Skip to content
This repository was archived by the owner on Apr 16, 2025. It is now read-only.

Commit 3cb6ee3

Browse files
authored
Merge pull request #595 from usc-isi-i2/security-oct-2023
Security update October
2 parents 2c436cf + aab3764 commit 3cb6ee3

File tree

7 files changed

+16
-18
lines changed

7 files changed

+16
-18
lines changed

karma-common/pom.xml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@
2222
<dependency>
2323
<groupId>com.fasterxml.jackson.core</groupId>
2424
<artifactId>jackson-core</artifactId>
25-
<version>2.3.3</version>
25+
<version>2.13.4</version>
2626
</dependency>
2727
<dependency>
2828
<groupId>org.glassfish.jersey.core</groupId>
@@ -143,7 +143,7 @@
143143
<dependency>
144144
<groupId>org.apache.avro</groupId>
145145
<artifactId>avro</artifactId>
146-
<version>1.7.7</version>
146+
<version>1.11.3</version>
147147
<exclusions>
148148
<exclusion>
149149
<groupId>org.xerial.snappy</groupId>
@@ -154,7 +154,7 @@
154154
<dependency>
155155
<groupId>org.apache.avro</groupId>
156156
<artifactId>avro-compiler</artifactId>
157-
<version>1.7.7</version>
157+
<version>1.11.3</version>
158158
<exclusions>
159159
<exclusion>
160160
<groupId>org.xerial.snappy</groupId>

karma-common/src/main/java/edu/isi/karma/imp/avro/AvroImport.java

Lines changed: 4 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,6 @@
1515
import org.apache.avro.io.EncoderFactory;
1616
import org.apache.avro.io.JsonEncoder;
1717
import org.apache.commons.io.IOUtils;
18-
import org.codehaus.jackson.JsonFactory;
1918
import org.json.JSONException;
2019

2120
import edu.isi.karma.imp.Import;
@@ -89,17 +88,17 @@ public Worksheet generateWorksheet() throws JSONException, IOException,
8988
GenericDatumWriter<GenericRecord> writer = new GenericDatumWriter<>(reader.getSchema());
9089
while(reader.hasNext())
9190
{
92-
91+
9392
GenericRecord record = reader.next();
94-
JsonEncoder encoder = EncoderFactory.get().jsonEncoder(reader.getSchema(), new JsonFactory().createJsonGenerator(baos)).configure(baos);
93+
JsonEncoder encoder = EncoderFactory.get().jsonEncoder(reader.getSchema(), baos).configure(baos);
9594
writer.write(record, encoder);
9695
encoder.flush();
9796
if(reader.hasNext())
9897
{
9998
baos.write(',');
10099
}
101-
102-
100+
101+
103102
}
104103
reader.close();
105104
baos.write('\n');

karma-jsonld/pom.xml

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
<dependency>
2020
<groupId>org.json</groupId>
2121
<artifactId>json</artifactId>
22-
<version>20230227</version>
22+
<version>20231013</version>
2323
</dependency>
2424
<dependency>
2525
<groupId>org.apache.commons</groupId>
@@ -40,6 +40,10 @@
4040
<groupId>org.xerial.snappy</groupId>
4141
<artifactId>snappy-java</artifactId>
4242
</exclusion>
43+
<exclusion>
44+
<groupId>org.apache.avro</groupId>
45+
<artifactId>avro</artifactId>
46+
</exclusion>
4347
</exclusions>
4448
</dependency>
4549
<dependency>

karma-mr/pom.xml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -183,7 +183,7 @@
183183
<hive.version>0.13.0.2.1.3.0-563</hive.version>
184184
<es.version>1.4.2</es.version>
185185
<es.hadoop.version>2.1.0.Beta2</es.hadoop.version>
186-
<avro.version>1.7.6</avro.version>
186+
<avro.version>1.11.3</avro.version>
187187
</properties>
188188
<dependencies>
189189
<dependency>
@@ -378,7 +378,7 @@
378378
<properties>
379379
<hadoop.version>2.6.0-cdh5.5.0</hadoop.version>
380380
<hive.version>1.1.0-cdh5.5.0</hive.version>
381-
<avro.version>1.7.6-cdh5.5.0</avro.version>
381+
<avro.version>1.11.3-cdh5.5.0</avro.version>
382382
<es.version>1.4.4</es.version>
383383
<es.hadoop.version>2.1.0.Beta2</es.hadoop.version>
384384
</properties>

karma-offline/pom.xml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -56,7 +56,7 @@
5656
<dependency>
5757
<groupId>org.apache.tika</groupId>
5858
<artifactId>tika-parsers</artifactId>
59-
<version>1.18</version>
59+
<version>1.20</version>
6060
</dependency>
6161
<dependency>
6262
<groupId>jaxen</groupId>

karma-spark/pom.xml

Lines changed: 0 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -109,11 +109,6 @@
109109
<artifactId>jsonld-java</artifactId>
110110
<version>0.7.0</version>
111111
</dependency>
112-
<dependency>
113-
<groupId>org.xerial.snappy</groupId>
114-
<artifactId>snappy-java</artifactId>
115-
<version>1.1.10.0</version>
116-
</dependency>
117112
<dependency>
118113
<groupId>com.holdenkarau</groupId>
119114
<artifactId>spark-testing-base_2.11</artifactId>

pom.xml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -235,7 +235,7 @@
235235
<dependency>
236236
<groupId>org.json</groupId>
237237
<artifactId>json</artifactId>
238-
<version>20230227</version>
238+
<version>20231013</version>
239239
</dependency>
240240
<dependency>
241241
<groupId>commons-fileupload</groupId>

0 commit comments

Comments
 (0)