Skip to content

Suppress CVE in libthrift#11093

Merged
suneet-s merged 1 commit intoapache:masterfrom
suneet-s:security
Apr 13, 2021
Merged

Suppress CVE in libthrift#11093
suneet-s merged 1 commit intoapache:masterfrom
suneet-s:security

Conversation

@suneet-s
Copy link
Copy Markdown
Contributor

@suneet-s suneet-s commented Apr 11, 2021

#11028 talks about bumping the libthrift dependency. This patch simply suppresses the CVE so that the cron CI will show it as successful since there is already a tracking issue to fix this.

To ensure that we do not forget about fixing the issue, the suppression has an expiration date of the end of the month.

This PR has:

  • been self-reviewed.
  • added comments explaining the "why" and the intent of the code wherever would not be obvious for an unfamiliar reader.
  • been tested locally

@suneet-s suneet-s added Area - Dev For items related to the project itself, like dev docs and checklists, but not CI Security labels Apr 11, 2021
@suneet-s suneet-s merged commit c86178a into apache:master Apr 13, 2021
@suneet-s suneet-s deleted the security branch April 13, 2021 01:13
jihoonson pushed a commit to jihoonson/druid that referenced this pull request Apr 14, 2021
@jihoonson jihoonson added this to the 0.21.0 milestone Apr 14, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Area - Dev For items related to the project itself, like dev docs and checklists, but not CI Security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants