Uploaded image for project: 'Spark'
  1. Spark
  2. SPARK-39020

[CVE-2020-9480] Transitive dependency "unused" from spark-sql_2.12 highlight as vulnerable in dependency tracker

    XMLWordPrintableJSON

Details

    • Question
    • Status: Resolved
    • Minor
    • Resolution: Not A Problem
    • 3.2.1
    • None
    • Spark Core
    • None

    Description

      I am using spark-sql_2.12 dependency version 3.2.1 in my project. My dependency tracker highlights  the transitive dependency  "unused"  from  spark-sql_2.12 as vulnerable. I check there is no update for this artifacts since 2014. Is the artifact used anywhere in spark ?

      To resolve this vulnerability,  can I exclude this "unused" artifact from spark-sql_2.12 ?  Will it cause any issues in my project ? 

      Attachments

        1. Dependency-Track.png
          81 kB
          Sundar

        Activity

          People

            Unassigned Unassigned
            sundar.s.m Sundar
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: