Details
-
Task
-
Status: Resolved
-
Blocker
-
Resolution: Fixed
-
None
-
None
-
None
Description
HBase accidentally let OWASP's ESAPI artifact slip into a few release which is not allowed (as there are GPL deps).
This was resolved in 1.1.6 and 1.2.3. A trivial fix would be to upgrade the 1.1 and 1.2 branches to these versions, but I don't know if there are other implications to doing that..
I'm not sure if there are runtime concerns if we just omit those dependencies. Would have to look at the suite of reverts that came in via HBASE-16317 to see if any of them would actually affect us in phoenix-landia.
Attachments
Attachments
Issue Links
- is related to
-
HBASE-16317 revert all ESAPI changes
-
- Resolved
-