This is an automated email from the ASF dual-hosted git repository. srowen pushed a commit to branch branch-3.5 in repository https://gitbox.apache.org/repos/asf/spark.git
The following commit(s) were added to refs/heads/branch-3.5 by this push: new 7b68ccd1cb4 [SPARK-44604][BUILD] Upgrade Netty to 4.1.96.Final 7b68ccd1cb4 is described below commit 7b68ccd1cb48c38052b0458c5192d5ffcfc97409 Author: panbingkun <pbk1...@gmail.com> AuthorDate: Tue Aug 1 08:55:27 2023 -0500 [SPARK-44604][BUILD] Upgrade Netty to 4.1.96.Final ### What changes were proposed in this pull request? The pr aims to upgrade Netty from 4.1.93.Final to 4.1.96.Final. ### Why are the changes needed? 1.Netty 4.1.93.Final VS 4.1.96.Final https://github.com/netty/netty/compare/netty-4.1.93.Final...netty-4.1.96.Final 2.Netty newest version Fix a possible security issue: ([CVE-2023-34462](https://github.com/netty/netty/security/advisories/GHSA-6mjq-h674-j845)) when using SniHandler. 3.Netty full release notes: https://netty.io/news/2023/07/27/4-1-96-Final.html https://netty.io/news/2023/07/20/4-1-95-Final.html https://netty.io/news/2023/06/19/4-1-94-Final.html ### Does this PR introduce _any_ user-facing change? No. ### How was this patch tested? Pass GA. Closes #42232 from panbingkun/SPARK-44604. Authored-by: panbingkun <pbk1...@gmail.com> Signed-off-by: Sean Owen <sro...@gmail.com> (cherry picked from commit 8053d5f16541edb8e17cbc50684abae69187ff5a) Signed-off-by: Sean Owen <sro...@gmail.com> --- dev/deps/spark-deps-hadoop-3-hive-2.3 | 36 +++++++++++++++++------------------ pom.xml | 6 +----- 2 files changed, 19 insertions(+), 23 deletions(-) diff --git a/dev/deps/spark-deps-hadoop-3-hive-2.3 b/dev/deps/spark-deps-hadoop-3-hive-2.3 index beae2232202..566f7c9a3ea 100644 --- a/dev/deps/spark-deps-hadoop-3-hive-2.3 +++ b/dev/deps/spark-deps-hadoop-3-hive-2.3 @@ -183,24 +183,24 @@ metrics-jmx/4.2.19//metrics-jmx-4.2.19.jar metrics-json/4.2.19//metrics-json-4.2.19.jar metrics-jvm/4.2.19//metrics-jvm-4.2.19.jar minlog/1.3.0//minlog-1.3.0.jar -netty-all/4.1.93.Final//netty-all-4.1.93.Final.jar -netty-buffer/4.1.93.Final//netty-buffer-4.1.93.Final.jar -netty-codec-http/4.1.93.Final//netty-codec-http-4.1.93.Final.jar -netty-codec-http2/4.1.93.Final//netty-codec-http2-4.1.93.Final.jar -netty-codec-socks/4.1.93.Final//netty-codec-socks-4.1.93.Final.jar -netty-codec/4.1.93.Final//netty-codec-4.1.93.Final.jar -netty-common/4.1.93.Final//netty-common-4.1.93.Final.jar -netty-handler-proxy/4.1.93.Final//netty-handler-proxy-4.1.93.Final.jar -netty-handler/4.1.93.Final//netty-handler-4.1.93.Final.jar -netty-resolver/4.1.93.Final//netty-resolver-4.1.93.Final.jar -netty-transport-classes-epoll/4.1.93.Final//netty-transport-classes-epoll-4.1.93.Final.jar -netty-transport-classes-kqueue/4.1.93.Final//netty-transport-classes-kqueue-4.1.93.Final.jar -netty-transport-native-epoll/4.1.93.Final/linux-aarch_64/netty-transport-native-epoll-4.1.93.Final-linux-aarch_64.jar -netty-transport-native-epoll/4.1.93.Final/linux-x86_64/netty-transport-native-epoll-4.1.93.Final-linux-x86_64.jar -netty-transport-native-kqueue/4.1.93.Final/osx-aarch_64/netty-transport-native-kqueue-4.1.93.Final-osx-aarch_64.jar -netty-transport-native-kqueue/4.1.93.Final/osx-x86_64/netty-transport-native-kqueue-4.1.93.Final-osx-x86_64.jar -netty-transport-native-unix-common/4.1.93.Final//netty-transport-native-unix-common-4.1.93.Final.jar -netty-transport/4.1.93.Final//netty-transport-4.1.93.Final.jar +netty-all/4.1.96.Final//netty-all-4.1.96.Final.jar +netty-buffer/4.1.96.Final//netty-buffer-4.1.96.Final.jar +netty-codec-http/4.1.96.Final//netty-codec-http-4.1.96.Final.jar +netty-codec-http2/4.1.96.Final//netty-codec-http2-4.1.96.Final.jar +netty-codec-socks/4.1.96.Final//netty-codec-socks-4.1.96.Final.jar +netty-codec/4.1.96.Final//netty-codec-4.1.96.Final.jar +netty-common/4.1.96.Final//netty-common-4.1.96.Final.jar +netty-handler-proxy/4.1.96.Final//netty-handler-proxy-4.1.96.Final.jar +netty-handler/4.1.96.Final//netty-handler-4.1.96.Final.jar +netty-resolver/4.1.96.Final//netty-resolver-4.1.96.Final.jar +netty-transport-classes-epoll/4.1.96.Final//netty-transport-classes-epoll-4.1.96.Final.jar +netty-transport-classes-kqueue/4.1.96.Final//netty-transport-classes-kqueue-4.1.96.Final.jar +netty-transport-native-epoll/4.1.96.Final/linux-aarch_64/netty-transport-native-epoll-4.1.96.Final-linux-aarch_64.jar +netty-transport-native-epoll/4.1.96.Final/linux-x86_64/netty-transport-native-epoll-4.1.96.Final-linux-x86_64.jar +netty-transport-native-kqueue/4.1.96.Final/osx-aarch_64/netty-transport-native-kqueue-4.1.96.Final-osx-aarch_64.jar +netty-transport-native-kqueue/4.1.96.Final/osx-x86_64/netty-transport-native-kqueue-4.1.96.Final-osx-x86_64.jar +netty-transport-native-unix-common/4.1.96.Final//netty-transport-native-unix-common-4.1.96.Final.jar +netty-transport/4.1.96.Final//netty-transport-4.1.96.Final.jar objenesis/3.3//objenesis-3.3.jar okhttp/3.12.12//okhttp-3.12.12.jar okio/1.15.0//okio-1.15.0.jar diff --git a/pom.xml b/pom.xml index 6ced5c7cab7..ffb9c6046e0 100644 --- a/pom.xml +++ b/pom.xml @@ -216,11 +216,7 @@ <commons-cli.version>1.5.0</commons-cli.version> <bouncycastle.version>1.70</bouncycastle.version> <tink.version>1.9.0</tink.version> - <!-- - Please don't upgrade the version to 4.1.94.Final, - it needs to wait for `arrow-memory-netty` to be greater than 12.0.1. - --> - <netty.version>4.1.93.Final</netty.version> + <netty.version>4.1.96.Final</netty.version> <!-- If you are changing Arrow version specification, please check ./python/pyspark/sql/pandas/utils.py, and ./python/setup.py too. --------------------------------------------------------------------- To unsubscribe, e-mail: commits-unsubscr...@spark.apache.org For additional commands, e-mail: commits-h...@spark.apache.org