Skip to content

[SPARK-41686][SPARK-41030][BUILD][3.3] Upgrade Apache Ivy to 2.5.1 - #39176

Closed
tobiasstadler wants to merge 1 commit into
apache:branch-3.3from
tobiasstadler:SPARK-41686
Closed

[SPARK-41686][SPARK-41030][BUILD][3.3] Upgrade Apache Ivy to 2.5.1#39176
tobiasstadler wants to merge 1 commit into
apache:branch-3.3from
tobiasstadler:SPARK-41686

Conversation

@tobiasstadler

@tobiasstadlertobiasstadler commented Dec 22, 2022

Copy link
Copy Markdown
Contributor

What changes were proposed in this pull request?

Upgrade Apache Ivy from 2.5.0 to 2.5.1

Why are the changes needed?

CVE-2022-37865
and
CVE-2022-37866

Does this PR introduce any user-facing change?

No.

How was this patch tested?

Pass GA

@tobiasstadlertobiasstadler changed the title [SPARK-41686][BUILD] Updated ivy to 2.5.1[SPARK-41686][BUILD] Upgrade Apache Ivy to 2.5.1Dec 22, 2022
@HyukjinKwon

Copy link
Copy Markdown
Member

@tobiasstadler mind creating a PR against master branch? We can backport the change to other branches.

@tobiasstadler

Copy link
Copy Markdown
ContributorAuthor

@HyukjinKwon This is actually a backport of SPARK-41030.

@HyukjinKwonHyukjinKwon changed the title [SPARK-41686][BUILD] Upgrade Apache Ivy to 2.5.1[SPARK-41686][SPARK-41030][BUILD][3.3] Upgrade Apache Ivy to 2.5.1Dec 22, 2022
@HyukjinKwon

Copy link
Copy Markdown
Member

Merged to branch-3.3.

HyukjinKwon pushed a commit that referenced this pull request Dec 22, 2022
### What changes were proposed in this pull request?
Upgrade Apache Ivy from 2.5.0 to 2.5.1
### Why are the changes needed?
[CVE-2022-37865](https://www.cve.org/CVERecord?id=CVE-2022-37865)
and
[CVE-2022-37866](https://nvd.nist.gov/vuln/detail/CVE-2022-37866)
### Does this PR introduce _any_ user-facing change?
No.
### How was this patch tested?
Pass GA
Closes#39176 from tobiasstadler/SPARK-41686.
Authored-by: Tobias Stadler <ts.stadler@gmx.de>
Signed-off-by: Hyukjin Kwon <gurwls223@apache.org>
@tobiasstadler

Copy link
Copy Markdown
ContributorAuthor

Thank you!

@dongjoon-hyundongjoon-hyun left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+1, late LGTM.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tobiasstadler@HyukjinKwon@dongjoon-hyun