-
Notifications
You must be signed in to change notification settings - Fork 5.5k
chore(deps): Upgrade org.apache.thrift:libthrift versio to 0.18.1 #26398
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
|
|
9c27906 to
baccadf
Compare
|
@ZacBlanco / @hantangwangd could you please review this PR. |
agrawalreetika
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I see even the version we are upgrading to has CVEs - https://mvnrepository.com/artifact/org.apache.thrift/libthrift/0.22.0
I think we could upgrade to CVE free version instead - https://mvnrepository.com/artifact/org.apache.thrift/libthrift/0.18.1
baccadf to
f6bead7
Compare
f6bead7 to
b7fafee
Compare
agrawalreetika
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Mostly lgtm. I have one question: why do we need to change the scope from test in all the places?
b7fafee to
4f2c110
Compare
Thanks for the comment. When I upgraded to version 0.22.0, Getting a ‘Test dependency scope issues found’ error. After changing the version to 0.18.1, the error disappeared, so I reverted the changes. |
Description
Upgrade org.apache.thrift:libthrift versio to 0.18.1
Motivation and Context
Using a more recent version helps avoid potential vulnerabilities and ensures we aren't relying on outdated or unsupported code.
Impact
Test Plan
Contributor checklist
Release Notes
Please follow release notes guidelines and fill in the release notes below.