Skip to content

Bump avro, fix CVE-2024-47561 - #32770

Merged
damccorm merged 4 commits into
masterfrom
users/damccorm/avroBump
Nov 18, 2024
Merged

damccorm merged 4 commits into
masterfrom
users/damccorm/avroBump

Conversation

@damccorm

@damccorm damccorm commented Oct 14, 2024 •

Copy link
Copy Markdown
Contributor

Fixes #33144


Thank you for your contribution! Follow this checklist to help us incorporate your contribution quickly and easily:

  • Mention the appropriate issue in your description (for example: addresses #123), if applicable. This will automatically add a link to the pull request in the issue. If you would like the issue to automatically close on merging the pull request, comment fixes #<ISSUE NUMBER> instead.
  • Update CHANGES.md with noteworthy changes.
  • If this contribution is large, please file an Apache Individual Contributor License Agreement.

See the Contributor Guide for more tips on how to make review process smoother.

To check the build health, please visit https://github.com/apache/beam/blob/master/.test-infra/BUILD_STATUS.md

GitHub Actions Tests Status (on master branch)

Build python source distribution and wheels
Python tests
Java tests
Go tests

See CI.md for more information about GitHub Actions CI or the workflows README to see a list of phrases to trigger workflows.

@damccorm

damccorm commented Nov 18, 2024 •

Copy link
Copy Markdown
Contributor Author

May go with #33159 depending on how that goes. Update - can't go to 1.12.0 because of Java compatability issues

@damccorm
damccorm marked this pull request as ready for review November 18, 2024 21:58
@damccorm

Copy link
Copy Markdown
Contributor Author

R: @Abacn

@github-actions

Copy link
Copy Markdown
Contributor

Stopping reviewer notifications for this pull request: review requested by someone other than the bot, ceding control. If you'd like to restart, comment assign set of reviewers

@damccorm
damccorm merged commit 3b759f2 into master Nov 18, 2024
@damccorm
damccorm deleted the users/damccorm/avroBump branch November 18, 2024 23:41
@Abacn

Abacn commented Dec 10, 2024

Copy link
Copy Markdown
Contributor

I found the fix isn't effective, due to a logic in BeamModulePlugin here:

def librariesWithVersion = project.library.java.values().findAll { it.split(':').size() > 2 }

which we get

        force "org.apache.avro:avro:1.11.4"
        force "org.apache.avro:avro:1.11.3:tests"

and one always get avro:1.11.3

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Task]: Upgrade Avro to 1.11.4 to fix CVE-2024-47561

2 participants