Skip to content

Commit

Permalink
Upgrade nimbus and jetty library versions for CVE
Browse files Browse the repository at this point in the history
  • Loading branch information
xiangfu0 committed Mar 7, 2024
1 parent 7a79e1e commit b7b7199
Show file tree
Hide file tree
Showing 3 changed files with 49 additions and 13 deletions.
5 changes: 5 additions & 0 deletions pinot-plugins/pinot-file-system/pinot-adls/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -105,6 +105,11 @@
<artifactId>wildfly-openssl-java</artifactId>
<version>${wildfly-openssl.version}</version>
</dependency>
<dependency>
<groupId>com.nimbusds</groupId>
<artifactId>nimbus-jose-jwt</artifactId>
<version>9.37.3</version>
</dependency>
</dependencies>
</dependencyManagement>
</project>
17 changes: 4 additions & 13 deletions pinot-plugins/pinot-stream-ingestion/pinot-pulsar/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,6 @@
<phase.prop>package</phase.prop>
<pinot.root>${basedir}/../../..</pinot.root>
<pulsar.version>2.11.0</pulsar.version>
<jetty-server.version>9.4.51.v20230217</jetty-server.version>
<javax.servlet-api.version>3.1.0</javax.servlet-api.version>
<javax.ws.rs-api.version>2.1</javax.ws.rs-api.version>
<jersey-container-grizzly2-http.version>2.39</jersey-container-grizzly2-http.version>
Expand All @@ -54,17 +53,6 @@
</properties>

<dependencies>
<dependency>
<groupId>org.eclipse.jetty</groupId>
<artifactId>jetty-server</artifactId>
<version>${jetty-server.version}</version>
<exclusions>
<exclusion>
<groupId>javax.servlet</groupId>
<artifactId>javax.servlet-api</artifactId>
</exclusion>
</exclusions>
</dependency>
<dependency>
<groupId>org.testcontainers</groupId>
<artifactId>pulsar</artifactId>
Expand Down Expand Up @@ -155,10 +143,13 @@
<artifactId>simpleclient</artifactId>
<version>${simpleclient_common.version}</version>
</dependency>
<dependency>
<groupId>org.eclipse.jetty</groupId>
<artifactId>jetty-server</artifactId>
</dependency>
<dependency>
<groupId>org.eclipse.jetty</groupId>
<artifactId>jetty-servlet</artifactId>
<version>${jetty-server.version}</version>
</dependency>
<dependency>
<groupId>com.squareup.okio</groupId>
Expand Down
40 changes: 40 additions & 0 deletions pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -203,6 +203,7 @@
<jline.version>3.24.1</jline.version>
<wildfly.version>1.7.0.Final</wildfly.version>
<jettison.version>1.5.4</jettison.version>
<eclipse.jetty.version>9.4.54.v20240208</eclipse.jetty.version>
</properties>

<profiles>
Expand Down Expand Up @@ -972,6 +973,45 @@
<artifactId>jettison</artifactId>
<version>${jettison.version}</version>
</dependency>

<!-- Consolidate eclipse jetty dependencies for hadoop/spark/pulsar -->
<dependency>
<groupId>org.eclipse.jetty.websocket</groupId>
<artifactId>websocket-client</artifactId>
<version>${eclipse.jetty.version}</version>
</dependency>
<dependency>
<groupId>org.eclipse.jetty</groupId>
<artifactId>jetty-server</artifactId>
<version>${eclipse.jetty.version}</version>
<exclusions>
<exclusion>
<groupId>javax.servlet</groupId>
<artifactId>javax.servlet-api</artifactId>
</exclusion>
</exclusions>
</dependency>
<dependency>
<groupId>org.eclipse.jetty</groupId>
<artifactId>jetty-servlet</artifactId>
<version>${eclipse.jetty.version}</version>
</dependency>
<dependency>
<groupId>org.eclipse.jetty</groupId>
<artifactId>jetty-util</artifactId>
<version>${eclipse.jetty.version}</version>
</dependency>
<dependency>
<groupId>org.eclipse.jetty</groupId>
<artifactId>jetty-util-ajax</artifactId>
<version>${eclipse.jetty.version}</version>
</dependency>
<dependency>
<groupId>org.eclipse.jetty</groupId>
<artifactId>jetty-webapp</artifactId>
<version>${eclipse.jetty.version}</version>
</dependency>

<!-- Upgrade hadoop-common dependency from hadoop-shaded-protobuf_3_7 to hadoop-shaded-protobuf_3_21 -->
<dependency>
<groupId>org.apache.hadoop.thirdparty</groupId>
Expand Down

0 comments on commit b7b7199

Please sign in to comment.