Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Infra] [Security] Update Scala and packages dependencies #2828

Merged

Conversation

felipepessoto
Copy link
Contributor

@felipepessoto felipepessoto commented Mar 30, 2024

Which Delta project/connector is this regarding?

  • Spark
  • Standalone
  • Flink
  • Kernel
  • Other (fill in here)

Description

We haven't updated some dependencies for a while, exposing us to security risks.

This PR updates:

How was this patch tested?

CI

Does this PR introduce any user-facing changes?

No

@felipepessoto
Copy link
Contributor Author

@allisonport-db @scottsand-db, could you please take a look? This kind of PR gets old and conflicting pretty quick

@scottsand-db
Copy link
Collaborator

LGTM! Thanks!

@felipepessoto
Copy link
Contributor Author

@allisonport-db could you help with the merge?

Thanks!

@felipepessoto
Copy link
Contributor Author

@scottsand-db @allisonport-db could we merge this before 3.2?

Signed-off-by: Felipe Pessoto <fepessot@microsoft.com>
Signed-off-by: Felipe Pessoto <fepessot@microsoft.com>
Signed-off-by: Felipe Pessoto <fepessot@microsoft.com>
Signed-off-by: Felipe Pessoto <fepessot@microsoft.com>
@felipepessoto felipepessoto force-pushed the update-dependencies-version branch from 1f56ff4 to 001a310 Compare April 30, 2024 19:20
Signed-off-by: Felipe Pessoto <fepessot@microsoft.com>
@felipepessoto
Copy link
Contributor Author

@scottsand-db @allisonport-db I rebased and updated the PR to include a new file spark_master_test.yaml.

@scottsand-db
Copy link
Collaborator

Will merge after it passes tests (except for the 1 failing test in Spark Master)

@scottsand-db scottsand-db merged commit 8eb3bb3 into delta-io:master May 1, 2024
7 of 8 checks passed
scottsand-db pushed a commit to scottsand-db/delta that referenced this pull request May 1, 2024
)

#### Which Delta project/connector is this regarding?
- [X] Spark
- [X] Standalone
- [X] Flink
- [X] Kernel
- [ ] Other (fill in here)

## Description
We haven't updated some dependencies for a while, exposing us to
security risks.

This PR updates:
- Scala 2.12 to 2.12.18 (the same used by Spark 3.5 branch)
- Scala 2.13 to 2.13.13 (the same in Spark master branch).
[CVE-2022-36944](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-36944)
- Update SBT to 1.9.9.
[CVE-2023-46122](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-46122)
- Update JUnit. Fix delta-io#1518 -
[CVE-2020-15250](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15250)
- Update plugins: sbt-mima-plugin and sbt-scoverage

## How was this patch tested?
CI

## Does this PR introduce _any_ user-facing changes?
No

---------

Signed-off-by: Felipe Pessoto <fepessot@microsoft.com>
scottsand-db pushed a commit to scottsand-db/delta that referenced this pull request May 1, 2024
)

- [X] Spark
- [X] Standalone
- [X] Flink
- [X] Kernel
- [ ] Other (fill in here)

We haven't updated some dependencies for a while, exposing us to
security risks.

This PR updates:
- Scala 2.12 to 2.12.18 (the same used by Spark 3.5 branch)
- Scala 2.13 to 2.13.13 (the same in Spark master branch).
[CVE-2022-36944](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-36944)
- Update SBT to 1.9.9.
[CVE-2023-46122](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-46122)
- Update JUnit. Fix delta-io#1518 -
[CVE-2020-15250](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15250)
- Update plugins: sbt-mima-plugin and sbt-scoverage

CI

No

---------

Signed-off-by: Felipe Pessoto <fepessot@microsoft.com>
allisonport-db added a commit that referenced this pull request May 3, 2024
<!--
Thanks for sending a pull request!  Here are some tips for you:
1. If this is your first time, please read our contributor guidelines:
https://github.com/delta-io/delta/blob/master/CONTRIBUTING.md
2. If the PR is unfinished, add '[WIP]' in your PR title, e.g., '[WIP]
Your PR title ...'.
  3. Be sure to keep the PR description updated to reflect all changes.
  4. Please write your PR title to summarize what this PR proposes.
5. If possible, provide a concise example to reproduce the issue for a
faster review.
6. If applicable, include the corresponding issue number in the PR title
and link it in the body.
-->

#### Which Delta project/connector is this regarding?
<!--
Please add the component selected below to the beginning of the pull
request title
For example: [Spark] Title of my pull request
-->

- [ ] Spark
- [ ] Standalone
- [ ] Flink
- [ ] Kernel
- [X] Other (fill in here)

