Skip to content

Conversation

@pan3793
Copy link
Member

@pan3793 pan3793 commented Jun 15, 2023

What changes were proposed in this pull request?

Bump snappy-java from 1.1.10.0 to 1.1.10.1.

Why are the changes needed?

This mostly is a security version, the notable changes are CVE fixing.

Full changelog: https://github.com/xerial/snappy-java/releases/tag/v1.1.10.1

Does this PR introduce any user-facing change?

No.

How was this patch tested?

Pass GA.

@github-actions github-actions bot added the BUILD label Jun 15, 2023
Copy link
Member

@dongjoon-hyun dongjoon-hyun left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+1, LGTM (Pending CIs). Thank you always, @pan3793 .

@dongjoon-hyun
Copy link
Member

Could you re-trigger the failed pipeline, please, @pan3793 ?

@LuciferYang LuciferYang changed the title [SPARK-44070][BUILD] Bump snappy-jave 1.1.10.1 [SPARK-44070][BUILD] Bump snappy-java 1.1.10.1 Jun 16, 2023
@wangyum wangyum closed this in 0502a42 Jun 16, 2023
@wangyum
Copy link
Member

wangyum commented Jun 16, 2023

Merged to master and branch-3.4.

wangyum added a commit that referenced this pull request Jun 16, 2023
### What changes were proposed in this pull request?

Bump snappy-java from 1.1.10.0 to 1.1.10.1.

### Why are the changes needed?

This mostly is a security version, the notable changes are CVE fixing.

- CVE-2023-34453 Integer overflow in shuffle
- CVE-2023-34454 Integer overflow in compress
- CVE-2023-34455 Unchecked chunk length

Full changelog: https://github.com/xerial/snappy-java/releases/tag/v1.1.10.1

### Does this PR introduce _any_ user-facing change?

No.

### How was this patch tested?

Pass GA.

Closes #41616 from pan3793/SPARK-44070.

Authored-by: Cheng Pan <[email protected]>
Signed-off-by: Yuming Wang <[email protected]>
(cherry picked from commit 0502a42)
Signed-off-by: Yuming Wang <[email protected]>
@dongjoon-hyun
Copy link
Member

Thank you all!

@dongjoon-hyun
Copy link
Member

It seems that branch-3.4 is broken due to some other issue.

@wangyum
Copy link
Member

wangyum commented Jun 17, 2023

It seems that branch-3.4 is broken due to some other issue.

It is back to normal.

czxm pushed a commit to czxm/spark that referenced this pull request Jun 19, 2023
### What changes were proposed in this pull request?

Bump snappy-java from 1.1.10.0 to 1.1.10.1.

### Why are the changes needed?

This mostly is a security version, the notable changes are CVE fixing.

- CVE-2023-34453 Integer overflow in shuffle
- CVE-2023-34454 Integer overflow in compress
- CVE-2023-34455 Unchecked chunk length

Full changelog: https://github.com/xerial/snappy-java/releases/tag/v1.1.10.1

### Does this PR introduce _any_ user-facing change?

No.

### How was this patch tested?

Pass GA.

Closes apache#41616 from pan3793/SPARK-44070.

Authored-by: Cheng Pan <[email protected]>
Signed-off-by: Yuming Wang <[email protected]>
snmvaughan pushed a commit to snmvaughan/spark that referenced this pull request Jun 20, 2023
### What changes were proposed in this pull request?

Bump snappy-java from 1.1.10.0 to 1.1.10.1.

### Why are the changes needed?

This mostly is a security version, the notable changes are CVE fixing.

- CVE-2023-34453 Integer overflow in shuffle
- CVE-2023-34454 Integer overflow in compress
- CVE-2023-34455 Unchecked chunk length

Full changelog: https://github.com/xerial/snappy-java/releases/tag/v1.1.10.1

### Does this PR introduce _any_ user-facing change?

No.

### How was this patch tested?

Pass GA.

Closes apache#41616 from pan3793/SPARK-44070.

Authored-by: Cheng Pan <[email protected]>
Signed-off-by: Yuming Wang <[email protected]>
(cherry picked from commit 0502a42)
Signed-off-by: Yuming Wang <[email protected]>
GladwinLee pushed a commit to lyft/spark that referenced this pull request Oct 10, 2023
### What changes were proposed in this pull request?

Bump snappy-java from 1.1.10.0 to 1.1.10.1.

### Why are the changes needed?

This mostly is a security version, the notable changes are CVE fixing.

- CVE-2023-34453 Integer overflow in shuffle
- CVE-2023-34454 Integer overflow in compress
- CVE-2023-34455 Unchecked chunk length

Full changelog: https://github.com/xerial/snappy-java/releases/tag/v1.1.10.1

### Does this PR introduce _any_ user-facing change?

No.

### How was this patch tested?

Pass GA.

Closes apache#41616 from pan3793/SPARK-44070.

Authored-by: Cheng Pan <[email protected]>
Signed-off-by: Yuming Wang <[email protected]>
(cherry picked from commit 0502a42)
Signed-off-by: Yuming Wang <[email protected]>
catalinii pushed a commit to lyft/spark that referenced this pull request Oct 10, 2023
### What changes were proposed in this pull request?

Bump snappy-java from 1.1.10.0 to 1.1.10.1.

### Why are the changes needed?

This mostly is a security version, the notable changes are CVE fixing.

- CVE-2023-34453 Integer overflow in shuffle
- CVE-2023-34454 Integer overflow in compress
- CVE-2023-34455 Unchecked chunk length

Full changelog: https://github.com/xerial/snappy-java/releases/tag/v1.1.10.1

### Does this PR introduce _any_ user-facing change?

No.

### How was this patch tested?

Pass GA.

Closes apache#41616 from pan3793/SPARK-44070.

Authored-by: Cheng Pan <[email protected]>
Signed-off-by: Yuming Wang <[email protected]>
(cherry picked from commit 0502a42)
Signed-off-by: Yuming Wang <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants