Skip to content

HADOOP-19841. hadoop-thirdparty: upgrade to avro 1.11.5#51

Merged
steveloughran merged 1 commit intoapache:trunkfrom
steveloughran:pr-upgrade-avro-to-1.11.5
Mar 19, 2026
Merged

HADOOP-19841. hadoop-thirdparty: upgrade to avro 1.11.5#51
steveloughran merged 1 commit intoapache:trunkfrom
steveloughran:pr-upgrade-avro-to-1.11.5

Conversation

@steveloughran
Copy link
Contributor

Bumps the shaded Avro dependency to the latest 1.11.x patch release.

For code changes:

  • Does the title or this PR start with the corresponding JIRA issue id (e.g. 'HADOOP-17799. Your PR title ...')?
  • Have you updated the LICENSE, LICENSE-binary, NOTICE-binary files?
  • If adding new dependencies to the code, are these dependencies licensed in a way that is compatible for inclusion under ASF 2.0?

Use of AI

Was AI used to help generate this PR? yes, actually. It forgot about the license/notice changes first time round.

If so: which tool: Claude

Upgrade Apache Avro from 1.11.4 to 1.11.5 in hadoop-shaded-avro_1_11

Addresses CVE-2025-33042

Updates LICENSE-binary to reflect the new version.
Copy link
Contributor

@cnauroth cnauroth left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+1. Thanks, Steve.

@steveloughran steveloughran merged commit 7ccab4c into apache:trunk Mar 19, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants