Skip to content

[Feature][Linkis]Security Work Order - Basic Tool Library Dependency Version Upgrade #5308

@v-kkhuang

Description

@v-kkhuang

Search before asking

  • I had searched in the https://github.com/apache/linkis/issues and found no similar feature requirement.

Problem Description

Linkis使用的基础工具库版本存在安全漏洞,需要升级Guava和Jackson到安全版本。

Description

  1. guava.version: 从32.0.0-jre升级到33.2.1-jre,修复已知安全漏洞
  2. jackson-bom.version: 从2.13.4.20221013升级到2.15.0,修复已知安全漏洞
  3. 确保升级后的依赖与现有代码兼容

Use case

确保Linkis系统在生产环境中的安全性,修复已知的基础工具库漏洞。

Solutions

  1. 升级guava.version到33.2.1-jre
  2. 升级jackson-bom.version到2.15.0
  3. 验证所有依赖升级后的兼容性和稳定性
  4. 进行全面的测试验证

Anything else

none

Are you willing to submit a PR?

  • Yes I am willing to submit a PR!

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions