LuciferYang commented on PR #58128:
URL: https://github.com/apache/spark/pull/58128#issuecomment-5365275860

   > ### Why are the changes needed?
   > 
   > Fixes CVE-2026-26032 (MEDIUM 5.4): Security vulnerability in Ivy 
dependency resolution.
   
   
   @anoopamS If this upgrade is motivated by the advisory, could you add to the 
PR description the practical impact of 
[[https://github.com/advisories/GHSA-j482](https://link.wtturl.cn/?target=https%3A%2F%2Fgithub.com%2Fadvisories%2FGHSA-j482&scene=im&aid=582478&lang=zh)](https://link.wtturl.cn/?target=https%3A%2F%2Fgithub.com%2Fadvisories%2FGHSA-j482&scene=im&aid=582478&lang=zh)‑hm6j‑v5jj
 on Apache Spark? From what I can tell, GHSA‑j482‑hm6j‑v5jj is very unlikely to 
affect Spark.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to