Uploaded image for project: 'Zeppelin'
  1. Zeppelin
  2. ZEPPELIN-404

Certain project dependencies are pulled from 3rd parties repos instead of ASF or public Maven

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Blocker
    • Resolution: Fixed
    • 0.5.0
    • 0.5.5
    • build
    • None

    Description

      Looking at the source code I see that
      spark/pom.xml
      lens/pom.xml
      spark-dependencies/pom.xml
      use cloudera's repo for the dependency resolution. All these projects are Apache TLPs, hence their artifacts and their dependencies should be pulled either from ASF server or public Maven server.

      We shouldn't be pulling Apache projects dependencies from a 3rd party source that could be outdated, contain non-Apache bits or outright malicious artifacts.

      Attachments

        Activity

          People

            moon Lee Moon Soo
            cos Konstantin I Boudnik
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: