Skip to content

APPSEC-60: Upgrade org.apache.maven:apache-maven - #564

Merged
xjin-Confluent merged 1 commit into
2.5from
upgrade-maven-artifact
May 19, 2021
Merged

APPSEC-60: Upgrade org.apache.maven:apache-maven#564
xjin-Confluent merged 1 commit into
2.5from
upgrade-maven-artifact

Conversation

@xjin-Confluent

Copy link
Copy Markdown

Upgrade org.apache.maven:apache-maven.

Committer Checklist (excluded from commit message)

  • Verify design and implementation
  • Verify test coverage and CI build status
  • Verify documentation (including upgrade notes)

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

xjin-Confluent Thanks for the PR. LGTM

@xjin-Confluent

Copy link
Copy Markdown
Author

xjin-Confluent Thanks for the PR. LGTM

BTW, what is this package used for? That seems to be a package from Apache Maven.

@omkreddy

Manikumar Reddy (omkreddy) commented May 17, 2021

Copy link
Copy Markdown
Member

xjin-Confluent Thanks for the PR. LGTM

BTW, what is this package used for? That seems to be a package from Apache Maven.

Yeah, I think connect module is using utility class for parsing and storing connector lib version. . We can copy the util class and remove the maven package usage if required.
cc Konstantine Karantasis (@kkonstantine)

@xjin-Confluent

xjin-Confluent commented May 17, 2021

Copy link
Copy Markdown
Author

xjin-Confluent Thanks for the PR. LGTM

BTW, what is this package used for? That seems to be a package from Apache Maven.

Yeah, I think connect module is using utility class for parsing and storing connector lib version. . We can copy the util class and remove the maven package usage if required.
cc Konstantine Karantasis (@kkonstantine)

We'd prefer if this could be removed easily. Can you create a Jira and track the work? For https://confluentinc.atlassian.net/browse/APPSEC-60, this PR is sufficient.

@omkreddy

Manikumar Reddy (omkreddy) commented May 17, 2021

Copy link
Copy Markdown
Member

We'd prefer if this could be removed easily. Can you create a Jira and track the work?

Pls check with #connect-eng team

@kkonstantine

Copy link
Copy Markdown
Member

If this dependency is problematic, indeed we can consider copying the class. I'll create a Jira ticket tomorrow. Probably will be good to address in AK directly.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants