Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEZOOKEEPER-15443353
|
This upgrade includes major version changes for Apache Hive from 2.x to 4.x/3.x and a minor upgrade for Apache Hudi. The Hive upgrade is a high-risk, complex migration that requires significant manual intervention and will introduce breaking API changes. High-Risk Upgrades1. org.apache.hive:hive-jdbc @ 2.3.4 → 4.0.0 These packages are part of a major Apache Hive upgrade from version 2.x to 3.x and 4.x. This is not a drop-in replacement and requires a carefully planned migration. Both Hive 2.x and 3.x are now considered End-of-Life (EOL). Key Breaking Changes & Required Actions:
Recommendation: This is a major migration effort that requires careful planning, data migration, and code refactoring. It should not be merged without a dedicated migration project to address the prerequisite steps and API changes. Medium-Risk Upgrades4. org.apache.hudi:hudi-common @ 1.0.0-SNAPSHOT → 1.1.0 This upgrade moves from a snapshot version to a stable minor release. While it includes significant performance improvements and new features, it also introduces a breaking API change. Key Breaking Changes & Required Actions:
Recommendation: Review code that implements Hudi record merging logic and update it to use the new, recommended APIs to avoid breakage.
|
⛔ Snyk checks have failed. 135 issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEZOOKEEPER-15443353
Snyk has created this PR to fix 1 vulnerabilities in the maven dependencies of this project.
Snyk changed the following file(s):
pom.xmlVulnerabilities that will be fixed with an upgrade:
SNYK-JAVA-ORGAPACHEZOOKEEPER-15443353
2.3.4->4.0.0org.apache.hive:hive-metastore:
2.3.4->4.0.0org.apache.hive:hive-service:
2.3.4->3.1.0Major version upgradeNo Path FoundNo Known ExploitBreaking Change Risk
Vulnerabilities that could not be fixed
org.apache.hudi:hudi-common@1.0.0-SNAPSHOTtoorg.apache.hudi:hudi-common@1.1.0; Reasoncould not apply upgrade, dependency is managed externally; Location:provenance does not contain locationImportant
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Insertion of Sensitive Information into Log File