Repository navigation
Clear all 48 oss-canary CVEs blocking ELR and bump to 2.45.61 - #180
Merged
Merged
Conversation
ELR 367778 for beam-runners-flink-1.18:2.45.60 failed oss-canary validation with 48 flagged Maven coordinates. This clears all 48 and shrinks the runtime dependency graph from 212 to 70 nodes. Drop google-cloud-platform-core from the Flink runner (clears 31). It was a compile-scope dependency reaching the published POM, but its only use in main source was one line in FlinkJobServerDriver setting a GCS upload buffer. beam-runner already excludes the GCP artifacts. Bump flagged libraries: jackson 2.14.1 -> 2.19.2 (also pulls snakeyaml 2.4), classgraph -> 4.8.179, commons-compress -> 1.27.1, commons-lang3 -> 3.18.0, snappy-java -> 1.1.10.7. commons-io -> 2.16.1 and commons-codec -> 1.17.1 are required floors for commons-compress 1.26+. Exclude commons-compress from the Flink modules. flink-core declares 1.21 in its own POM and reaches it only through the compressed FileInputFormat factories, which Beam pipelines do not use. Migrate Avro 1.8.2 -> 1.11.4, which clears the last two coordinates. Move the codegen plugin to com.github.davidmc24.gradle.plugin:gradle-avro-plugin:1.9.1 so generated sources match the runtime Avro version, declare org.tukaani:xz explicitly since Avro 1.11 marks it optional, and add java.time branches to the AvroUtils converters for Avro 1.9+ date/timestamp logical types. The Kryo and SerializableSchemaSupplier changes are ported from upstream Beam 2.75. Avro ReflectData field ordering changed in Avro 1.10, but beam-runner already pins 1.11.3, so LinkedIn runtime behavior is unchanged; the updated test expectations align Beam with what already executes. Bump version to 2.45.61. BeamModulePlugin.groovy is the publish trigger and holds project.version, so a change there without a bump would republish 2.45.60. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
cirquare
marked this pull request as ready for review
October 2, 2026 20:54
yananhao12
approved these changes
Oct 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
ELR 367778 for
com.linkedin.beam:beam-runners-flink-1.18:2.45.60failedoss-canaryvalidation with 48 flagged Maven coordinates, blocking publication. This clears all 48 and shrinks the runtime dependency graph from 212 to 70 nodes.Why the previous tickets did not unblock it
ELR runs two independent gates. INFOSEC-143688 and TOOLS-496440 both address the 7-day cooldown gate — INFOSEC-143688 explicitly says "from the age requirement only." ELR 367778 failed the vulnerability gate, which is separate.
Also worth noting:
oss-canarywalks the unresolved POM graph (the report lists 10 guava versions, 9 protobuf-java, 6 jackson-core). Gradleforce/resolutionStrategycannot help, because losing versions remain as nodes. Only edge removal, exclusion, or raising a version we declare ourselves works.The 2.45.58 → 2.45.60 diff touched only
DoFnOperatorand the version bump — no dependency changes. The artifact did not regress; the CVE feed got stricter.Changes
1. Drop
google-cloud-platform-corefrom the Flink runner — clears 31 coordinatesIt was a compile-scope dependency reaching the published POM and pulling the entire Google Cloud stack, but its only use in main source was one line in
FlinkJobServerDriversetting a GCS upload buffer for the portability job server. This removesguava(10 versions),protobuf-java(9),grpc-netty-shaded(4),gson(3),google-oauth-client(2),protobuf-javalite(2),bouncycastle(2),httpclient,protobuf-parent, oldjackson-core2.9.6–2.13.4, andcommons-lang3:3.5.Safe downstream:
beam-runneralready excludes the GCP artifacts (exclude group: 'com.google.cloud'inbuild.gradle, plus a gcp-core exclusion inruntime-spark), andruntime-flinknever references gcp-core. ThetestImplementationonsdks:java:io:google-cloud-platformis untouched.2. Version bumps in
BeamModulePlugin.groovycreateParser(DataInput)ClassUtils.getClassuncontrolled recursionSnappyInputStreamDoSsnakeyaml1.33 → 2.4 comes free viajackson-dataformat-yaml, fixing CVE-2022-1471.Note: commons-compress 1.26+ calls
BoundedInputStream.builder(), which requires commons-io ≥ 2.16. Bumping it alone fails 32 tests withNoSuchMethodError.3. Exclude
commons-compressfrom the Flink modules — clears 1flink-core:1.18.0declares 1.21 in its own POM, so bumping ours does not remove it from the scan. Verifiedflink-runtimereferences it in 0 classes andflink-corein exactly 3 (Bzip2/XZ/ZStandardInputStreamFactory— the compressedFileInputFormatpath Beam pipelines never use). Beam still supplies the patched 1.27.1 viasdks:java:core → avro.Per-dependency exclusions are used deliberately; a blanket
configurations.all { exclude ... }was tried and rejected because it stripped commons-compress entirely, including the copy Avro needs for its bzip2/xz codecs.4. Avro 1.8.2 → 1.11.4 — clears the last 2 (
avro:1.8.2,jackson-mapper-asl:1.9.13)com.github.davidmc24.gradle.plugin:gradle-avro-plugin:1.9.1(bundlesavro-compiler:1.11.3). The old0.16.0pinnedavro-compiler:1.8.2, which emitsTimeConversions.TimeConversion/TimestampConversion— deleted in Avro 1.9 when Joda was dropped forjava.time. The now-unused JitPack repository entry is removed.org.tukaani:xzdeclared explicitly — Avro 1.11 marks it optional, so it silently left the classpath and broke the xz codec.org.apache.avro.RandomData→org.apache.avro.util.RandomData.java.timebranches added to theAvroUtilsByteBuddy converters (AvroConvertType,...ForGetter,...ForSetter) and to the runtimeLogicalTypes.TimestampMillispath. Purely additive — these types previously threwClassCastException.addDefaultSerializer(SerializableSchemaSupplier.class, JavaSerializer.class)plus widening that class fromprivateto package-private, exactly as upstream. Root cause is Avro 1.9+ givingJsonPropertiesan instance-level immutablereservedSet that Kryo cannot rebuild.5. Version bump to 2.45.61
BeamModulePlugin.groovyis the publish trigger path and holdsproject.version(line 401), so changing it without a bump would republish 2.45.60. Applied via./update_version.sh 2.45.61.On the Avro ReflectData field-order change — no production impact
Avro's
ReflectDataswitched from declaration order to alphabetical. Measured directly across versions:The change landed in Avro 1.10, and 1.11.3 is behaviorally identical to 1.11.4.
ReflectDataresolves at runtime from the classpath, andbeam-runner'sproduct-spec.jsonalready pins 1.11.3 — so LinkedIn jobs have been getting alphabetical ordering all along. Beam declaring 1.8.2 only affected what Beam compiled and tested against.The updated
AvroSchemaTestexpectations are therefore Beam's tests catching up to what already runs, not a behavior change. This PR removes a version skew rather than introducing one. No repo in the SP workspace pins Avro below 1.10 (beam-runner1.11.3,ctc1.11.4).Testing Done
Local, JDK 11 (CI uses JDK 8 — see caveat below).
:runners:flink:build+:runners:flink:1.18:build:runners:flink:1.18:test:runners:flink:1.20:test:runners:spark:3:build:runners:samza:build:sdks:java:core:test:runners:core-java:testspotlessApply+checkstyleEvery failure was baselined against clean
li_trunkin a separate worktree before being attributed. For Samza the failing-test name sets were compared and are identical (21 vs 21, zero new). Samza failures are an arm64 macOS issue (NoClassDefFoundError: org.rocksdb.Options— no Apple Silicon native in the bundled RocksDB JNI) and should pass on CI'subuntu-latest.Pre-existing failures carried over unchanged:
ProxyInvocationHandlerTest.testConcurrency,DistributionCellTest.{testEquals,testReset},MetricsContainerImplTest.*(3),MetricsContainerStepMapTest.*,SplittableParDoProcessFnTest.testCheckpointsAfterDuration.CVE verification
Re-resolved
:runners:flink:1.18:runtimeClasspathand checked each of the 48 reported coordinates:Published POM verified: gcp-core absent,
jackson-databindat 2.19.2,<exclusion>entries present for commons-compress.Caveats for reviewers
javaVersion=1.8); all local validation ran on JDK 11 (no JDK 8 available locally).validatesRunnernot run locally for Flink, Spark, or Samza. CI runs all three.BeamModulePlugin.groovymatches the trigger path for the Flink, Spark, and both Samza workflows, so all four will run even though only Flink files changed.auto-elrpublishes 22 modules, each with its own ELR. The version bumps and Avro migration help all of them, but the gcp-core removal only helps Flink —sdks:java:extensions:google-cloud-platform-coreandsdks:java:io:google-cloud-platformare GCP by nature and will still carry that stack.sdks:java:corehas pre-existing spotless and checkstyle violations in unrelated files (DLQ /WindowedValue*), left untouched here.