuf version so that Hadoop
   is not a vulnerable to CVE-2021-22569.
   
   I'm not renaming the module hadoop-shaded-protobuf_3_7
   because that significantly complicates imports/upgrading.
   That said, I don't see why the version number needed to be
   included there. We will have to live with that.
   
   This also fixes up the parent POM references in the child modules
   as IntelliJ requires a full path.
   
   Testing: needs to go through hadoop built with the updated jar and
   with its own protobuf version marker updated.
   Verified hadoop compiles on a macbook m1.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: common-dev-unsubscr...@hadoop.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org


---------------------------------------------------------------------
To unsubscribe, e-mail: common-dev-unsubscr...@hadoop.apache.org
For additional commands, e-mail: common-dev-h...@hadoop.apache.org

Reply via email to