spark-instrumented-optimizer/dev/deps
Adam Roberts 04a2c072d9 [SPARK-16751] Upgrade derby to 10.12.1.1
## What changes were proposed in this pull request?

Version of derby upgraded based on important security info at VersionEye. Test scope added so we don't include it in our final package anyway. NB: I think this should be backported to all previous releases as it is a security problem https://www.versioneye.com/java/org.apache.derby:derby/10.11.1.1

The CVE number is 2015-1832. I also suggest we add a SECURITY tag for JIRAs

## How was this patch tested?
Existing tests with the change making sure that we see no new failures. I checked derby 10.12.x and not derby 10.11.x is downloaded to our ~/.m2 folder.

I then used dev/make-distribution.sh and checked the dist/jars folder for Spark 2.0: no derby jar is present.

I don't know if this would also remove it from the assembly jar in our 1.x branches.

Author: Adam Roberts <aroberts@uk.ibm.com>

Closes #14379 from a-roberts/patch-4.
2016-07-29 04:43:01 -07:00
..
spark-deps-hadoop-2.2 [SPARK-16751] Upgrade derby to 10.12.1.1 2016-07-29 04:43:01 -07:00
spark-deps-hadoop-2.3 [SPARK-16751] Upgrade derby to 10.12.1.1 2016-07-29 04:43:01 -07:00
spark-deps-hadoop-2.4 [SPARK-16751] Upgrade derby to 10.12.1.1 2016-07-29 04:43:01 -07:00
spark-deps-hadoop-2.6 [SPARK-16751] Upgrade derby to 10.12.1.1 2016-07-29 04:43:01 -07:00
spark-deps-hadoop-2.7 [SPARK-16751] Upgrade derby to 10.12.1.1 2016-07-29 04:43:01 -07:00