Skip to content

Conversation

@sumi-mathew
Copy link
Contributor

@sumi-mathew sumi-mathew commented Jan 28, 2026

Description

Upgrade parquet version to 1.17.0

Motivation and Context

Using a more recent version helps avoid potential vulnerabilities and ensures we aren't relying on outdated or unsupported code.

Impact

Test Plan

Contributor checklist

  • Please make sure your submission complies with our contributing guide, in particular code style and commit standards.
  • PR description addresses the issue accurately and concisely. If the change is non-trivial, a GitHub Issue is referenced.
  • Documented new properties (with its default value), SQL syntax, functions, or other functionality.
  • If release notes are required, they follow the release notes guidelines.
  • Adequate tests were added if applicable.
  • CI passed.
  • If adding new dependencies, verified they have an OpenSSF Scorecard score of 5.0 or higher (or obtained explicit TSC approval for lower scores).

Release Notes

Please follow release notes guidelines and fill in the release notes below.

== NO RELEASE NOTE ==

@prestodb-ci prestodb-ci added the from:IBM PR from IBM label Jan 28, 2026
@sumi-mathew sumi-mathew changed the title upgrade parquet version to 1.17.0 chore(dep): Upgrade parquet version to 1.17.0 Jan 29, 2026
@sumi-mathew sumi-mathew changed the title chore(dep): Upgrade parquet version to 1.17.0 chore(deps): Upgrade parquet version to 1.17.0 Jan 29, 2026
@sumi-mathew sumi-mathew marked this pull request as ready for review January 29, 2026 10:55
@sumi-mathew sumi-mathew requested a review from a team as a code owner January 29, 2026 10:55
@prestodb-ci prestodb-ci requested review from a team, ShahimSharafudeen and aaneja and removed request for a team January 29, 2026 10:55
@imjalpreet imjalpreet self-requested a review January 29, 2026 16:42
Copy link
Member

@agrawalreetika agrawalreetika left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks like version 1.16.0 and newer version 1.17.0 has the same CVEs.
So if the aim is to be on latest, then changes lgtm.

@agrawalreetika
Copy link
Member

Also I see, We are using parquet dependency only in iceberg module. Would it be better to maintain version just in there, instead on root pom?

@hantangwangd
Copy link
Member

As I see it, Iceberg1.10.1 (the newest release) still depends on Parquet1.16.0. But it appears that it will upgrade Parquet to version 1.17.0 in the next release. Should we keep consistency with it as well? What are your thoughts about this? @sumi-mathew @agrawalreetika

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

from:IBM PR from IBM

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants