Details
Description
uses of protobuf 2.5 and RpcEnginej have been deprecated since 3.3.0 in HADOOP-17046
while still keeping those files around (for a long time...), how about we make the protobuf 2.5.0 export off hadoop common and hadoop-hdfs provided, rather than compile
that way, if apps want it for their own apis, they have to explicitly ask for it, but at least our own scans don't break.
i have no idea what will happen to the rest of the stack at this point, it will be "interesting" to see
Attachments
Issue Links
- is depended upon by
-
HADOOP-17860 Upgrade third party protobuf-java-2.5.0.jar to address vulnerabilities #CVE-2015-5237, CVE-2019-15544,
- Open
- is related to
-
HADOOP-13363 Upgrade protobuf from 2.5.0 to something newer
- Open
-
HADOOP-19165 Explore dropping protobuf 2.5.0 from the distro
- Resolved
- Testing discovered
-
YARN-11657 Remove protobuf-2.5 as dependency of hadoop-yarn-api
- Resolved
- links to