apache / submarine

Submarine is Cloud Native Machine Learning Platform.
https://submarine.apache.org/
Apache License 2.0
689 stars 252 forks source link

submarine uses a non OSS friendly version of org.json jar #1119

Open pjfanning opened 5 months ago

pjfanning commented 5 months ago

https://github.com/apache/submarine/blob/246ecee0706cad8cfa6a66006a7005c67ae235da/pom.xml#L135

See https://www.apache.org/legal/resolved.html (JSON license section)

Could you upgrade to a newer version? And these versions have security fixes too.

Since late 2022, this jar is now properly in the public domain.

cdmikechen commented 4 months ago

@pjfanning Thanks for that, I'll fix it this weekend