upgrade h2 due to cves
Open
- Dominant language
- Java
- Stars
- 6.1k
- Forks
- 1.5k
- Avg merge
- 1d 21h
- Merged PRs (30d)
- 189
Description
see cves in https://mvnrepository.com/artifact/com.h2database/h2
Contributor guide
Research direction
The issue only points to the H2 CVE listing and names no files, tests, or target version. Start by locating the H2 dependency declaration in Pinot’s build, then use the linked advisory to define the upgrade and run the relevant build checks; done means the vulnerable dependency is upgraded.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- databases
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100