Skip to content

Address CVE-2020-8570, suppress CVE-2020-8554#10826

Merged
jihoonson merged 2 commits intoapache:masterfrom
jon-wei:k8s_cve
Feb 3, 2021
Merged

Address CVE-2020-8570, suppress CVE-2020-8554#10826
jihoonson merged 2 commits intoapache:masterfrom
jon-wei:k8s_cve

Conversation

@jon-wei
Copy link
Copy Markdown
Contributor

@jon-wei jon-wei commented Feb 1, 2021

The dependency check currently fails on the kubernetes extension due to the CVEs in the title.

This PR:

This PR has:

  • been self-reviewed.
  • added documentation for new or modified features or behaviors.
  • added Javadocs for most classes and all non-trivial methods. Linked related entities via Javadoc links.
  • added or updated version, license, or notice information in licenses.yaml
  • added comments explaining the "why" and the intent of the code wherever would not be obvious for an unfamiliar reader.
  • added unit tests or modified existing tests to cover new code paths, ensuring the threshold for code coverage is met.
  • added integration tests.
  • been tested in a test Druid cluster.

@jihoonson
Copy link
Copy Markdown
Contributor

The leadership integration test failures should be fixed by #10846. I'm merging this PR to unblock other PRs from getting merged.

@jihoonson jihoonson merged commit a1a4981 into apache:master Feb 3, 2021
jon-wei added a commit to jon-wei/druid that referenced this pull request Feb 11, 2021
* move integration tests from ZooKeeper 3.4.x to 3.5.x (apache#10786)

* move integration tests from ZooKeeper 3.4.x to 3.5.x
* run a subset of our integration tests with ZK 3.4 for backwards compatibility testing.
* remove need to build separate docker-base image
- use multi-stage build for the base image
- use openjdk base image instead of building our own JDK base
- workaround Debian not including MySQL by using MariaDB
- download mysql connector directly instead of using distro version
* fix incorrect openssl command failing on Debian
* keep mysql connector version in sync with pom version

* K8s IT Test enhance  (apache#10785)

* do build and stop action in IT

* change base dir from druidHome to druidHome/integration-tests

* add env DRUID_HOME

* bug fix

* modify stop_sh

* ready to test

* bug fix

* modify dir

* tested on dev

* modify dir

* move DRUID_HOME env

* done

Co-authored-by: yuezhang <yuezhang@freewheel.tv>

* Update NOTICE copyright year (apache#10834)

the future is now

* Cleanup openssl fixes to keep certs

* Address CVE-2020-8570, suppress CVE-2020-8554 (apache#10826)

* Address CVE-2020-8570, suppress CVE-2020-8554

* Update licenses.yaml

* wget debug

* Suppress CVE-2020-9492 for hadoop-mapreduce-client-core (apache#10847)

* Revert "wget debug"

This reverts commit 5b81c33b4728420e2312b3c919b7de9c1b4da589.

* Add MYSQL_VERSION env variable in integration-tests-imply tests

* Increase heap to 64m for custom node (apache#10846)

* Fix CVE-2021-25646 (apache#10818)

* Add ZK_VERSION env variable

Co-authored-by: Xavier Léauté <xvrl@apache.org>
Co-authored-by: zhangyue19921010 <69956021+zhangyue19921010@users.noreply.github.com>
Co-authored-by: yuezhang <yuezhang@freewheel.tv>
Co-authored-by: Clint Wylie <cwylie@apache.org>
Co-authored-by: Slava Mogilevsky <triggerwoods91@gmail.com>
Co-authored-by: Jihoon Son <jihoonson@apache.org>
jihoonson pushed a commit to jihoonson/druid that referenced this pull request Apr 14, 2021
@jihoonson jihoonson added this to the 0.21.0 milestone Apr 14, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants