Skip to content

Conversation

@debasishbsws
Copy link
Member

@debasishbsws debasishbsws commented Sep 13, 2024

Reason GHSA-rcjc-c4pj-xxrp

Updated the advisory note to explain why Spark-3.5 cannot upgrade Derby from version 10.14.2.0 to 10.17.1.0 due to Java bytecode version incompatibility. The upstream project has updated to version 10.16.1.1, which does not resolve the vulnerability. The fix is planing to fix this in spark-4 or later if there is a backported fix Derby version like 10.16.2.x. For more details, see: apache/spark#44174

…park-3.5

Updated the advisory note to explain why Spark-3.5 cannot upgrade Derby from version 10.14.2.0 to 10.17.1.0 due to Java bytecode version incompatibility. The upstream project has updated to version 10.16.1.1, which does not resolve the vulnerability. The fix is planned with Derby version 10.16.2.x if it gets backported in Spark-4 or later. For more details, see: apache/spark#44174

Signed-off-by: debasishbsws <[email protected]>
…cy on hive 2.3

Spark has a transitive dependency on the unmaintained codehaus jackson-mapper-asl library due to Hive 2.3, which is required for initializing the FunctionRegistry. Hive 3.x, planned for Spark 4.x, should remove this dependency. However, any fix in Spark 4.x cannot be backported to Spark 3.5.x due to its reliance on Hive 2.3.

Signed-off-by: debasishbsws <[email protected]>
@debasishbsws
Copy link
Member Author

Reason for CVE GHSA-c27h-mcmw-48hv

Spark has a transitive dependency on the unmaintained codehaus jackson-mapper-asl library due to Hive 2.3, which is required for initializing the FunctionRegistry. Hive 3.x, planned for Spark 4.x, should remove this dependency. However, any fix in Spark 4.x cannot be backported to Spark 3.5.x due to its reliance on Hive 2.3.

For more details: SPARK-44114, PR #40893, SPARK-30466."

@debasishbsws debasishbsws changed the title Feat(adv): Fix not planed for GHSA-rcjc-c4pj-xxrp Derby component ins… Feat(adv): Fix not planed for GHSA-rcjc-c4pj-xxrp and GHSA-c27h-mcmw-48hv Sep 13, 2024
@cpanato cpanato added this pull request to the merge queue Sep 13, 2024
Merged via the queue into wolfi-dev:main with commit ad423fc Sep 13, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants