AbsaOSS / AbsaOSS/pramen

Remove security vulnerabilities if possible

Aperta
#215 2 commenti 0 reazioni 1 assegnatario Rivendicata da @yruslan Vedi su GitHub
DE DS enhancement
Lingua principale
Scala
Stelle
31
Fork
4
Merge medio
1g 10m
PR unite (30g)
4

Descrizione

## Background
SonaType has created this dependency security report:
https://sbom.lift.sonatype.com/report/T1-118f0f57da8c6b3097cc-bb6bb3ca7a4e7-1687241554-048abf44d6b64eb2a99d21507e643b0b

Vulnerable libraries include:
- Kafka Client v2.5.1 - this is explicit dependency that we can change
- Snappy Java (1.1.7.3) - this is a transitive dependency. Maybe we can switch to the latest Spark for default builds and it can solve it.

## Feature
Update project dependencies to remove security vulnerabilities while keeping Pramen compatible with Spark 2.4.3+

Make the default build for Spark 3.4.0 or later

## Example
Kafka client can be made spark version dependent if Spark requires certain version of the Kafka client

Guida per i contributori

Nessuna guida per i contributori indicizzata per questo repository

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.