Repository navigation
fix: address Jackson 1 and Netty vulnerabilities - #19808
FrankChen021 wants to merge 17 commits into
Conversation
There was a problem hiding this comment.
Pull request overview
Note
Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.
Removes end-of-life Jackson 1 (org.codehaus.jackson) dependencies and related OWASP suppression to close Dependabot alerts while preserving existing transitive exclusions that keep Jackson 1 out of the production dependency graph.
Changes:
- Removed the unused Jackson 1 version property and dependency-management entries from the root POM.
- Removed explicit test-scope
jackson-core-asl/jackson-mapper-asldependencies fromextensions-contrib/ambari-metrics-emitter. - Removed the now-obsolete OWASP Dependency-Check suppression for
jackson-mapper-asl:1.9.13.
Reviewed changes
Copilot reviewed 3 out of 3 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| pom.xml | Removes Jackson 1 version property and dependency-management entries to prevent resolution of vulnerable artifacts. |
| owasp-dependency-check-suppressions.xml | Drops suppression that was only needed due to test-scope Jackson 1 usage. |
| extensions-contrib/ambari-metrics-emitter/pom.xml | Removes explicit test dependencies on Jackson 1 core/mapper artifacts. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
The failing |
FrankChen021
left a comment
There was a problem hiding this comment.
| Severity | Findings |
|---|---|
| P0 | 0 |
| P1 | 1 |
| P2 | 0 |
| P3 | 0 |
| Total | 1 |
Reviewed 4 of 4 changed files.
This is an automated review by Codex GPT-5.6-Sol
FrankChen021
left a comment
There was a problem hiding this comment.
| Severity | Findings |
|---|---|
| P0 | 0 |
| P1 | 0 |
| P2 | 1 |
| P3 | 0 |
| Total | 1 |
Reviewed 4 of 4 changed files. The Jackson 1 compatibility concern is resolved, but the new catch-all Netty 3 suppression hides future advisories from OWASP CI.
This is an automated review by Codex GPT-5.6-Sol
FrankChen021
left a comment
There was a problem hiding this comment.
I have reviewed the code for correctness, edge cases, concurrency, and integration risks; no issues found.
Reviewed 4 of 4 changed files. The prior catch-all Netty 3 suppression concern is resolved: the wildcard has been replaced with an explicit CVE list, so future advisories remain visible.
This is an automated review by Codex GPT-5.6-Sol
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 3 out of 3 changed files in this pull request and generated no new comments.
Suppressed comments (1)
owasp-dependency-check-suppressions.xml:347
- This suppression is scoped only by
packageUrl(uuid@7.0.3), which makes it repository-wide for that dependency version. Ifuuid@7.0.3is used outside the web-console (now or in the future), this would also hide a potentially real finding there. Prefer scoping the suppression to the specific lockfile/build artifact for the web-console (e.g., add afilePath/related matcher supported by Dependency-Check suppressions) so the justification in the notes matches the suppression’s actual impact.
<suppress>
<notes><![CDATA[
web-console uses uuid v4() only to generate query IDs. GHSA-w5hq-g745-h8pq
(CVE-2026-41907) affects the v3/v5/v6 buffer APIs; v4 is not affected.
Revisit this suppression when uuid is upgraded.
]]></notes>
<packageUrl regex="true">^pkg:npm/uuid@7\.0\.3$</packageUrl>
<vulnerabilityName>GHSA-w5hq-g745-h8pq</vulnerabilityName>
<cve>CVE-2026-41907</cve>
</suppress>
FrankChen021
left a comment
There was a problem hiding this comment.
I have reviewed the updated head for correctness, dependency compatibility, security, and integration risks; no issues found.
Reviewed 3 of 3 changed files. The prior Netty catch-all suppression concern remains resolved because the suppression is still limited to explicit CVEs.
This is an automated review by Codex GPT-5.6-Sol
FrankChen021
left a comment
There was a problem hiding this comment.
| Severity | Findings |
|---|---|
| P0 | 0 |
| P1 | 0 |
| P2 | 1 |
| P3 | 0 |
| Total | 1 |
| Severity | Findings |
|---|---|
| P0 | 0 |
| P1 | 0 |
| P2 | 1 |
| P3 | 0 |
| Total | 1 |
Reviewed 3 of 3 changed files. The prior catch-all Netty suppression concern remains resolved, but the production Ambari extension still bundles Jackson 1.
This is an automated review by Codex GPT-5.6-Luna(max)
| @@ -119,16 +119,6 @@ | |||
| <artifactId>JUnitParams</artifactId> | |||
There was a problem hiding this comment.
[P2] Jackson 1 remains bundled
Removing the test dependencies hides the Maven alert, but ambari-metrics-common:2.7.0.0.0 still embeds Jackson 1.9.13 under a relocated package and uses it to serialize metrics in production. The bundled Ambari extension therefore still ships Jackson 1; upgrade or replace that dependency, or explicitly assess and retain the suppression.
There was a problem hiding this comment.
Addressed in commit 3b80ce5. ambari-metrics-common:2.7.0.0.0 is the latest published release, and its AbstractTimelineMetricsSink uses the relocated Jackson 1.9.13 classes bundled inside that jar, so upgrading it is not a compatible drop-in fix. I added an explicit exclusion for org.codehaus.jackson:jackson-xc, removing the unrelocated Jackson artifact from the emitter dependency graph, and documented the retained explicit CVE assessment for the unavoidable shaded runtime copy. The focused dependency tree now has no org.codehaus.jackson entries, and all 28 Ambari emitter tests pass.
FrankChen021
left a comment
There was a problem hiding this comment.
| Severity | Findings |
|---|---|
| P0 | 0 |
| P1 | 0 |
| P2 | 1 |
| P3 | 0 |
| Total | 1 |
Reviewed 3 of 3 changed files.
The existing Ambari Jackson 1 finding remains unresolved; the prior Netty catch-all suppression concern is resolved.
Validation: git diff --check and XML parsing passed; the packet reports 28 focused tests passed.
This is an automated review by Codex GPT-5.6-Luna(max)
| @@ -119,16 +119,6 @@ | |||
| <artifactId>JUnitParams</artifactId> | |||
There was a problem hiding this comment.
[P2] Ambari still ships Jackson 1 via jackson-xc
The deletion removes only test-scoped jackson-core-asl and jackson-mapper-asl. The compile-scoped ambari-metrics-common dependency remains, and dependency-tree validation reports that it still resolves org.codehaus.jackson:jackson-xc. The production extension therefore continues to ship EOL Jackson 1 code. Upgrade or replace Ambari, or remove the remaining artifact with a verified runtime-compatible alternative.
There was a problem hiding this comment.
This is addressed in the same commit, 3b80ce5. The compile-scoped ambari-metrics-common dependency now explicitly excludes org.codehaus.jackson:jackson-xc, so dependency-tree validation no longer resolves any unrelocated org.codehaus.jackson artifact. The Ambari jar necessarily retains its relocated Jackson 1.9.13 implementation because AbstractTimelineMetricsSink uses it and 2.7.0.0.0 is the latest published release; I documented and retained the explicit CVE suppression assessment for that shaded copy. All 28 Ambari emitter tests pass with the exclusion.
FrankChen021
left a comment
There was a problem hiding this comment.
I have reviewed the code for correctness, edge cases, concurrency, and integration risks; no issues found.
Reviewed 3 of 3 changed files.
Validation: git diff --check and XML parsing passed; no builds or tests were run.
This is an automated review by Codex GPT-5.6-Luna(max)
Related
Supersedes #18456.
Summary
jackson-core-aslandjackson-mapper-asldependencies fromambari-metrics-emitterjackson-mapper-aslRoot cause
Dependabot alerts #2 and #221 report
org.codehaus.jackson:jackson-mapper-asl:1.9.13. Jackson 1 is end-of-life and has no patched release. The Ambari Metrics dependency already excluded Jackson 1 core and mapper from production, but the module explicitly added both artifacts back in test scope. The root POM also kept global dependency-management entries for them.Druid's Ambari emitter source and tests use Jackson 2 (
com.fasterxml.jackson), so the explicit Jackson 1 test dependencies are unnecessary.Why the Netty changes are included
Removing the obsolete Jackson suppression changes
owasp-dependency-check-suppressions.xml, which is the path trigger for Druid's full OWASP dependency-check workflow. That repository-wide scan exposed pre-existing findings againstnetty-3.10.6.Final. GitHub's advisory records scope each reported CVE to Netty 4 module artifacts such asnetty-codec-http,netty-resolver-dns, andnetty-handler, but Dependency-Check's generic Netty CPE mapping also attaches them to the monolithic Netty 3 artifact.The misattributed CVEs are listed explicitly rather than using a package-wide wildcard. This allows the security workflow to assess the Jackson removal without failing on Netty 4-only findings, while ensuring that future Netty advisories remain visible and trigger a fresh assessment. Migrating Druid's legacy
NettyHttpClientfrom Netty 3 to Netty 4 remains a separate change.Impact
The Ambari emitter no longer resolves
jackson-core-aslorjackson-mapper-asl, allowing Dependabot alerts #2 and #221 to close without hiding an active vulnerable dependency. Runtime behavior is unchanged because those artifacts were already excluded from the production Ambari dependency path.Netty 3 remains unchanged at runtime. The OWASP suppression only covers explicitly assessed Netty 4 module advisories that Dependency-Check misattributes to Netty 3; newly published CVEs remain visible.
Validation
mvn -ntp dependency:tree -pl extensions-contrib/ambari-metrics-emitter -Dincludes=org.codehaus.jackson -Dverbose -Pskip-static-checks -Dweb.console.skip=true -T1Cjackson-core-aslnorjackson-mapper-aslis resolved; Ambari's separatejackson-xcartifact remainsmvn -ntp test -pl extensions-contrib/ambari-metrics-emitter -Pskip-static-checks -Dweb.console.skip=true -T1Cio.netty:nettyNetty 3 artifactowasp-dependency-check-suppressions.xmlagainst Dependency-Check'sdependency-suppression.1.3.xsdgit diff --checkThe focused local OWASP run could not execute without a populated NVD database; the GitHub security workflow provides the authoritative rescan with its configured NVD access.
Caveats
This intentionally does not upgrade Ambari or alter its binary API. The existing exclusions remain in place to prevent its transitive Jackson 1 core/mapper dependencies from returning.
The explicit Netty 3 suppressions are not a claim that Netty 3 is patched. They cover only individually assessed Netty 4-only advisories misattributed through the generic CPE; actual Netty 3 remediation still requires the separate
NettyHttpClientmigration.Created by GPT-5.6-Sol.