apache / apache/parquet-java

upgrade libraries to work around security issues

Open
#2,205 0 comments 0 reactions 0 assignees View on GitHub
Component: Java Component: Parquet Priority: Major Type: bug
Dominant language
Java
Stars
3.1k
Forks
1.6k
Avg merge
3d 12h
Merged PRs (30d)
33

Description

There are a number of libraries which need updating.  Among other reasons, there are several security issues filed in CVE for [Hadoop](https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=hadoop) and [guava](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10237)

 

 

**Reporter**: [Matt Darwin](https://issues.apache.org/jira/secure/ViewProfile.jspa?name=mdarwin) / @mattdarwin
#### PRs and other links:
- [GitHub Pull Request #508](https://github.com/apache/parquet-mr/pull/508)

**Note**: *This issue was originally created as [PARQUET-1367](https://issues.apache.org/jira/browse/PARQUET-1367). Please see the [migration documentation](https://issues.apache.org/jira/browse/PARQUET-2502) for further details.*

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with pull request #508 and the linked Hadoop and Guava CVE references; inspect which dependency updates it proposes. Done means the affected libraries are upgraded to address the reported security issues, with the result aligned with that pull request.

Written by the indexing model from the issue text.

Assessment

Tech stack
hadoop, java
Domain
data-engineering, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.