Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix advisory to not use object_store 0.9.1 #1749

Closed
tillrohrmann opened this issue Jul 25, 2024 · 0 comments · Fixed by #1750
Closed

Fix advisory to not use object_store 0.9.1 #1749

tillrohrmann opened this issue Jul 25, 2024 · 0 comments · Fixed by #1750
Assignees

Comments

@tillrohrmann
Copy link
Contributor

Currently, our Datafusion dependency (35.0.0) relies on the object_store dependency 0.9.1 which has a security vulnerability. Unfortunately, we cannot simply bump the version since it would also require bumping Datafusion. Bumping Datafusion is currently blocked on some problems with joins (see #1673).

Technically, we shouldn't be using object_store (also not indirectly). Therefore, we should not be affected by this vulnerability.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant