This is an automated email from the ASF dual-hosted git repository.

yiguolei pushed a commit to branch branch-4.2
in repository https://gitbox.apache.org/repos/asf/doris.git

commit 6f2c64f5ae7231871a9e0839915c465f141692f6
Author: Calvin Kirs <[email protected]>
AuthorDate: Tue Sep 29 09:32:45 2026 +0800

    branch-4.1: [fix](fe) Bump vulnerable FE dependency versions (#68557)
    
    https://github.com/apache/doris/pull/68445
---
 fe/pom.xml | 26 ++++++++++++++++++--------
 1 file changed, 18 insertions(+), 8 deletions(-)

diff --git a/fe/pom.xml b/fe/pom.xml
index 41c040cc869..3322689eaae 100644
--- a/fe/pom.xml
+++ b/fe/pom.xml
@@ -234,7 +234,7 @@ under the License.
         
<doris.hive.catalog.shade.version>3.1.3</doris.hive.catalog.shade.version>
         <!-- iceberg 1.9.1 depends avro on 1.12 -->
         <avro.version>1.12.1</avro.version>
-        <parquet.version>1.17.0</parquet.version>
+        <parquet.version>1.18.0</parquet.version>
         <spark.version>3.4.3</spark.version>
         <hudi.version>1.0.2</hudi.version>
         <obs.dependency.scope>compile</obs.dependency.scope>
@@ -291,14 +291,14 @@ under the License.
         <hikaricp.version>6.0.0</hikaricp.version>
         <thrift.version>0.24.0</thrift.version>
         <tomcat-embed.version>9.0.104</tomcat-embed.version>
-        <log4j2.version>2.25.4</log4j2.version>
-        <log4j-1.2.version>2.25.4</log4j-1.2.version>
+        <log4j2.version>2.25.5</log4j2.version>
+        <log4j-1.2.version>2.25.5</log4j-1.2.version>
         <mqtt.version>1.2.5</mqtt.version>
         <slf4j.version>2.0.17</slf4j.version>
         <metrics-core.version>4.0.2</metrics-core.version>
         <resilience4j.version>2.4.0</resilience4j.version>
         <!-- Keep Netty compatible with Arrow Flight SQL 19 and other 
transitive Netty users. -->
-        <netty-all.version>4.2.15.Final</netty-all.version>
+        <netty-all.version>4.2.17.Final</netty-all.version>
         <!-- OpenTelemetry versions before 1.62.0 allow unbounded allocation 
while parsing W3C
              baggage (CVE-2026-45292); align the complete OpenTelemetry graph 
on the fixed BOM. -->
         <opentelemetry.version>1.62.0</opentelemetry.version>
@@ -373,7 +373,7 @@ under the License.
         <!-- HttpClient 5.5.2 can leak pooled connections on decode errors 
(CVE-2026-64607),
              and HttpCore 5.3.6 is affected by HTTP/1 and HTTP/2 
memory-exhaustion issues
              (CVE-2026-54399 and CVE-2026-54428). Use their fixed maintenance 
releases. -->
-        <httpclient5.version>5.6.3</httpclient5.version>
+        <httpclient5.version>5.6.4</httpclient5.version>
         <httpcore5.version>5.4.3</httpcore5.version>
         <aws-java-sdk.version>1.12.669</aws-java-sdk.version>
         <mariadb-java-client.version>3.0.9</mariadb-java-client.version>
@@ -382,8 +382,8 @@ under the License.
         <re2j.version>1.8</re2j.version>
         
<hadoop.thirdparty.guava.version>1.2.0</hadoop.thirdparty.guava.version>
         
<hadoop.thirdparty.protobuf_3_25.version>1.5.0</hadoop.thirdparty.protobuf_3_25.version>
-        <hbase.version>2.6.3</hbase.version>
-        <jline.version>3.30.6</jline.version>
+        <hbase.version>2.6.6</hbase.version>
+        <jline.version>3.30.14</jline.version>
         <hbase-shaded-gson.version>4.1.7</hbase-shaded-gson.version>
         <antlr4.version>4.13.1</antlr4.version>
         <joda.version>2.8.1</joda.version>
@@ -397,7 +397,7 @@ under the License.
         <orc.version>1.8.4</orc.version>
         <zookeeper.version>3.9.3</zookeeper.version>
         <velocity-engine-core.version>2.4</velocity-engine-core.version>
-        <ranger-plugins-common.version>2.8.0</ranger-plugins-common.version>
+        <ranger-plugins-common.version>2.9.0</ranger-plugins-common.version>
         <!-- Huawei IAM pulls bcprov-jdk15on 1.69, whose final 1.70 release is 
vulnerable to
              CVE-2023-33202. Use the compatible jdk18on line at 1.84, which 
also fixes
              CVE-2025-14813, CVE-2026-0636, CVE-2026-3505, CVE-2026-5588, and 
CVE-2026-5598. -->
@@ -1898,6 +1898,16 @@ under the License.
                         <artifactId>bootstrap</artifactId>
                         <groupId>io.airlift</groupId>
                     </exclusion>
+                    <!-- trino-main is used to load Trino connector plugins 
and plan through them
+                         (fe-common and fe-core datasource/trinoconnector, BE 
trino-connector-scanner);
+                         none of them starts Trino's own HTTP server 
(io.airlift.http.server). Drops
+                         the Jetty server side it brings (jetty-servlet, 
http2-server, jetty-jmx, and
+                         jetty-server/jetty-security where nothing else brings 
them); http2-client
+                         stays, it comes from io.airlift:http-client. -->
+                    <exclusion>
+                        <artifactId>http-server</artifactId>
+                        <groupId>io.airlift</groupId>
+                    </exclusion>
                     <exclusion>
                         <artifactId>re2j</artifactId>
                         <groupId>io.trino</groupId>


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to