beinan opened a new pull request, #11365:
URL: https://github.com/apache/arrow-rs/pull/11365

   Parquet 58 still depends on Thrift 0.17, which is affected by 
GHSA-2f9f-gq7v-9h6m. Upgrade the legacy Thrift dependency to 0.23 on 
`58_maintenance`, preserving the Arrow/Parquet 58 APIs for downstream readers 
such as Paimon.
   
   Add regressions for compact-protocol Statistics round trips and rejection of 
an oversized binary field before allocation. The existing internal Parquet 
decoder is unchanged.
   
   Validation: `cargo +stable test -p parquet --lib thrift::tests` passes all 
12 matching tests; formatting and `git diff --check` pass.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to