HADOOP-19791: Upgraded GCS to remediate CVE-2025-55163#8213
HADOOP-19791: Upgraded GCS to remediate CVE-2025-55163#8213shub-est wants to merge 3 commits intoapache:trunkfrom
Conversation
Signed-off-by: Shubham Kalloli <shubham.kalloli@est.tech>
Signed-off-by: Shubham Kalloli <shubham.kalloli@est.tech>
Signed-off-by: Shubham Kalloli <shubham.kalloli@est.tech>
|
aah, this is a PITA. Can you also do a PR for hadoop-thirdparty for its updates, so it can be done broadly and that LICENSE-binary file is consistent |
|
If you are going to update guava and protobuf everywhere, this Pr should update the project/pom.xml to update the guava.version and hadoop.protobuf.version. 3.25.5 appears in many places in the txt files that act as build instructions. Presumably they need to be upgraded too. |
|
And -- this is another module that uses grpc - shouldn't that have its grpc.version upgraded too to match what is being updated for the gcp module? |
|
Hi @steveloughran @pjfanning, thank you for reviewing the PR. Is it okay to use this PR and ticket to upgrade the Protobuf Java and Guava across the entire project while also removing the CVE? Alternatively, I can create a separate PR just upgrading Protobuf and Guava across the entire project. Appreciate your guidance here, thanks |
|
I'd prefer a separate one for the thirdparty module as it'll be on a separate release cycle |
|
Hi @steveloughran, will do. I have raised PRs for the Apache Third Party module apache/hadoop-thirdparty#48 Once merged and new release is created, I will create a PR to update the Thirdparty version along with Guava and Protobuf upgrade. Thanks |
Description of PR
Upgraded GCS from 2.52.0 to 2.62.0 to remediate GHSA-prj3-ccx8-p6x4
Upgraded Guava and Protobuf Java to avoid conflict
How was this patch tested?
Local build
For code changes:
LICENSE,LICENSE-binary,NOTICE-binaryfiles?AI Tooling
N/A