Skip to content

Conversation

@felipepessoto
Copy link
Contributor

@felipepessoto felipepessoto commented Mar 30, 2024

Which Delta project/connector is this regarding?

  • Spark
  • Standalone
  • Flink
  • Kernel
  • Other (fill in here)

Description

We haven't updated some dependencies for a while, exposing us to security risks.

This PR updates:

How was this patch tested?

CI

Does this PR introduce any user-facing changes?

No

@felipepessoto
Copy link
Contributor Author

@allisonport-db @scottsand-db, could you please take a look? This kind of PR gets old and conflicting pretty quick

@scottsand-db
Copy link
Collaborator

LGTM! Thanks!

@felipepessoto
Copy link
Contributor Author

@allisonport-db could you help with the merge?

Thanks!

@felipepessoto
Copy link
Contributor Author

@scottsand-db @allisonport-db could we merge this before 3.2?

Signed-off-by: Felipe Pessoto <[email protected]>
Signed-off-by: Felipe Pessoto <[email protected]>
Signed-off-by: Felipe Pessoto <[email protected]>
Signed-off-by: Felipe Pessoto <[email protected]>
@felipepessoto felipepessoto force-pushed the update-dependencies-version branch from 1f56ff4 to 001a310 Compare April 30, 2024 19:20
@felipepessoto
Copy link
Contributor Author

@scottsand-db @allisonport-db I rebased and updated the PR to include a new file spark_master_test.yaml.

@scottsand-db
Copy link
Collaborator

Will merge after it passes tests (except for the 1 failing test in Spark Master)

@scottsand-db scottsand-db merged commit 8eb3bb3 into delta-io:master May 1, 2024
scottsand-db pushed a commit to scottsand-db/delta that referenced this pull request May 1, 2024
)

#### Which Delta project/connector is this regarding?
- [X] Spark
- [X] Standalone
- [X] Flink
- [X] Kernel
- [ ] Other (fill in here)

## Description
We haven't updated some dependencies for a while, exposing us to
security risks.

This PR updates:
- Scala 2.12 to 2.12.18 (the same used by Spark 3.5 branch)
- Scala 2.13 to 2.13.13 (the same in Spark master branch).
[CVE-2022-36944](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-36944)
- Update SBT to 1.9.9.
[CVE-2023-46122](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-46122)
- Update JUnit. Fix delta-io#1518 -
[CVE-2020-15250](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15250)
- Update plugins: sbt-mima-plugin and sbt-scoverage

## How was this patch tested?
CI

## Does this PR introduce _any_ user-facing changes?
No

---------

Signed-off-by: Felipe Pessoto <[email protected]>
scottsand-db pushed a commit to scottsand-db/delta that referenced this pull request May 1, 2024
)

- [X] Spark
- [X] Standalone
- [X] Flink
- [X] Kernel
- [ ] Other (fill in here)

We haven't updated some dependencies for a while, exposing us to
security risks.

This PR updates:
- Scala 2.12 to 2.12.18 (the same used by Spark 3.5 branch)
- Scala 2.13 to 2.13.13 (the same in Spark master branch).
[CVE-2022-36944](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-36944)
- Update SBT to 1.9.9.
[CVE-2023-46122](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-46122)
- Update JUnit. Fix delta-io#1518 -
[CVE-2020-15250](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15250)
- Update plugins: sbt-mima-plugin and sbt-scoverage

CI

No

---------

Signed-off-by: Felipe Pessoto <[email protected]>
allisonport-db added a commit that referenced this pull request May 3, 2024
<!--
Thanks for sending a pull request!  Here are some tips for you:
1. If this is your first time, please read our contributor guidelines:
https://github.com/delta-io/delta/blob/master/CONTRIBUTING.md
2. If the PR is unfinished, add '[WIP]' in your PR title, e.g., '[WIP]
Your PR title ...'.
  3. Be sure to keep the PR description updated to reflect all changes.
  4. Please write your PR title to summarize what this PR proposes.
5. If possible, provide a concise example to reproduce the issue for a
faster review.
6. If applicable, include the corresponding issue number in the PR title
and link it in the body.
-->

#### Which Delta project/connector is this regarding?
<!--
Please add the component selected below to the beginning of the pull
request title
For example: [Spark] Title of my pull request
-->

- [ ] Spark
- [ ] Standalone
- [ ] Flink
- [ ] Kernel
- [X] Other (fill in here)

