Skip to content

chore(deps): Upgrade avro to version 1.12.1#27153

Draft
bibith4 wants to merge 1 commit intoprestodb:masterfrom
bibith4:upgrade_avro
Draft

chore(deps): Upgrade avro to version 1.12.1#27153
bibith4 wants to merge 1 commit intoprestodb:masterfrom
bibith4:upgrade_avro

Conversation

@bibith4
Copy link
Contributor

@bibith4 bibith4 commented Feb 17, 2026

Description

Upgrade avro to version 1.12.1 to fix the CVE-2025-33042

Motivation and Context

Using a more recent version helps avoid potential vulnerabilities and ensures we aren't relying on outdated or unsupported code.

Impact

Test Plan

Screenshot 2026-02-19 at 1 12 20 PM

Contributor checklist

  • Please make sure your submission complies with our contributing guide, in particular code style and commit standards.
  • PR description addresses the issue accurately and concisely. If the change is non-trivial, a GitHub Issue is referenced.
  • Documented new properties (with its default value), SQL syntax, functions, or other functionality.
  • If release notes are required, they follow the release notes guidelines.
  • Adequate tests were added if applicable.
  • CI passed.
  • If adding new dependencies, verified they have an OpenSSF Scorecard score of 5.0 or higher (or obtained explicit TSC approval for lower scores).

Release Notes

Please follow release notes guidelines and fill in the release notes below.

== NO RELEASE NOTE ==

@prestodb-ci prestodb-ci added the from:IBM PR from IBM label Feb 17, 2026
@bibith4 bibith4 marked this pull request as ready for review February 18, 2026 05:08
@bibith4 bibith4 requested a review from a team as a code owner February 18, 2026 05:08
@prestodb-ci prestodb-ci requested review from a team, auden-woolfson and jp-sivaprasad and removed request for a team February 18, 2026 05:08
@nishithakbhaskaran
Copy link
Contributor

Thanks @bibith4. LGTM!

@nishithakbhaskaran nishithakbhaskaran removed their request for review February 18, 2026 05:15
@Dilli-Babu-Godari Dilli-Babu-Godari self-requested a review February 19, 2026 07:47
Copy link
Contributor

@Dilli-Babu-Godari Dilli-Babu-Godari left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks

@bibith4 bibith4 requested a review from imjalpreet February 19, 2026 11:36
Copy link
Member

@imjalpreet imjalpreet left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, @bibith4. As discussed offline, please upgrade Avro in hive-apache, too. Once we release a new version for hive-apache, we need to include that version upgrade in this PR.

To validate CI before merging any changes in hive-apache, you can use JitPack and upgrade the hive-apache version in this PR.

@bibith4 bibith4 marked this pull request as draft February 20, 2026 07:43
@bibith4
Copy link
Contributor Author

bibith4 commented Feb 20, 2026

Converting this to draft, as the hive-apache-pr needs to be merged before proceeding with this

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

from:IBM PR from IBM

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

Comments