Hi, New releases are announced via mailing lists user@spark.apache.org<mailto:user@spark.apache.org> & d...@spark.apache.org<mailto:d...@spark.apache.org>.
Best, Meikel From: Theodore J Griesenbrock <t...@ibm.com> Sent: Mittwoch, 19. Januar 2022 18:50 To: sro...@gmail.com Cc: Juan Liu <liuj...@cn.ibm.com>; user@spark.apache.org Subject: RE: Does Spark 3.1.2/3.2 support log4j 2.17.1+, and how? your target release day for Spark3.3? Sie erhalten nicht oft E-Mail von "t...@ibm.com<mailto:t...@ibm.com>". Weitere Informationen, warum dies wichtig ist<http://aka.ms/LearnAboutSenderIdentification> Again, sorry to bother you. What is the best option available to ensure we get notified when a new version is released for Apache Spark? I do not see any RSS feeds, nor do I see any e-mail subscription option for this page: https://spark.apache.org/news/index.html<https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fspark.apache.org%2Fnews%2Findex.html&data=04%7C01%7CMeikel.Bode%40bertelsmann.de%7C50197a78ba4b4bef3ca108d9db77e438%7C1ca8bd943c974fc68955bad266b43f0b%7C0%7C0%7C637782130240616190%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=%2BtL780hmjJoLAFTiNjQc%2FB7QtPU2u1dyW%2B1LhkXWL7o%3D&reserved=0> Please let me know what we can do to ensure we stay up to date with the news. Thanks! -T.J. T.J. Griesenbrock Technical Release Manager Watson Health He/Him/His +1 (602) 377-7673 (Text only) t...@ibm.com<mailto:t...@ibm.com> IBM ----- Original message ----- From: "Sean Owen" <sro...@gmail.com<mailto:sro...@gmail.com>> To: "Juan Liu" <liuj...@cn.ibm.com<mailto:liuj...@cn.ibm.com>> Cc: "Theodore J Griesenbrock" <t...@ibm.com<mailto:t...@ibm.com>>, "User" <user@spark.apache.org<mailto:user@spark.apache.org>> Subject: [EXTERNAL] Re: Does Spark 3.1.2/3.2 support log4j 2.17.1+, and how? your target release day for Spark3.3? Date: Thu, Jan 13, 2022 08:05 Yes, Spark does not use the SocketServer mentioned in CVE-2019-17571, however, so is not affected. 3.3.0 would probably be out in a couple months. On Thu, Jan 13, 2022 at 3:14 AM Juan Liu <liuj...@cn.ibm.com<mailto:liuj...@cn.ibm.com>> wrote: We are informed that CVE-2021-4104 is not only problem with Log4J 1.x. There is one more CVE-2019-17571, and as Apache announced EOL in 2015, so Spark 3.3.0 will be very expected. Do you think middle 2022 is a reasonable time for Spark 3.3.0 release? Juan Liu (刘娟) PMP® Release Management, Watson Health, China Development Lab Email: liuj...@cn.ibm.com<mailto:liuj...@cn.ibm.com> Phone: 86-10-82452506 --------------------------------------------------------------------- To unsubscribe e-mail: user-unsubscr...@spark.apache.org<mailto:user-unsubscr...@spark.apache.org>