HADOOP-19878. Upgrade to Netty 4.1.133.Final due to CVEs#8469
Conversation
steveloughran
left a comment
There was a problem hiding this comment.
+1 pending the build.
@pjfanning we really an upgrade marathon don't we, where everything which can be upgraded is (trunk, and 3.5) and anything which still works on java8 is done for the 3.4 branch. Then we can think of new releases
ajfabbri
left a comment
There was a problem hiding this comment.
+1 pending jenkins/pr-merge CI passing. We can ignore the PR update / Build (pull_request_target) — Workflow run detection failed check for now: We are adding new github actions-based CI which requires enabling actions in your forked repo to get past that error, but it is not a requirement yet.
| io.netty:netty-codec-http2:4.1.133.Final | ||
| io.netty:netty-codec-memcache:4.1.133.Final | ||
| io.netty:netty-codec-mqtt:4.1.133.Final | ||
| io.netty:netty-codec-redis:4.1.133.Final |
There was a problem hiding this comment.
are all those netty libs used by hadoop? I don't think hadoop requires netty-codec-redis ...
There was a problem hiding this comment.
it feels like there is a separate task to revisit the entire LICENSE-binary file - I guarantee that this is not the only is it/isn't it correct line in the file
|
@pjfanning could you follow the instructions to ensure GHA on your forked repo? https://github.com/apache/hadoop/pull/8469/checks?check_run_id=74443729055 |
adb3358 to
b3f0d8a
Compare
|
@steveloughran do we want to land this in branch-3.4? HADOOP-19788 upgraded Netty from 4.1.127.Final to 4.1.130.Final, which does not land branch-3.4, we need both or neither. |
Reviewed-by: Steve Loughran <stevel@cloudera.com> Reviewed-by: Aaron Fabbri <fabbri@apache.org> Signed-off-by: Cheng Pan <chengpan@apache.org>
|
merged to trunk/branch-3.5 for now. branch-3.4 backport requires making a decision first. |
|
i don't see any specific reason for holding back the 3.4 update, so go with it |
Reviewed-by: Steve Loughran <stevel@cloudera.com> Reviewed-by: Aaron Fabbri <fabbri@apache.org> Signed-off-by: Cheng Pan <chengpan@apache.org>
|
backported to branch-3.4 |
Description of PR
https://issues.apache.org/jira/browse/HADOOP-19878
How was this patch tested?
For code changes:
LICENSE,LICENSE-binary,NOTICE-binaryfiles?AI Tooling
If an AI tool was used:
where is the name of the AI tool used.
https://www.apache.org/legal/generative-tooling.html