beinan opened a new pull request, #11365: URL: https://github.com/apache/arrow-rs/pull/11365
Parquet 58 still depends on Thrift 0.17, which is affected by GHSA-2f9f-gq7v-9h6m. Upgrade the legacy Thrift dependency to 0.23 on `58_maintenance`, preserving the Arrow/Parquet 58 APIs for downstream readers such as Paimon. Add regressions for compact-protocol Statistics round trips and rejection of an oversized binary field before allocation. The existing internal Parquet decoder is unchanged. Validation: `cargo +stable test -p parquet --lib thrift::tests` passes all 12 matching tests; formatting and `git diff --check` pass. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
