-
Notifications
You must be signed in to change notification settings - Fork 14.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix: bump pyarrow constraints (CVE-2023-47248) #26187
Merged
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
PyArrow < 14.0.1 is vulnerable to RCE when using IPC, Flight or Parquet from untrusted sources. Superset SQLLab does so. So we need to care about this vulnerability.
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## master #26187 +/- ##
==========================================
- Coverage 69.15% 67.00% -2.16%
==========================================
Files 1944 1944
Lines 75925 75925
Branches 8451 8451
==========================================
- Hits 52505 50871 -1634
- Misses 21235 22869 +1634
Partials 2185 2185
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Sentry. |
cwegener
changed the title
chore: bump pyarrow constraints (CVE-2023-47248)
fix: bump pyarrow constraints (CVE-2023-47248)
Dec 5, 2023
dpgaspar
approved these changes
Dec 6, 2023
Fixes #26153 |
3 tasks
michael-s-molina
pushed a commit
that referenced
this pull request
Dec 11, 2023
(cherry picked from commit 2ac2892)
michael-s-molina
pushed a commit
that referenced
this pull request
Dec 15, 2023
(cherry picked from commit 2ac2892)
sadpandajoe
added a commit
to preset-io/superset
that referenced
this pull request
Dec 18, 2023
This reverts commit 2ac2892.
3 tasks
josedev-union
pushed a commit
to Ortege-xyz/studio
that referenced
this pull request
Jan 22, 2024
(cherry picked from commit 2ac2892)
mistercrunch
added
🍒 3.0.3
🍒 3.0.4
🍒 3.1.0
🍒 3.1.1
🏷️ bot
A label used by `supersetbot` to keep track of which PR where auto-tagged with release labels
labels
Mar 8, 2024
sfirke
pushed a commit
to sfirke/superset
that referenced
this pull request
Mar 22, 2024
vinothkumar66
pushed a commit
to vinothkumar66/superset
that referenced
this pull request
Nov 11, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
2.1.3
🏷️ bot
A label used by `supersetbot` to keep track of which PR where auto-tagged with release labels
size/XS
v2.1
v3.0
Label added by the release manager to track PRs to be included in the 3.0 branch
v3.1
Label added by the release manager to track PRs to be included in the 3.1 branch
🍒 3.0.3
🍒 3.0.4
🍒 3.1.0
🍒 3.1.1
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
PyArrow < 14.0.1 is vulnerable to RCE when using IPC, Flight or Parquet
from untrusted sources.
Superset SQLLab does so.
So we need to care about this vulnerability.