Uploaded image for project: 'Apache Tez'
  1. Apache Tez
  2. TEZ-4158

Change to a maintained bouncy castle version

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • None
    • 0.10.0, 0.9.3
    • None
    • None

    Description

      The outdated bcprov-jdk16 (which is full of vulnerabilities) triggers blackduck alerts, however, it's used only in test scope since TEZ-1832. The currently maintained artifact is bcprov-jdk15on, which covers current JDK versions up to JDK11.
      So if tests (TestSecureShuffle) still pass, let's upgrade test scoped bouncy castle.

      Attachments

        1. TEZ-4158.01.patch
          0.8 kB
          László Bodor
        2. TEZ-4158.01.patch
          0.8 kB
          László Bodor

        Activity

          People

            abstractdog László Bodor
            abstractdog László Bodor
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: