world-federation-of-advertisers / cross-media-measurement

Apache License 2.0
33 stars 11 forks source link

Panel exchange daemon images have old, vulnerable library dependencies #1578

Open SanjayVas opened 3 months ago

SanjayVas commented 3 months ago

The container images for panel exchange daemons depend on an old version of Apache Beam libraries. These have vendored dependencies on old, vulnerable artifacts. The Beam library dependency cannot be updated due to the deprecated Spark 2 support being dropped. Spark 2 support is currently required for Meta infrastructure.

AwsExampleDaemon:

GoogleCloudExampleDaemon:

stevenwarejones commented 3 months ago

This is unblocked from a Meta perspective. Instead, I think what's holding this up is cloud testing to ensure to breakage or unforeseen issues for Kantar.