[SERVER-84612] Define a version for immer Created: 05/Jan/24 Updated: 24/Jan/24 Resolved: 23/Jan/24 |
|
| Status: | Closed |
| Project: | Core Server |
| Component/s: | None |
| Affects Version/s: | None |
| Fix Version/s: | 7.3.0-rc0 |
| Type: | Task | Priority: | Major - P3 |
| Reporter: | Spencer Jackson | Assignee: | Dan Larkin-York |
| Resolution: | Fixed | Votes: | 0 |
| Labels: | None | ||
| Remaining Estimate: | Not Specified | ||
| Time Spent: | Not Specified | ||
| Original Estimate: | Not Specified | ||
| Assigned Teams: |
Storage Execution
|
| Backwards Compatibility: | Fully Compatible |
| Sprint: | Execution Team 2024-02-05 |
| Participants: |
| Description |
|
When we vendor third party libraries, we must ensure that they've been sourced from known origins and possess meaningful version identifiers. We use version identifiers to track security vulnerabilities and their mitigations, and libraries without versions cannot be easily audited. As we work toward publishing an SBOM, this information will be made public so that our customers can make informed decisions about supply chain risk. Library immr doesn’t seem to be vendored from a specific release identified by a version identifier issued by its upstream vendor. Please either identify the release which originated the library and update README.third_party.md, update your library to a named release, or migrate to an alternative. If you require an exception, please reach out to stacey.kingpoling@mongodb.com. |
| Comments |
| Comment by Githook User [ 23/Jan/24 ] |
|
Author: {'name': 'Dan Larkin-York', 'email': '13419935+dhly-etc@users.noreply.github.com', 'username': 'dhly-etc'}Message: GitOrigin-RevId: a67458238e861c443fa0c8ee3ee301574aa61a62 |
| Comment by Steven Vannelli [ 23/Jan/24 ] |
|
Triage notes: We should be able to use the upstream hash that we forked off of. |