From ctubbsii <>
Subject [GitHub] accumulo pull request #131: ACCUMULO-4356 Remove bundled jars from -bin.tar....
Date Fri, 22 Jul 2016 16:41:35 GMT
Github user ctubbsii commented on a diff in the pull request:
    I don't want to mislead downstream. What I've described appears to be the reality of the
situation, as far as I understand it. You're right that just because there is an update to
a dependency, doesn't mean it will work with Accumulo. That can't be figured out without some
work, and I don't want to communicate that false narrative. However, I also don't want to
communicate that we are responsible for the reliability, security, and stability of all of
our dependencies, because we're not. They each have their own open source communities responsible
for them. Accumulo can no more take responsibility for a security vulnerability in jetty or
commons-io than we can in Hadoop or ZooKeeper.
    What we can do is communicate what worked for us at the time, and we can patch to support
the updated dependencies, as they are brought to our attention (we can also periodically check
for updates ourselves, but there is some burden involved in updating our dependencies internally
due to license/notice file updates, JDK compatibility, and occasional reluctance in the community
to not test with earlier versions).
    Bottom line is for me: the upstream Accumulo project cannot take responsibility for the
dependencies, but we can communicate with our downstream and work to support newer deps as
they are patched in their respective communities.

