[GitHub] [spark] sarutak commented on pull request #31574: [SPARK-34449][BUILD] Upgrade Jetty to fix CVE-2020-27218

2021-02-18 Thread GitBox
sarutak commented on pull request #31574: URL: https://github.com/apache/spark/pull/31574#issuecomment-781252482 @HyukjinKwon Sure. I'll do it. This is an automated message from the Apache Git Service. To respond to the messa

[GitHub] [spark] sarutak commented on pull request #31574: [SPARK-34449][BUILD] Upgrade Jetty to fix CVE-2020-27218

2021-02-17 Thread GitBox
sarutak commented on pull request #31574: URL: https://github.com/apache/spark/pull/31574#issuecomment-781113672 As of 9.4.35, Jetty seems to change the behavior of handling the context path which doesn't have the trailing `/`. `v9.4.34` https://github.com/eclipse/jetty.project/b

[GitHub] [spark] sarutak commented on pull request #31574: [SPARK-34449][BUILD] Upgrade Jetty to fix CVE-2020-27218

2021-02-17 Thread GitBox
sarutak commented on pull request #31574: URL: https://github.com/apache/spark/pull/31574#issuecomment-780399873 I'll look into the cause of the failure. This is an automated message from the Apache Git Service. To respond to

[GitHub] [spark] sarutak commented on pull request #31574: [SPARK-34449][BUILD] Upgrade Jetty to fix CVE-2020-27218

2021-02-16 Thread GitBox
sarutak commented on pull request #31574: URL: https://github.com/apache/spark/pull/31574#issuecomment-780316712 @dongjoon-hyun Sorry for my late response. I don't think this CVE is not a blocker. This is an automated messag

[GitHub] [spark] sarutak commented on pull request #31574: [SPARK-34449][BUILD] Upgrade Jetty to fix CVE-2020-27218

2021-02-16 Thread GitBox
sarutak commented on pull request #31574: URL: https://github.com/apache/spark/pull/31574#issuecomment-780272740 cc: @HyukjinKwon and @dongjoon-hyun because you are release managers. This is an automated message from the Apac