-
Notifications
You must be signed in to change notification settings - Fork 4.5k
Fix parquet-avro vulnerability in io expansion service #34860
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
Assigning reviewers. If you would like to opt out of this review, comment R: @ahmedabu98 for label java. Available commands:
The PR bot will only process comments in the main thread (not review comments). |
|
Reminder, please take a look at this pr: @ahmedabu98 |
|
Assigning new set of reviewers because Pr has gone too long without review. If you would like to opt out of this review, comment R: @robertwb for label java. Available commands:
|
| resolutionStrategy.force 'org.apache.kafka:kafka-clients:3.9.0' | ||
|
|
||
| // Pin org.apache.parquet:parquet-avro to a non-vulnerable version compatible. | ||
| resolutionStrategy.force 'org.apache.parquet:parquet-avro:1.15.1' |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Do you know which dependenc(y|ies) currently cause parquet-avro to be installed? I'm in favor of the change, but it would be good for us to know this so that we can respond once the dependency is fixed. Once we figure out that dependency FOO is causing the lower version of parquet-avro to be installed, we should add a couple comments:
- A comment here mentioning that this can be removed once that dependency is upgraded and
./gradlew :sdks:java:io:expansion-service:dependencies --configuration runtimeClasspath | grep parquet-avroshows no entries - A comment next to dependency
FOOmentioning that this should be removed once that is upgraded to a version with a higher parquet-avro dependency.
Both should link to a tracking issue with context (e.g. like b287985 does)
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks. Its covered now by another PR - #35037
Fixes CVE-2025-30065
./gradlew :sdks:java:io:expansion-service:dependencies --configuration runtimeClasspath | grep parquet-avro

Thank you for your contribution! Follow this checklist to help us incorporate your contribution quickly and easily:
addresses #123), if applicable. This will automatically add a link to the pull request in the issue. If you would like the issue to automatically close on merging the pull request, commentfixes #<ISSUE NUMBER>instead.CHANGES.mdwith noteworthy changes.See the Contributor Guide for more tips on how to make review process smoother.
To check the build health, please visit https://github.com/apache/beam/blob/master/.test-infra/BUILD_STATUS.md
GitHub Actions Tests Status (on master branch)
See CI.md for more information about GitHub Actions CI or the workflows README to see a list of phrases to trigger workflows.