Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade the ZooKeeper charts for log4j exposure #173

Open
akash-apple opened this issue Nov 17, 2023 · 0 comments
Open

Upgrade the ZooKeeper charts for log4j exposure #173

akash-apple opened this issue Nov 17, 2023 · 0 comments

Comments

@akash-apple
Copy link

Description

Hey team,
Latest released solr-operator (https://artifacthub.io/packages/helm/apache-solr/solr-operator) v0.8.0 has a dependency on ZooKeeper operator (https://artifacthub.io/packages/helm/banzaicloud-stable/zookeeper-operator) v0.2.15 which in turn depends on older ZooKeeper version exposing log4j 1.x usage for Solr.

Latest ZooKeeper version mitigated this issue by upgrading underlying ZooKeeper deps. This issue is created to request release of new solr-operator chart that depends on updated ZooKeeper to remediate log4j exposure for downstream Ranger/Solr users.

Importance

Apache community depending on these charts using ZooKeeper will benefit from remediation of log4j issues.

Location

N/A

Suggestions for an improvement

Releasing a new chart for ZooKeeper operator will help solr-operator to upgrade their dependency, which will have exponential impact on the OSS community.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant