apache / apache/uniffle

[Improvement] Consider removing easyjson dependency due to sanction concerns

Open
#2,477 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
454
Forks
172
Avg merge
5d 17h
Merged PRs (30d)
5

Description

### Code of Conduct

- [x] I agree to follow this project's [Code of Conduct](https://www.apache.org/foundation/policies/conduct)

### Search before asking

- [x] I have searched in the [issues](https://github.com/apache/incubator-uniffle/issues?q=is%3Aissue) and found no similar issues.

### What would you like to be improved?

Security Researchers Warn a Widely Used Open Source Tool Poses a 'Persistent' Risk to the US

https://www.wired.com/story/easyjson-open-source-vk-ties/

### How should we improve?

_No response_

### Are you willing to submit PR?

- [ ] Yes I am willing to submit a PR!

Contributor guide

Open the contributing guide

Research direction

The issue names the easyjson dependency but no files, tests, or entry points. Start by locating easyjson references in the repository's dependency configuration and reviewing the linked Wired report; done requires a documented decision about removal and any resulting dependency updates.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Refactor
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.