anoopamS commented on PR #58128: URL: https://github.com/apache/spark/pull/58128#issuecomment-5423835536
│ Agreed — Spark does not use PackagerResolver, so the practical exploitability is minimal. However, this is a non-breaking minor version bump ( 2.5.3 → 2.6.0), and it removes the CVE flag for downstream users who are required to ship with zero known vulnerabilities in their dependency tree. Happy to add this context to the PR description. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
