[Improvement] Consider removing easyjson dependency due to sanction concerns
- Dominant language
- Java
- Stars
- 454
- Forks
- 172
- Avg merge
- 5d 17h
- Merged PRs (30d)
- 5
Description
### Code of Conduct
- [x] I agree to follow this project's [Code of Conduct](https://www.apache.org/foundation/policies/conduct)
### Search before asking
- [x] I have searched in the [issues](https://github.com/apache/incubator-uniffle/issues?q=is%3Aissue) and found no similar issues.
### What would you like to be improved?
Security Researchers Warn a Widely Used Open Source Tool Poses a 'Persistent' Risk to the US
https://www.wired.com/story/easyjson-open-source-vk-ties/
### How should we improve?
_No response_
### Are you willing to submit PR?
- [ ] Yes I am willing to submit a PR!
Contributor guide
Research direction
The issue names the easyjson dependency but no files, tests, or entry points. Start by locating easyjson references in the repository's dependency configuration and reviewing the linked Wired report; done requires a documented decision about removal and any resulting dependency updates.
Written by the indexing model from the issue text.
Assessment
- Domain
- security
- Issue type
- Refactor
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100