Re: Apache Ignite H2 Vulnerabilities

2022-05-06 Thread Lokesh Bandaru
release 2.14. > > On Tue, 3 May 2022 at 15:17, Lokesh Bandaru > wrote: > > > > Thanks Stephen. > > Not sure if this is the right forum but wanted to check if there is a > plan already to come up with a vulnerability free way of using Ignite? > > Or if there is a way

Re: Apache Ignite H2 Vulnerabilities

2022-05-03 Thread Lokesh Bandaru
wrote: > That is my understanding, yes. > > On 2 May 2022, at 09:28, Lokesh Bandaru wrote: > > Thank you Stephen/Nikita. > Looks like version 2.13 still depends on the older H2 versions - those > with vulnerabilities. > And as the dependencies are all hard, there doesn't seem to be

Re: Apache Ignite H2 Vulnerabilities

2022-05-02 Thread Lokesh Bandaru
downloads (download.cgi) if you want to > get a copy now. > > > > On 29 Apr 2022, at 02:19, Lokesh Bandaru > wrote: > > > > Hello Stephen, the document(ReadMe) you shared earlier, has mentioned > that ignite-calcite must be declared as a dependency. &

Re: Re[2]: Apache Ignite H2 Vulnerabilities

2022-04-28 Thread Lokesh Bandaru
ith this > 'experimental' feature? > > On Thu, Apr 28, 2022 at 4:30 PM Stephen Darlington < > stephen.darling...@gridgain.com > > > wrote: > > https://github.com/apache/ignite/blob/2.13.0/modules/calcite/README.txt > > > On 28 Apr 2022, at 11:46, Lokesh Bandaru &g

Re: Apache Ignite H2 Vulnerabilities

2022-04-28 Thread Lokesh Bandaru
> On 28 Apr 2022, at 11:46, Lokesh Bandaru wrote: > > Thanks Ilya. > > Version 2.13 has come out but still seems to be shipping with the same > vulnerability-ridden version of h2 database. > The documentation doesn't mention if/how Calcite is turned on. > Can you advise on ho

Re: Re: Apache Ignite H2 Vulnerabilities

2022-04-28 Thread Lokesh Bandaru
esh, > > Updates for running Ignite over Java 17 is already in master. Please > take a look: > https://github.com/apache/ignite/blob/master/bin/include/jvmdefaults.sh > > On 2022/04/12 10:11:57 Lokesh Bandaru wrote: > > You are fast. :) Was just typing a reply on top

Re: Apache Ignite H2 Vulnerabilities

2022-04-12 Thread Lokesh Bandaru
ate is 22 April. > > More here: Apache+Ignite+2.13 > <https://cwiki.apache.org/confluence/display/IGNITE/Apache+Ignite+2.13> > > On 12 Apr 2022, at 11:03, Lokesh Bandaru wrote: > > Thanks for getting back, Stephen. > I am aware that Calcite is in the plans. > Any

Re: Apache Ignite H2 Vulnerabilities

2022-04-12 Thread Lokesh Bandaru
11 Apr 2022, at 20:34, Lokesh Bandaru wrote: > > Resending. > > On Mon, Apr 11, 2022 at 6:42 PM Lokesh Bandaru > wrote: > >> Hello there, hi >> >> Writing to you with regards to the security vulnerabilities(particularly >> the most recent ones, CVE-2022-xxx an

Re: Apache Ignite H2 Vulnerabilities

2022-04-11 Thread Lokesh Bandaru
Resending. On Mon, Apr 11, 2022 at 6:42 PM Lokesh Bandaru wrote: > Hello there, hi > > Writing to you with regards to the security vulnerabilities(particularly > the most recent ones, CVE-2022-xxx and CVE-2021-xxx) in the H2 database and > the Apache Ignite's dependency on the f