## Description

#2828 upgrades the SBT version
from 1.5.5 to 1.9.9 which causes `projectName/checkstyle` to fail with
```
sbt:delta> kernelApi/checkstyle
[error] stack trace is suppressed; run last kernelApi / checkstyle for the full output
[error] (kernelApi / checkstyle) org.xml.sax.SAXParseException; lineNumber: 18; columnNumber: 10; DOCTYPE is disallowed when the feature "http://apache.org/xml/features/disallow-doctype-decl" set to true.
[error] Total time: 0 s, completed May 1, 2024 2:59:48 PM
```

This failure was silent in our CI runs for some reason, if you search
the logs before that commit you can see "checkstyle" in them but no
instances after. This is a little concerning but don't really have time
to figure out why this was silent.

For now, upgrades versions to match Spark's current plugins which fixes
the issue. See the matching Spark PR here
apache/spark#38481.

## How was this patch tested?

Ran `kernelApi/checkstyle` locally.
TODO: verify it's present in the CI runs after as well

## Does this PR introduce _any_ user-facing changes?

No.
allisonport-db added a commit to allisonport-db/delta that referenced this pull request May 4, 2024
…#3019)

<!--
Thanks for sending a pull request!  Here are some tips for you:
1. If this is your first time, please read our contributor guidelines:
https://github.com/delta-io/delta/blob/master/CONTRIBUTING.md
2. If the PR is unfinished, add '[WIP]' in your PR title, e.g., '[WIP]
Your PR title ...'.
  3. Be sure to keep the PR description updated to reflect all changes.
  4. Please write your PR title to summarize what this PR proposes.
5. If possible, provide a concise example to reproduce the issue for a
faster review.
6. If applicable, include the corresponding issue number in the PR title
and link it in the body.
-->

#### Which Delta project/connector is this regarding?
<!--
Please add the component selected below to the beginning of the pull
request title
For example: [Spark] Title of my pull request
-->

- [ ] Spark
- [ ] Standalone
- [ ] Flink
- [ ] Kernel
- [X] Other (fill in here)

## Description

delta-io#2828 upgrades the SBT version
from 1.5.5 to 1.9.9 which causes `projectName/checkstyle` to fail with
```
sbt:delta> kernelApi/checkstyle
[error] stack trace is suppressed; run last kernelApi / checkstyle for the full output
[error] (kernelApi / checkstyle) org.xml.sax.SAXParseException; lineNumber: 18; columnNumber: 10; DOCTYPE is disallowed when the feature "http://apache.org/xml/features/disallow-doctype-decl" set to true.
[error] Total time: 0 s, completed May 1, 2024 2:59:48 PM
```

This failure was silent in our CI runs for some reason, if you search
the logs before that commit you can see "checkstyle" in them but no
instances after. This is a little concerning but don't really have time
to figure out why this was silent.

For now, upgrades versions to match Spark's current plugins which fixes
the issue. See the matching Spark PR here
apache/spark#38481.

## How was this patch tested?

Ran `kernelApi/checkstyle` locally.
TODO: verify it's present in the CI runs after as well

## Does this PR introduce _any_ user-facing changes?

No.

(cherry picked from commit 12cabb7)
@felipepessoto felipepessoto deleted the update-dependencies-version branch May 23, 2024 00:22
allisonport-db pushed a commit that referenced this pull request Aug 16, 2024
…#3139)

#### Which Delta project/connector is this regarding?
- [ ] Spark
- [ ] Standalone
- [ ] Flink
- [X] Kernel
- [X] Other (connector, examples, benchmark)

## Description
#2828 updated SBT version to Spark Delta. This is a follow up to update
other projects.
- Update SBT to 1.9.9.
[CVE-2023-46122](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-46122)

## How was this patch tested?
CI

## Does this PR introduce _any_ user-facing changes?
No

---------

Signed-off-by: Felipe Pessoto <[email protected]>
rajeshparangi pushed a commit to rajeshparangi/delta that referenced this pull request Aug 16, 2024
…delta-io#3139)

#### Which Delta project/connector is this regarding?
- [ ] Spark
- [ ] Standalone
- [ ] Flink
- [X] Kernel
- [X] Other (connector, examples, benchmark)

## Description
delta-io#2828 updated SBT version to Spark Delta. This is a follow up to update
other projects.
- Update SBT to 1.9.9.
[CVE-2023-46122](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-46122)

## How was this patch tested?
CI

## Does this PR introduce _any_ user-facing changes?
No

---------

Signed-off-by: Felipe Pessoto <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Dependency vulnerabilities

2 participants