[Feature][Linkis]Security Work Order - Basic Tool Library Dependency Version Upgrade
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 45/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- java
- Domain
- build-system, security
Research direction
Find the dependency declarations for guava.version and jackson-bom.version, then review how those versions are used across the Linkis build. Run the existing test suite and verify that upgrading to Guava 33.2.1-jre and Jackson 2.15.0 introduces no compatibility or stability regressions.
Written by the indexing model from the issue text.
Description
Search before asking
- I had searched in the
https://github.com/apache/linkis/issuesand found no similar feature requirement.
Problem Description
Linkis使用的基础工具库版本存在安全漏洞,需要升级Guava和Jackson到安全版本。
Description
- guava.version: 从32.0.0-jre升级到33.2.1-jre,修复已知安全漏洞
- jackson-bom.version: 从2.13.4.20221013升级到2.15.0,修复已知安全漏洞
- 确保升级后的依赖与现有代码兼容
Use case
确保Linkis系统在生产环境中的安全性,修复已知的基础工具库漏洞。
Solutions
- 升级guava.version到33.2.1-jre
- 升级jackson-bom.version到2.15.0
- 验证所有依赖升级后的兼容性和稳定性
- 进行全面的测试验证
Anything else
none
Are you willing to submit a PR?
- Yes I am willing to submit a PR!
- Dominant language
- Java
- Stars
- 3.4k
- Forks
- 1.2k
- PR merge metrics
- No merged PRs in 30d
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from apache/linkis
-
[Bug] linkis-application-manager's RMUtils class has a logic bugMay be free again @zhang-arvin claimed this 38 days ago, and no pull request is open. Openbug
Difficulty 1/5 Under an hour Newbie friendliness 86/100
-
[Bug][CI] GitHub Actions startup failure: third-party actions not in ASF allow-listPossibly taken @aiceflower claimed this today. Openbug
Difficulty 3/5 1-2 days Newbie friendliness 35/100
-
Scala Compilation is broken on master branch and recent PRsPossibly taken @pjfanning claimed this 16 days ago. Open
Difficulty 4/5 3-5 days Newbie friendliness 38/100
-
[bug][CGS][entrance] parallelgroup cache not updated when entrance instance goes offlinePossibly taken @zhang-arvin claimed this 30 days ago. Open
Difficulty 4/5 3-5 days Newbie friendliness 55/100
-
Difficulty 4/5 3-5 days Newbie friendliness 28/100
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
NationalSecurityAgency/ghidra#9748 ·
Maintainers usually reply within 1 day
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
Maintainers usually reply within 1 day
-
spring-mcp-tools
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
explyt/spring-plugin#591 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
jenkinsci/build-monitor-plugin#1367 ·
Maintainers usually reply within 1 day
-
waiting-for-triage
Difficulty 1/5 Under an hour Newbie friendliness 72/100
spring-cloud/spring-cloud-openfeign#1443 ·
Maintainers usually reply within 1 day