upgrade thrift to v0.14.1 in jaeger exporter#1712
Merged
MrAlias merged 5 commits intoopen-telemetry:mainfrom Mar 22, 2021
Merged
upgrade thrift to v0.14.1 in jaeger exporter#1712MrAlias merged 5 commits intoopen-telemetry:mainfrom
MrAlias merged 5 commits intoopen-telemetry:mainfrom
Conversation
Member
|
This shouldn't have dependencies under |
Codecov Report
@@ Coverage Diff @@
## main #1712 +/- ##
=======================================
- Coverage 77.8% 77.8% -0.1%
=======================================
Files 131 131
Lines 6985 6984 -1
=======================================
- Hits 5439 5437 -2
- Misses 1296 1297 +1
Partials 250 250
|
Aneurysm9
approved these changes
Mar 18, 2021
MrAlias
approved these changes
Mar 22, 2021
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
With CVE-2020-13949 in mind, this PR upgrades the version of the vendored thrift library in the jaeger exporter from v0.13.0 to v0.14.1. It was not super clear to me why the thrift dependencies were packaged in this way, but I did my best to adhere to the established patterns as best I could, with respect to how the libraries were packaged into the exporter.
The thrift code was incorporated from a vendored version of the v0.14.1 library and I used thrift version 0.14.1 to auto-generate the jaeger-specific libraries from the jaeger-idl, modifying it only to establish new dependency paths within the opentracing project itself.