dongjoon-hyun commented on PR #52535: URL: https://github.com/apache/spark/pull/52535#issuecomment-3382045827
When it's not an Apache Spark vulnerability, we don't make a misleading backport because we don't want to be a boy who cried wolf. There are too many false alarms already. > My only justification is removing the vulnerable dependency Let me close this PR to prevent accidental merging. We can continue to discuss on this topic on this closed PR. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
