LuciferYang commented on PR #58128: URL: https://github.com/apache/spark/pull/58128#issuecomment-5365275860
> ### Why are the changes needed? > > Fixes CVE-2026-26032 (MEDIUM 5.4): Security vulnerability in Ivy dependency resolution. @anoopamS If this upgrade is motivated by the advisory, could you add to the PR description the practical impact of [[https://github.com/advisories/GHSA-j482](https://link.wtturl.cn/?target=https%3A%2F%2Fgithub.com%2Fadvisories%2FGHSA-j482&scene=im&aid=582478&lang=zh)](https://link.wtturl.cn/?target=https%3A%2F%2Fgithub.com%2Fadvisories%2FGHSA-j482&scene=im&aid=582478&lang=zh)‑hm6j‑v5jj on Apache Spark? From what I can tell, GHSA‑j482‑hm6j‑v5jj is very unlikely to affect Spark. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
