Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

TEZ-4469:Upgrade jettison to 1.5.3 to fix CVE-2022-40150 #268

Closed

Conversation

devaspatikrishnatri
Copy link

Upgrading Jettison version to 1.5.3 to fix CVEs

@devaspatikrishnatri
Copy link
Author

@abstractdog Please review this.I am unable to manually add reviewers.

@abstractdog abstractdog self-requested a review February 14, 2023 12:32
@tez-yetus
Copy link

💔 -1 overall

Vote Subsystem Runtime Comment
+0 🆗 reexec 24m 47s Docker mode activated.
_ Prechecks _
+1 💚 dupname 0m 1s No case conflicting files found.
+1 💚 @author 0m 0s The patch does not contain any @author tags.
-1 ❌ test4tests 0m 0s The patch doesn't appear to include any new or modified tests. Please justify why no new tests are needed for this patch. Also please list what manual steps were performed to verify this patch.
_ master Compile Tests _
+0 🆗 mvndep 7m 38s Maven dependency ordering for branch
+1 💚 mvninstall 11m 8s master passed
+1 💚 compile 2m 57s master passed with JDK Ubuntu-11.0.17+8-post-Ubuntu-1ubuntu222.04
+1 💚 compile 2m 39s master passed with JDK Private Build-1.8.0_352-8u352-ga-1~22.04-b08
+1 💚 checkstyle 1m 31s master passed
+1 💚 javadoc 2m 44s master passed with JDK Ubuntu-11.0.17+8-post-Ubuntu-1ubuntu222.04
+1 💚 javadoc 2m 16s master passed with JDK Private Build-1.8.0_352-8u352-ga-1~22.04-b08
+0 🆗 spotbugs 6m 12s Used deprecated FindBugs config; considering switching to SpotBugs.
+1 💚 findbugs 7m 44s master passed
_ Patch Compile Tests _
+0 🆗 mvndep 0m 15s Maven dependency ordering for patch
+1 💚 mvninstall 4m 35s the patch passed
+1 💚 compile 2m 57s the patch passed with JDK Ubuntu-11.0.17+8-post-Ubuntu-1ubuntu222.04
+1 💚 javac 2m 57s the patch passed
+1 💚 compile 2m 37s the patch passed with JDK Private Build-1.8.0_352-8u352-ga-1~22.04-b08
+1 💚 javac 2m 37s the patch passed
-0 ⚠️ checkstyle 0m 29s tez-dag: The patch generated 1 new + 58 unchanged - 0 fixed = 59 total (was 58)
-0 ⚠️ checkstyle 0m 46s root: The patch generated 1 new + 58 unchanged - 0 fixed = 59 total (was 58)
+1 💚 whitespace 0m 0s The patch has no whitespace issues.
+1 💚 xml 0m 1s The patch has no ill-formed XML file.
+1 💚 javadoc 2m 35s the patch passed with JDK Ubuntu-11.0.17+8-post-Ubuntu-1ubuntu222.04
+1 💚 javadoc 2m 13s the patch passed with JDK Private Build-1.8.0_352-8u352-ga-1~22.04-b08
+1 💚 findbugs 7m 44s the patch passed
_ Other Tests _
-1 ❌ unit 5m 15s tez-dag in the patch failed.
+1 💚 unit 71m 35s root in the patch passed.
+1 💚 asflicense 0m 48s The patch does not generate ASF License warnings.
167m 20s
Subsystem Report/Notes
Docker ClientAPI=1.42 ServerAPI=1.42 base: https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-268/1/artifact/out/Dockerfile
GITHUB PR #268
JIRA Issue TEZ-4469
Optional Tests dupname asflicense javac javadoc unit xml compile spotbugs findbugs checkstyle
uname Linux 17b849675dfb 4.15.0-200-generic #211-Ubuntu SMP Thu Nov 24 18:16:04 UTC 2022 x86_64 x86_64 x86_64 GNU/Linux
Build tool maven
Personality personality/tez.sh
git revision master / 97cc788
Default Java Private Build-1.8.0_352-8u352-ga-1~22.04-b08
Multi-JDK versions /usr/lib/jvm/java-11-openjdk-amd64:Ubuntu-11.0.17+8-post-Ubuntu-1ubuntu222.04 /usr/lib/jvm/java-8-openjdk-amd64:Private Build-1.8.0_352-8u352-ga-1~22.04-b08
checkstyle https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-268/1/artifact/out/diff-checkstyle-tez-dag.txt
checkstyle https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-268/1/artifact/out/diff-checkstyle-root.txt
unit https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-268/1/artifact/out/patch-unit-tez-dag.txt
Test Results https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-268/1/testReport/
Max. process+thread count 1383 (vs. ulimit of 5500)
modules C: tez-dag . U: .
Console output https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-268/1/console
versions git=2.34.1 maven=3.6.3 findbugs=3.0.1
Powered by Apache Yetus 0.12.0 https://yetus.apache.org

This message was automatically generated.

@abstractdog
Copy link
Contributor

handled in #271

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants