tez icon indicating copy to clipboard operation
tez copied to clipboard

TEZ-4449: Upgrade jettison to 1.5.1 to fix CVE-2022-40149.

Open slfan1989 opened this issue 3 years ago • 2 comments

JIRA: TEZ-4449: Upgrade jettison to 1.5.1 to fix CVE-2022-40149.

slfan1989 avatar Oct 08 '22 08:10 slfan1989

@abstractdog Can you help review this pr? Thank you very much!

slfan1989 avatar Oct 08 '22 08:10 slfan1989

:broken_heart: -1 overall

Vote Subsystem Runtime Comment
+0 :ok: reexec 0m 33s Docker mode activated.
_ Prechecks _
+1 :green_heart: dupname 0m 0s No case conflicting files found.
+1 :green_heart: @author 0m 0s The patch does not contain any @author tags.
-1 :x: test4tests 0m 0s The patch doesn't appear to include any new or modified tests. Please justify why no new tests are needed for this patch. Also please list what manual steps were performed to verify this patch.
_ master Compile Tests _
+1 :green_heart: mvninstall 15m 49s master passed
+1 :green_heart: compile 2m 45s master passed with JDK Ubuntu-11.0.16+8-post-Ubuntu-0ubuntu120.04
+1 :green_heart: compile 2m 29s master passed with JDK Private Build-1.8.0_342-8u342-b07-0ubuntu1~20.04-b07
+1 :green_heart: javadoc 2m 49s master passed with JDK Ubuntu-11.0.16+8-post-Ubuntu-0ubuntu120.04
+1 :green_heart: javadoc 2m 8s master passed with JDK Private Build-1.8.0_342-8u342-b07-0ubuntu1~20.04-b07
_ Patch Compile Tests _
+1 :green_heart: mvninstall 4m 52s the patch passed
+1 :green_heart: compile 2m 46s the patch passed with JDK Ubuntu-11.0.16+8-post-Ubuntu-0ubuntu120.04
+1 :green_heart: javac 2m 46s the patch passed
+1 :green_heart: compile 2m 29s the patch passed with JDK Private Build-1.8.0_342-8u342-b07-0ubuntu1~20.04-b07
+1 :green_heart: javac 2m 29s the patch passed
+1 :green_heart: whitespace 0m 0s The patch has no whitespace issues.
+1 :green_heart: xml 0m 1s The patch has no ill-formed XML file.
+1 :green_heart: javadoc 2m 28s the patch passed with JDK Ubuntu-11.0.16+8-post-Ubuntu-0ubuntu120.04
+1 :green_heart: javadoc 2m 5s the patch passed with JDK Private Build-1.8.0_342-8u342-b07-0ubuntu1~20.04-b07
_ Other Tests _
+1 :green_heart: unit 74m 35s root in the patch passed.
+1 :green_heart: asflicense 0m 53s The patch does not generate ASF License warnings.
118m 0s
Subsystem Report/Notes
Docker ClientAPI=1.41 ServerAPI=1.41 base: https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-242/1/artifact/out/Dockerfile
GITHUB PR https://github.com/apache/tez/pull/242
Optional Tests dupname asflicense javac javadoc unit xml compile
uname Linux 8569607d41a2 4.15.0-191-generic #202-Ubuntu SMP Thu Aug 4 01:49:29 UTC 2022 x86_64 x86_64 x86_64 GNU/Linux
Build tool maven
Personality personality/tez.sh
git revision master / de88f2a2c
Default Java Private Build-1.8.0_342-8u342-b07-0ubuntu1~20.04-b07
Multi-JDK versions /usr/lib/jvm/java-11-openjdk-amd64:Ubuntu-11.0.16+8-post-Ubuntu-0ubuntu120.04 /usr/lib/jvm/java-8-openjdk-amd64:Private Build-1.8.0_342-8u342-b07-0ubuntu1~20.04-b07
Test Results https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-242/1/testReport/
Max. process+thread count 1503 (vs. ulimit of 5500)
modules C: . U: .
Console output https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-242/1/console
versions git=2.25.1 maven=3.6.3
Powered by Apache Yetus 0.12.0 https://yetus.apache.org

This message was automatically generated.

tez-yetus avatar Oct 08 '22 10:10 tez-yetus

@abstractdog Thank you very much for helping to review the code!

slfan1989 avatar Oct 23 '22 12:10 slfan1989