Comments (4)
Actually, Jackson is a huge problem, since it leads to all kinds of compatibility problems in downstream projects.
apache/pekko-projection#19 shows a problem where we probably cannot release a 1.0.0 of pekko-projection without upgrading Jackson everywhere (i.e. we can release it but it won't work with pekko-persistence-cassandra which might be one of the main combination that people are using). The reason is that the last OS version of akka-projection is built against an old version of alpakka-cassandra (2.0.1) that we don't intend to support (pekko-connectors is based on alpakka 3).
IMO we should under no circumstances stay on Jackson 2.11 which is not supported any more and has all kinds of published security issues that will be immediately flagged for users. The question would still be which version to use instead (2.12, 2.13, or 2.14). This is hard to find out because so many potential combinations of subprojects need to be considered. Given the history of problems with Jackson, I would recommend going to the latest version (2.14) because that will hold up for the longest time.
Updating the version here will mean that we might pull up Jackson for our users. I consider that a much smaller problem (since there will be all kinds of challenges users might have while updating to Pekko) than staying on the old and broken version.
from pekko.
Can't we downgrade the cassandra driver - to one that uses Jackson 2.11?
Jackson 2.12.7.1 has no CVEs if we want to upgrade but not go all the way to Jackson 2.14. Jackson 2.15 is out soon but that introduces a StreamReadConstraints setting that defaults to high limits but not unlimited values so we would probably need to add settings in reference.conf that allow users to choose higher limits.
from pekko.
apache/pekko-projection#19 (review) is relevant
from pekko.
this is done
from pekko.
Related Issues (20)
- Move link validator to nightly/weekly job
- handle the case where `DeviceTerminated.groupId` may not match the `DeviceGroup.groupId` HOT 2
- review test dependency overrides associated with docker-java
- java.lang.UnsupportedOperationException pekko migration HOT 5
- EventSourcedBehavior/Durable State exposed to stack overflow when lots of read-only commands are in the stash HOT 6
- Reproducible Scala 3 artifacts HOT 1
- With entity passivation enabled the shard region will cause a lot of unhandled ShardsUpdated during shutdown
- Feature request: Add BoundedSourceQueue#isComplete method
- double "a" appearing in tutorial HOT 2
- Add FutureTimeoutSupport#timeout support HOT 4
- Add UntypedAbstractActorWithTimers
- Add Flow#onBackpressureDrop() operator HOT 2
- Support just warning instead of error when `pekko.scheduler.tick-duration` < 10ms on Windows?
- Bug - Assertion failure caused by exception during pre-start HOT 3
- stream-testkit: issue with scala 2.12 usage of expectNextWithTimeoutPF HOT 9
- long running tests should be run in a nightly build HOT 2
- Deprecate `org.apache.pekko.dispatch.Futures` HOT 3
- Attribute overriding in `SourceQueueWithComplete`
- jdk9 tests do not run HOT 1
- Feature: backoff for Pattern#retry
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from pekko.