Skip to content

Conversation

@dev-lpq
Copy link
Contributor

@dev-lpq dev-lpq commented Dec 24, 2025

Why are the changes needed?

upgrade commons-lang3 from 3.17.0 to 3.20.0 reducing direct CVE vulnerabilities, see
GHSA-j288-q9x7-2f5v
This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.

How was this patch tested?

  • Run test locally before make a pull request

Was this patch authored or co-authored using generative AI tooling?

No

@dev-lpq dev-lpq changed the title fix commons-lang3 cve upgrade commons-lang3 from 3.17.0 to 3.20.0 Dec 24, 2025
@dev-lpq dev-lpq closed this Dec 24, 2025
@dev-lpq dev-lpq deleted the kyuubi_cve_commons-lang3 branch December 24, 2025 09:43
@pan3793
Copy link
Member

pan3793 commented Dec 24, 2025

master already uses commons-lang3 3.18.0, so it is not affected by CVE, but it's also good to have regular dependency upgrading before releasing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants