Skip to content

Conversation

@kennknowles
Copy link
Member

Iceberg transitively depends on very old logback by way of hadoop-common. Forcing this to a newer version may work if compatibility was maintained.


Thank you for your contribution! Follow this checklist to help us incorporate your contribution quickly and easily:

  • Mention the appropriate issue in your description (for example: addresses #123), if applicable. This will automatically add a link to the pull request in the issue. If you would like the issue to automatically close on merging the pull request, comment fixes #<ISSUE NUMBER> instead.
  • Update CHANGES.md with noteworthy changes.
  • If this contribution is large, please file an Apache Individual Contributor License Agreement.

See the Contributor Guide for more tips on how to make review process smoother.

To check the build health, please visit https://github.com/apache/beam/blob/master/.test-infra/BUILD_STATUS.md

GitHub Actions Tests Status (on master branch)

Build python source distribution and wheels
Python tests
Java tests
Go tests

See CI.md for more information about GitHub Actions CI or the workflows README to see a list of phrases to trigger workflows.

@kennknowles
Copy link
Member Author

R: @ahmedabu98

@gemini-code-assist
Copy link
Contributor

Summary of Changes

Hello @kennknowles, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request updates the logback logging library to version 1.5.20 across the project. The primary motivation is to mitigate security vulnerabilities (CVEs) present in older logback versions that are transitively pulled in by hadoop-common through Iceberg. By explicitly forcing a newer, more secure version, the change aims to enhance the project's security posture without disrupting existing functionality.

Highlights

  • Logback Version Update: Introduced a new logback_version variable set to "1.5.20" in BeamModulePlugin.groovy to specify the desired version for the Logback logging library.
  • Forced Dependency Resolution: Explicitly forced logback-classic and logback-core dependencies to the new "1.5.20" version. This addresses security vulnerabilities (CVEs) present in older Logback versions transitively pulled in by hadoop-common.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

@github-actions github-actions bot added the build label Oct 22, 2025
@github-actions
Copy link
Contributor

Stopping reviewer notifications for this pull request: review requested by someone other than the bot, ceding control. If you'd like to restart, comment assign set of reviewers

@kennknowles
Copy link
Member Author

not sure which set of integration tests we should run to make sure this didn't break things - can you advise?

@kennknowles
Copy link
Member Author

CC: @Abacn

Copy link
Contributor

@Abacn Abacn left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

@kennknowles kennknowles merged commit f517b01 into apache:master Oct 26, 2025
17 checks passed
@kennknowles kennknowles deleted the logback-override branch October 26, 2025 14:31
@Abacn
Copy link
Contributor

Abacn commented Oct 27, 2025

Actually the new logback version dropped Java 8 support, causing tests running on Java8 to fail:

https://github.com/apache/beam/runs/53695655306

@Abacn
Copy link
Contributor

Abacn commented Oct 28, 2025

We may pin logback version in expansion service (which required java11)

@kennknowles
Copy link
Member Author

Got it. That makes sense.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants