-
Notifications
You must be signed in to change notification settings - Fork 295
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
spark-3.5-scala-2.13/3.5.4-r0: cve remediation #38452
spark-3.5-scala-2.13/3.5.4-r0: cve remediation #38452
Conversation
Gen AI suggestions to solve the build error: Based on the build error, I'll provide a structured analysis and solution: • Detected Error: "Could not resolve dependencies for project org.apache.spark:spark-core_2.13:jar:3.5.4: The following artifacts could not be resolved: org.eclipse.jetty:jetty-server:jar:9.4.56" • Error Category: Dependency • Failure Point: Maven dependency resolution for spark-core_2.13 module • Root Cause Analysis: • Suggested Fix: # In pombump-properties.yaml
properties:
jetty.version: 9.4.54.v20240208 # Update to latest stable 9.4.x version • Explanation:
• Additional Notes:
• References:
|
…isories filed for each of the affected components Signed-off-by: Mark McCormick <[email protected]>
I removed the attempted pombumps for jetty, as advisories were required for them (see last comment) |
This should be resolved by the work done in this PR: |
spark-3.5-scala-2.13/3.5.4-r0: fix GHSA-rcjc-c4pj-xxrp/GHSA-8qv5-68g4-248j/GHSA-2jc4-r94c-rp7h/GHSA-j26w-f9rq-mr2q/GHSA-g8m5-722r-8whq/
Advisory data: https://github.com/wolfi-dev/advisories/blob/main/spark-3.5-scala-2.13.advisories.yaml