## Description

#2828 upgrades the SBT version
from 1.5.5 to 1.9.9 which causes `projectName/checkstyle` to fail with
```
sbt:delta> kernelApi/checkstyle
[error] stack trace is suppressed; run last kernelApi / checkstyle for the full output
[error] (kernelApi / checkstyle) org.xml.sax.SAXParseException; lineNumber: 18; columnNumber: 10; DOCTYPE is disallowed when the feature "http://apache.org/xml/features/disallow-doctype-decl" set to true.
[error] Total time: 0 s, completed May 1, 2024 2:59:48 PM
```

This failure was silent in our CI runs for some reason, if you search
the logs before that commit you can see "checkstyle" in them but no
instances after. This is a little concerning but don't really have time
to figure out why this was silent.

For now, upgrades versions to match Spark's current plugins which fixes
the issue. See the matching Spark PR here
apache/spark#38481.

## How was this patch tested?

Ran `kernelApi/checkstyle` locally.
TODO: verify it's present in the CI runs after as well

## Does this PR introduce _any_ user-facing changes?

No.
allisonport-db added a commit to allisonport-db/delta that referenced this pull request May 4, 2024
…#3019)

<!--
Thanks for sending a pull request!  Here are some tips for you:
1. If this is your first time, please read our contributor guidelines:
https://github.com/delta-io/delta/blob/master/CONTRIBUTING.md
2. If the PR is unfinished, add '[WIP]' in your PR title, e.g., '[WIP]
Your PR title ...'.
  3. Be sure to keep the PR description updated to reflect all changes.
  4. Please write your PR title to summarize what this PR proposes.
5. If possible, provide a concise example to reproduce the issue for a
faster review.
6. If applicable, include the corresponding issue number in the PR title
and link it in the body.
-->

#### Which Delta project/connector is this regarding?
<!--
Please add the component selected below to the beginning of the pull
request title
For example: [Spark] Title of my pull request
-->

- [ ] Spark
- [ ] Standalone
- [ ] Flink
- [ ] Kernel
- [X] Other (fill in here)

## Description

delta-io#2828 upgrades the SBT version
from 1.5.5 to 1.9.9 which causes `projectName/checkstyle` to fail with
```
sbt:delta> kernelApi/checkstyle
[error] stack trace is suppressed; run last kernelApi / checkstyle for the full output
[error] (kernelApi / checkstyle) org.xml.sax.SAXParseException; lineNumber: 18; columnNumber: 10; DOCTYPE is disallowed when the feature "http://apache.org/xml/features/disallow-doctype-decl" set to true.
[error] Total time: 0 s, completed May 1, 2024 2:59:48 PM
```

This failure was silent in our CI runs for some reason, if you search
the logs before that commit you can see "checkstyle" in them but no
instances after. This is a little concerning but don't really have time
to figure out why this was silent.

For now, upgrades versions to match Spark's current plugins which fixes
the issue. See the matching Spark PR here
apache/spark#38481.

## How was this patch tested?

Ran `kernelApi/checkstyle` locally.
TODO: verify it's present in the CI runs after as well

## Does this PR introduce _any_ user-facing changes?

No.

(cherry picked from commit 12cabb7)
@felipepessoto felipepessoto deleted the update-dependencies-version branch May 23, 2024 00:22
allisonport-db pushed a commit that referenced this pull request Aug 16, 2024
…#3139)

#### Which Delta project/connector is this regarding?
- [ ] Spark
- [ ] Standalone
- [ ] Flink
- [X] Kernel
- [X] Other (connector, examples, benchmark)

## Description
#2828 updated SBT version to Spark Delta. This is a follow up to update
other projects.
- Update SBT to 1.9.9.
[CVE-2023-46122](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-46122)

## How was this patch tested?
CI

## Does this PR introduce _any_ user-facing changes?
No

---------

Signed-off-by: Felipe Pessoto <fepessot@microsoft.com>
rajeshparangi pushed a commit to rajeshparangi/delta that referenced this pull request Aug 16, 2024
…delta-io#3139)

#### Which Delta project/connector is this regarding?
- [ ] Spark
- [ ] Standalone
- [ ] Flink
- [X] Kernel
- [X] Other (connector, examples, benchmark)

## Description
delta-io#2828 updated SBT version to Spark Delta. This is a follow up to update
other projects.
- Update SBT to 1.9.9.
[CVE-2023-46122](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-46122)

## How was this patch tested?
CI

## Does this PR introduce _any_ user-facing changes?
No

---------

Signed-off-by: Felipe Pessoto <fepessot@microsoft.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Dependency vulnerabilities
2 participants