You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@beam.apache.org by "Emily Ye (Jira)" <ji...@apache.org> on 2022/01/12 18:20:00 UTC
[jira] [Commented] (BEAM-13616) Update protobuf-java to 3.19.2 and other vendored dependencies that use protobuf
[ https://issues.apache.org/jira/browse/BEAM-13616?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17474788#comment-17474788 ]
Emily Ye commented on BEAM-13616:
---------------------------------
Marking as in-progress - multiple parts to this
> Update protobuf-java to 3.19.2 and other vendored dependencies that use protobuf
> --------------------------------------------------------------------------------
>
> Key: BEAM-13616
> URL: https://issues.apache.org/jira/browse/BEAM-13616
> Project: Beam
> Issue Type: Bug
> Components: build-system
> Reporter: Emily Ye
> Assignee: Emily Ye
> Priority: P1
> Fix For: 2.36.0
>
> Time Spent: 7h 50m
> Remaining Estimate: 0h
>
> [https://github.com/protocolbuffers/protobuf/security/advisories/GHSA-wrvw-hg22-4m67] requires us to update versions of vendored artifacts that use protobuf, and recommended version of protobuf in BeamModuleGroovy
>
--
This message was sent by Atlassian Jira
(v8.20.1#820001)