Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEZOOKEEPER-15443353
|
This upgrade includes a major version increase for 1. org.apache.hadoop:hadoop-client (2.10.2 → 3.0.0)Risk: HIGH The upgrade to Hadoop 3.0.0 is a major transition with several breaking changes. While the community aimed to preserve wire compatibility for clients, significant changes to the environment, APIs, and configuration require attention. Key Breaking Changes:
Recommendation: Developers must ensure their environment uses Java 8. Review code for dependencies on the previous logging implementation and update any custom scripts or configurations that rely on old port numbers or environment variable names. Source: Apache Hadoop 3.0.0 Release Notes, Hadoop 2 to 3 Upgrade Guide 2. org.apache.hudi:hudi-common (1.0.0-SNAPSHOT → 1.1.0)Risk: HIGH Although a minor version update, Hudi 1.1.0 introduces significant new features and a key API deprecation that constitutes a breaking change. Key Breaking Changes:
Recommendation: Developers should review code related to record merging and migrate from the deprecated payload classes to the new merger APIs as specified in the release documentation. Source: Apache Hudi 1.1 Release Notes
|
|
| Status | Scanner | Total (491) | ||||
|---|---|---|---|---|---|---|
| Open Source Security | 86 | 405 | 0 | 0 | See details | |
| Licenses | 0 | 0 | 0 | 0 | See details |
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEZOOKEEPER-15443353
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEZOOKEEPER-15443353
Snyk has created this PR to fix 1 vulnerabilities in the maven dependencies of this project.
Snyk changed the following file(s):
pom.xmlVulnerabilities that will be fixed with an upgrade:
SNYK-JAVA-ORGAPACHEZOOKEEPER-15443353
2.10.2->3.0.0Major version upgradeNo Path FoundNo Known ExploitBreaking Change Risk
Vulnerabilities that could not be fixed
org.apache.hudi:hudi-common@1.0.0-SNAPSHOTtoorg.apache.hudi:hudi-common@1.1.0; Reasoncould not apply upgrade, dependency is managed externally; Location:provenance does not contain locationImportant
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Insertion of Sensitive Information into Log File