Comments (3)
Actually, Jackson is a huge problem, since it leads to all kinds of compatibility problems in downstream projects.
apache/pekko-projection#19 shows a problem where we probably cannot release a 1.0.0 of pekko-projection without upgrading Jackson everywhere (i.e. we can release it but it won't work with pekko-persistence-cassandra which might be one of the main combination that people are using). The reason is that the last OS version of akka-projection is built against an old version of alpakka-cassandra (2.0.1) that we don't intend to support (pekko-connectors is based on alpakka 3).
IMO we should under no circumstances stay on Jackson 2.11 which is not supported any more and has all kinds of published security issues that will be immediately flagged for users. The question would still be which version to use instead (2.12, 2.13, or 2.14). This is hard to find out because so many potential combinations of subprojects need to be considered. Given the history of problems with Jackson, I would recommend going to the latest version (2.14) because that will hold up for the longest time.
Updating the version here will mean that we might pull up Jackson for our users. I consider that a much smaller problem (since there will be all kinds of challenges users might have while updating to Pekko) than staying on the old and broken version.
from incubator-pekko.
Can't we downgrade the cassandra driver - to one that uses Jackson 2.11?
Jackson 2.12.7.1 has no CVEs if we want to upgrade but not go all the way to Jackson 2.14. Jackson 2.15 is out soon but that introduces a StreamReadConstraints setting that defaults to high limits but not unlimited values so we would probably need to add settings in reference.conf that allow users to choose higher limits.
from incubator-pekko.
apache/pekko-projection#19 (review) is relevant
from incubator-pekko.
Related Issues (20)
- license: acknowledge use of netty code HOT 1
- license: acknowledge use of codahale code HOT 5
- other source files to add licenses to HOT 4
- Drop the shaded protobuf? HOT 1
- use standard pekko notice in jars (except when additions needed) HOT 1
- migrate incubator-pekko-samples to use pekko snapshots HOT 6
- rewrite pekko-platform-guide to use pekko artifacts and to remove Akka refs HOT 3
- remove or replace algolia and google analytics properties HOT 1
- update signature and fiddle properties in project/Paradox.scala HOT 1
- correct values for project-info.conf jdk-versions HOT 1
- current value for project-info.conf release notes link
- Introduce a timer source api? HOT 6
- Remove explicit handling of `java8Home` entirely in Pekko sbt build HOT 3
- See if `scripts/link-validator.conf` can accept wildcards to remove needing to specify Scala minor versions
- Make BroadcastHub only start pulling after atleast one Consumer attached to it?
- Investigate removal of bespoke JDK 1.8 `rt.jar` handling
- Investigate fixing exhaustive match issues in Pekko codebase HOT 5
- Move akka.japi. to java.util.function. HOT 2
- FAILED: HandshakeRetrySpec HOT 1
- Update the deprecate messages HOT 3
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from incubator-pekko.