Skip to content

Conversation

@bjornjorgensen
Copy link
Contributor

What changes were proposed in this pull request?

Upgrade Protobuf from 3.19.4 to 3.19.5

Why are the changes needed?

CVE-2022-1941

Does this PR introduce any user-facing change?

No.

How was this patch tested?

Pass GA

@bjornjorgensen bjornjorgensen changed the title [SPARK-XXXX][CONNECT] Upgrade Protobuf to 3.19.5 [SPARK-XXXX][CONNECT][BUILD][INFRA] Upgrade Protobuf to 3.19.5 Nov 23, 2022
@bjornjorgensen bjornjorgensen changed the title [SPARK-XXXX][CONNECT][BUILD][INFRA] Upgrade Protobuf to 3.19.5 [SPARK-41240][CONNECT][BUILD][INFRA] Upgrade Protobuf to 3.19.5 Nov 23, 2022
@zhengruifeng
Copy link
Contributor

@grundprinzip
Copy link
Contributor

There is currently no updated version on the buf schema registry. Given that this runs remotely, I think we're good for now. Mayber we can leave a comment with a todo JIRA?

@grundprinzip
Copy link
Contributor

@bjornjorgensen bjornjorgensen changed the title [SPARK-41240][CONNECT][BUILD][INFRA] Upgrade Protobuf to 3.19.5 [SPARK-41240][CONNECT][BUILD][INFRA][DOCS] Upgrade Protobuf to 3.19.5 Nov 24, 2022
@zhengruifeng
Copy link
Contributor

create https://issues.apache.org/jira/browse/SPARK-41265 to track buf.build/protocolbuffers/plugins/python

@zhengruifeng
Copy link
Contributor

merged into master

@AmplabJenkins
Copy link

Can one of the admins verify this patch?

@amaliujia
Copy link
Contributor

Question:

Should we keep the protobuf version in sync between the server and client? The server side now is using:
<protobuf.version>3.21.9</protobuf.version>?

@amaliujia
Copy link
Contributor

Just found an effort to unify the protobuf version which impacted connect server: #38783

beliefer pushed a commit to beliefer/spark that referenced this pull request Dec 15, 2022
### What changes were proposed in this pull request?
Upgrade Protobuf from 3.19.4 to 3.19.5

### Why are the changes needed?
[CVE-2022-1941](https://nvd.nist.gov/vuln/detail/CVE-2022-1941)

### Does this PR introduce _any_ user-facing change?
No.

### How was this patch tested?
Pass GA

Closes apache#38774 from bjornjorgensen/protobuf-3.19.5.

Lead-authored-by: Bjørn Jørgensen <[email protected]>
Co-authored-by: Bjorn Jorgensen <[email protected]>
Co-authored-by: Bjørn <[email protected]>
Signed-off-by: Ruifeng Zheng <[email protected]>
beliefer pushed a commit to beliefer/spark that referenced this pull request Dec 18, 2022
### What changes were proposed in this pull request?
Upgrade Protobuf from 3.19.4 to 3.19.5

### Why are the changes needed?
[CVE-2022-1941](https://nvd.nist.gov/vuln/detail/CVE-2022-1941)

### Does this PR introduce _any_ user-facing change?
No.

### How was this patch tested?
Pass GA

Closes apache#38774 from bjornjorgensen/protobuf-3.19.5.

Lead-authored-by: Bjørn Jørgensen <[email protected]>
Co-authored-by: Bjorn Jorgensen <[email protected]>
Co-authored-by: Bjørn <[email protected]>
Signed-off-by: Ruifeng Zheng <[email protected]>
@bjornjorgensen bjornjorgensen deleted the protobuf-3.19.5 branch December 21, 2022 14:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants