Skip to content

Conversation

@eschcam
Copy link
Contributor

@eschcam eschcam commented Oct 7, 2025

What changes were proposed in this pull request?

Upgrade commons-lang3 to 3.19.0

Why are the changes needed?

Commons-lang3 3.12.0 contains CVE-2025-48924

Does this PR introduce any user-facing change?

No

How was this patch tested?

Passed CI tests

Was this patch authored or co-authored using generative AI tooling?

No

@github-actions github-actions bot added the BUILD label Oct 7, 2025
Copy link
Member

@dongjoon-hyun dongjoon-hyun left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

To @eschcam , when it comes to backport, you need to verify that CVE is really meaningful for the users.

I don't think the Apache Spark is affected because we don't use org.apache.commons.lang3.ClassUtils.getClass method's CVE bug.

Commons-lang3 3.12.0 contains GHSA-j288-q9x7-2f5v

Please provide more reasons for justification.

@eschcam
Copy link
Contributor Author

eschcam commented Oct 8, 2025

My only justification is removing the vulnerable dependency

@dongjoon-hyun
Copy link
Member

When it's not an Apache Spark vulnerability, we don't make a misleading backport because we don't want to be a boy who cried wolf. There are too many false alarms already.

My only justification is removing the vulnerable dependency

Let me close this PR to prevent accidental merging. We can continue to discuss on this topic on this closed PR.

@eschcam
Copy link
Contributor Author

eschcam commented Oct 10, 2025

When it's not an Apache Spark vulnerability, we don't make a misleading backport because we don't want to be a boy who cried wolf. There are too many false alarms already.

So I'm guessing you only want to upgrade dependencies with reachable vulnerabilities and ignore others.

@eschcam eschcam deleted the 3.5-commons-lang-upgrade branch October 10, 2025 09:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants