diff --git a/dependencies.md b/dependencies.md index 217aa26..404e8d9 100644 --- a/dependencies.md +++ b/dependencies.md @@ -11,7 +11,7 @@ | [Spark Project SQL][6] | [Apache-2.0][7] | | [aircompressor][8] | [Apache License 2.0][7] | | [LZ4 Java Compression][9] | [Apache License, Version 2.0][10] | -| [Scala Library][11] | [Apache-2.0][10] | +| [scala-library-bootstrapped][11] | [Apache-2.0][10] | | [Apache Ivy][12] | [The Apache Software License, Version 2.0][13] | | [Apache ZooKeeper - Server][14] | [Apache License, Version 2.0][15] | | [Apache Avro][16] | [Apache-2.0][15] | @@ -75,7 +75,7 @@ [8]: https://github.com/airlift/aircompressor [9]: https://github.com/yawkat/lz4-java [10]: https://www.apache.org/licenses/LICENSE-2.0 -[11]: https://www.scala-lang.org/ +[11]: https://scala-lang.org/ [12]: http://ant.apache.org/ivy/ [13]: http://www.apache.org/licenses/LICENSE-2.0.txt [14]: http://zookeeper.apache.org/zookeeper diff --git a/doc/changes/changelog.md b/doc/changes/changelog.md index 9b5a820..15ca59e 100644 --- a/doc/changes/changelog.md +++ b/doc/changes/changelog.md @@ -1,5 +1,6 @@ # Changes +* [4.0.1](changes_4.0.1.md) * [4.0.0](changes_4.0.0.md) * [3.0.0](changes_3.0.0.md) * [2.0.16](changes_2.0.16.md) diff --git a/doc/changes/changes_4.0.1.md b/doc/changes/changes_4.0.1.md new file mode 100644 index 0000000..09ca52c --- /dev/null +++ b/doc/changes/changes_4.0.1.md @@ -0,0 +1,29 @@ +# Spark Connector Common Java 4.0.1, released 2026-??-?? + +Code name: Fixed vulnerability CVE-2026-75596 in io.netty:netty-handler:jar:4.2.16.Final:provided + +## Summary + +This release fixes the following vulnerability: + +### CVE-2026-75596 (CWE-407) in dependency `io.netty:netty-handler:jar:4.2.16.Final:provided` +io.netty:netty-handler - Inefficient Algorithmic Complexity +#### References +* https://guide.sonatype.com/vulnerability/CVE-2026-75596?component-type=maven&component-name=io.netty%2Fnetty-handler&utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.1 +* http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-75596 +* https://github.com/netty/netty/security/advisories/GHSA-fccg-mwvh-qqg4 + +## Security + +* #114: Fixed vulnerability CVE-2026-75596 in dependency `io.netty:netty-handler:jar:4.2.16.Final:provided` + +## Dependency Updates + +### Compile Dependency Updates + +* Updated `at.yawk.lz4:lz4-java:1.11.1` to `1.11.2` + +### Test Dependency Updates + +* Updated `nl.jqno.equalsverifier:equalsverifier:4.5` to `4.5.1` +* Updated `org.junit.jupiter:junit-jupiter-params:6.1.2` to `6.1.3` diff --git a/pk_generated_parent.pom b/pk_generated_parent.pom index f3740cf..bb99213 100644 --- a/pk_generated_parent.pom +++ b/pk_generated_parent.pom @@ -3,7 +3,7 @@ 4.0.0 com.exasol spark-connector-common-java-generated-parent - 4.0.0 + 4.0.1 pom UTF-8 diff --git a/pom.xml b/pom.xml index 03159bd..6103873 100644 --- a/pom.xml +++ b/pom.xml @@ -3,14 +3,14 @@ 4.0.0 com.exasol spark-connector-common-java - 4.0.0 + 4.0.1 spark-connector-common-java An Exasol common library for Apache Spark connectors https://github.com/exasol/spark-connector-common-java/ spark-connector-common-java-generated-parent com.exasol - 4.0.0 + 4.0.1 pk_generated_parent.pom @@ -23,7 +23,7 @@ io.netty netty-bom - 4.2.16.Final + 4.2.17.Final pom import @@ -63,14 +63,14 @@ com.fasterxml.jackson jackson-bom - 2.22.1 + 2.22.2 pom import org.junit junit-bom - 6.1.2 + 6.1.3 pom import @@ -95,7 +95,7 @@ org.apache.spark spark-sql_2.13 - 4.2.0 + 4.2.0-preview5 provided @@ -130,13 +130,13 @@ at.yawk.lz4 lz4-java - 1.11.1 + 1.11.2 org.scala-lang scala-library - 2.13.18 + 3.8.4 provided @@ -157,7 +157,7 @@ org.apache.avro avro - 1.12.1 + 1.12.2 provided @@ -171,7 +171,7 @@ com.google.protobuf protobuf-java - 4.35.1 + 4.36.0 provided @@ -225,7 +225,7 @@ nl.jqno.equalsverifier equalsverifier - 4.5 + 4.5.1 test