From 99abc94039e3c069d0fc8b8e7025522fea124cbb Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bj=C3=B8rn?= Date: Sat, 15 Oct 2022 17:17:44 +0800 Subject: [PATCH] [SPARK-40801][BUILD] Upgrade `Apache commons-text` to 1.10 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit ### What changes were proposed in this pull request? Upgrade Apache commons-text from 1.9 to 1.10.0 ### Why are the changes needed? [CVE-2022-42889](https://nvd.nist.gov/vuln/detail/CVE-2022-42889) ### Does this PR introduce _any_ user-facing change? No. ### How was this patch tested? Pass github action Closes #38262 from bjornjorgensen/commons-text-1.10. Authored-by: Bjørn Signed-off-by: Yuming Wang --- dev/deps/spark-deps-hadoop-2-hive-2.3 | 2 +- dev/deps/spark-deps-hadoop-3-hive-2.3 | 2 +- pom.xml | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/dev/deps/spark-deps-hadoop-2-hive-2.3 b/dev/deps/spark-deps-hadoop-2-hive-2.3 index 7ba452140a54c..934b5e7e407cc 100644 --- a/dev/deps/spark-deps-hadoop-2-hive-2.3 +++ b/dev/deps/spark-deps-hadoop-2-hive-2.3 @@ -52,7 +52,7 @@ commons-logging/1.1.3//commons-logging-1.1.3.jar commons-math3/3.6.1//commons-math3-3.6.1.jar commons-net/3.1//commons-net-3.1.jar commons-pool/1.5.4//commons-pool-1.5.4.jar -commons-text/1.9//commons-text-1.9.jar +commons-text/1.10.0//commons-text-1.10.0.jar compress-lzf/1.1//compress-lzf-1.1.jar curator-client/2.7.1//curator-client-2.7.1.jar curator-framework/2.7.1//curator-framework-2.7.1.jar diff --git a/dev/deps/spark-deps-hadoop-3-hive-2.3 b/dev/deps/spark-deps-hadoop-3-hive-2.3 index dd89f28212ed0..81452650f0ed5 100644 --- a/dev/deps/spark-deps-hadoop-3-hive-2.3 +++ b/dev/deps/spark-deps-hadoop-3-hive-2.3 @@ -49,7 +49,7 @@ commons-lang3/3.12.0//commons-lang3-3.12.0.jar commons-logging/1.1.3//commons-logging-1.1.3.jar commons-math3/3.6.1//commons-math3-3.6.1.jar commons-pool/1.5.4//commons-pool-1.5.4.jar -commons-text/1.9//commons-text-1.9.jar +commons-text/1.10.0//commons-text-1.10.0.jar compress-lzf/1.1//compress-lzf-1.1.jar curator-client/2.13.0//curator-client-2.13.0.jar curator-framework/2.13.0//curator-framework-2.13.0.jar diff --git a/pom.xml b/pom.xml index 5a8e13cbb3394..0071a6eb2462b 100644 --- a/pom.xml +++ b/pom.xml @@ -604,7 +604,7 @@ org.apache.commons commons-text - 1.9 + 1.10.0 commons-lang