Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[Feature][Linkis]Security Work Order - Basic Tool Library Dependency Version Upgrade

Open
#5,308 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
45/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Stale
Tech stack
java

Research direction

Find the dependency declarations for guava.version and jackson-bom.version, then review how those versions are used across the Linkis build. Run the existing test suite and verify that upgrading to Guava 33.2.1-jre and Jackson 2.15.0 introduces no compatibility or stability regressions.

Written by the indexing model from the issue text.

Description

feature
Search before asking
  • I had searched in the https://github.com/apache/linkis/issues and found no similar feature requirement.
Problem Description

Linkis使用的基础工具库版本存在安全漏洞,需要升级Guava和Jackson到安全版本。

Description
  1. guava.version: 从32.0.0-jre升级到33.2.1-jre,修复已知安全漏洞
  2. jackson-bom.version: 从2.13.4.20221013升级到2.15.0,修复已知安全漏洞
  3. 确保升级后的依赖与现有代码兼容
Use case

确保Linkis系统在生产环境中的安全性,修复已知的基础工具库漏洞。

Solutions
  1. 升级guava.version到33.2.1-jre
  2. 升级jackson-bom.version到2.15.0
  3. 验证所有依赖升级后的兼容性和稳定性
  4. 进行全面的测试验证
Anything else

none

Are you willing to submit a PR?
  • Yes I am willing to submit a PR!
Dominant language
Java
Stars
3.4k
Forks
1.2k
PR merge metrics
No merged PRs in 30d

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from apache/linkis

All issues in apache/linkis

Similar issues

More Java issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.