Skip to content

branch-4.1: [fix](fe) Upgrade vulnerable dependencies - #67148

Open
CalvinKirs wants to merge 2 commits into
apache:branch-4.1from
CalvinKirs:backport-67000-branch-4.1
Open

branch-4.1: [fix](fe) Upgrade vulnerable dependencies#67148
CalvinKirs wants to merge 2 commits into
apache:branch-4.1from
CalvinKirs:backport-67000-branch-4.1

Conversation

@CalvinKirs

Copy link
Copy Markdown
Member

Exclude the obsolete bcprov-jdk15on dependency pulled by Huawei IAM and use bcprov-jdk18on 1.78.1 instead to address CVE-2023-33202.
Upgrade the FE dependency set to releases containing the published security fixes, align Jetty core and EE10 artifacts, migrate LZ4 to its maintained coordinate, and update Maven Shade for Jackson Java 21 classes. Document every version change in the POMs. Thrift remains out of scope.
@CalvinKirs
CalvinKirs requested a review from yiguolei as a code owner August 26, 2026 03:46
@hello-stephen

Copy link
Copy Markdown
Contributor

Thank you for your contribution to Apache Doris.
Don't know what should be done next? See How to process your PR.

Please clearly describe your PR:

  1. What problem was fixed (it's best to include specific error reporting information). How it was fixed.
  2. Which behaviors were modified. What was the previous behavior, what is it now, why was it modified, and what possible impacts might there be.
  3. What features were added. Why was this function added?
  4. Which code was refactored and why was this part of the code refactored?
  5. Which functions were optimized and what is the difference before and after the optimization?

@CalvinKirs

Copy link
Copy Markdown
Member Author

run buildall

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants