flink-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From GitBox <...@apache.org>
Subject [GitHub] [flink] knaufk opened a new pull request #8123: FLINK-12119 [build-system] add owasp-dependency-check plugin
Date Mon, 08 Apr 2019 11:10:19 GMT
knaufk opened a new pull request #8123: FLINK-12119 [build-system] add owasp-dependency-check
URL: https://github.com/apache/flink/pull/8123
   ## What is the purpose of the change
   * Add OWASP dependency check to Flink build to keep track of known security vulnerabilities
in Flink's dependencies
   ## Brief change log
   * Added maven-dependency-check plugin check to parent pom
   * Skipping dependency-check for docs, contrib, yarn-tests & fs-tests
   ## Verifying this change
   *(Please pick either of the following options)*
   This change is a trivial rework / code cleanup without any test coverage.
   This change added tests and can be verified as follows:
   Run {{mvn clean org.owasp:dependency-check-maven:5.0.0-M2:aggregate}} and check depdency-report
in target directory
   ## Does this pull request potentially affect one of the following parts:
     - Dependencies (does it add or upgrade a dependency): no
     - The public API, i.e., is any changed class annotated with `@Public(Evolving)`: no
     - The serializers: no
     - The runtime per-record code paths (performance sensitive): no
     - Anything that affects deployment or recovery: JobManager (and its components), Checkpointing,
Yarn/Mesos, ZooKeeper: no
     - The S3 file system connector: no
   ## Documentation
     - Does this pull request introduce a new feature? yes, to the build-system
     - If yes, how is the feature documented? not sure, where to document it

This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
For queries about this service, please contact Infrastructure at:

With regards,
Apache Git Services

View raw message