You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@pulsar.apache.org by GitBox <gi...@apache.org> on 2021/04/19 08:26:15 UTC

[GitHub] [pulsar] lhotari opened a new pull request #10262: [Security] Remove jackson-mapper-asl dependency to resolve multiple CVEs

lhotari opened a new pull request #10262:
URL: https://github.com/apache/pulsar/pull/10262


   ### Motivation
   
   - jackson-mapper-asl is not required since Zookeeper 3.6.x+ no more depends
     on jackson-mapper-asl library (ZOOKEEPER-3051)
   - jackson-mapper-asl was replaced in Avro 1.9.x so it's not required because of
     Avro
   
   ### Modifications
   
   - remove dependency on jackson-mapper-asl
     - exclude it from Bookkeeper's stream-storage-server dependency
   
   ### Notice
   
     - there's a separate PR in Bookkeeper to remove jackson-mapper-asl dependency, apache/bookkeeper#2694


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [pulsar] codelipenghui merged pull request #10262: [Security] Remove jackson-mapper-asl dependency to resolve multiple CVEs

Posted by GitBox <gi...@apache.org>.
codelipenghui merged pull request #10262:
URL: https://github.com/apache/pulsar/pull/10262


   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [pulsar] lhotari commented on pull request #10262: [Security] Remove jackson-mapper-asl dependency to resolve multiple CVEs

Posted by GitBox <gi...@apache.org>.
lhotari commented on pull request #10262:
URL: https://github.com/apache/pulsar/pull/10262#issuecomment-822400719


   /pulsarbot run-failure-checks


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [pulsar] lhotari commented on pull request #10262: [Security] Remove jackson-mapper-asl dependency to resolve multiple CVEs

Posted by GitBox <gi...@apache.org>.
lhotari commented on pull request #10262:
URL: https://github.com/apache/pulsar/pull/10262#issuecomment-822364976


   /pulsarbot run-failure-checks


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
users@infra.apache.org