Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

bump: bump avro to 1.13.1 (was 1.8.2) #3039

Merged
merged 7 commits into from
Nov 23, 2023
Merged

bump: bump avro to 1.13.1 (was 1.8.2) #3039

merged 7 commits into from
Nov 23, 2023

Conversation

sebastian-alfers
Copy link
Contributor

@sebastian-alfers sebastian-alfers commented Nov 22, 2023

Explicitly bumps Avro to 1.13.1 which brings smaller API changes.

Fixes CVE-2023-39410.

@probot-autolabeler probot-autolabeler bot added the dependency-change For PRs changing the version of a dependency. label Nov 22, 2023
@ennru
Copy link
Member

ennru commented Nov 22, 2023

Some API got deprecated in that version
https://github.com/akka/alpakka/actions/runs/6958865333/job/18934801907?pr=3039#step:6:156

@sebastian-alfers
Copy link
Contributor Author

Would be good if reproducing this locally by default.

Copy link
Member

@ennru ennru left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

@ennru ennru changed the title bump: bump avro to 1.13.1 bump: bump avro to 1.13.1 (was 1.8.2) Nov 23, 2023
@ennru ennru merged commit 93a3bd0 into main Nov 23, 2023
46 of 49 checks passed
@ennru ennru deleted the bump-avro branch November 23, 2023 08:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependency-change For PRs changing the version of a dependency. p:avroparquet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants