Skip to content

Conversation

@jamie-albert
Copy link
Member

1. GHSA-p953-3j66-hg45

  • pending-upstream-fix: The version of hive-llap-common is not able to be upgraded from 2.3.9 to 4.0.0 due to version incompatibility with the parent dependency Hive, Spark-3.5 is only able to support Hive 2.3.9. To remediate this CVE would require Hive 4.0.0 which needs to be implemented by upstream maintainers. Upstream is targeting to remove this as part of the Spark-4.0.0 release as seen here: [SPARK-51029][BUILD] Remove hive-llap-common compile dependency apache/spark#49725

@powersj powersj added this pull request to the merge queue Jan 30, 2025
Merged via the queue into wolfi-dev:main with commit 6f6f0a5 Jan 30, 2025
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants