Skip to content

[MINOR] Update dependencies for Paimon due to CVEs#3039

Merged
cgivre merged 1 commit intoapache:masterfrom
pjfanning:paimon-jar-upgrades
Mar 9, 2026
Merged

[MINOR] Update dependencies for Paimon due to CVEs#3039
cgivre merged 1 commit intoapache:masterfrom
pjfanning:paimon-jar-upgrades

Conversation

@pjfanning
Copy link
Member

This module has lots of risky dependencies. Paimon itself has shaded jars for things like Jackson and Guava and the current versions seem well out date.

This PR concentrates on non-shaded jars.

Copy link
Contributor

@cgivre cgivre left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM +1
Thanks for the submission.

@cgivre
Copy link
Contributor

cgivre commented Mar 9, 2026

@pjfanning Do you think we can/should do anything about Paimon's shaded jars?

@pjfanning
Copy link
Member Author

@cgivre the Paimon team are way behind with their dependencies and don't appear to have better shaded releases available.

@cgivre cgivre added minor-update dependencies backport-to-stable This bug fix is applicable to the latest stable release and should be considered for inclusion there labels Mar 9, 2026
@cgivre cgivre merged commit e1a06f3 into apache:master Mar 9, 2026
6 checks passed
@pjfanning pjfanning deleted the paimon-jar-upgrades branch March 9, 2026 13:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport-to-stable This bug fix is applicable to the latest stable release and should be considered for inclusion there dependencies minor-update

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants