dongjoon-hyun commented on PR #52535:
URL: https://github.com/apache/spark/pull/52535#issuecomment-3382045827

   When it's not an Apache Spark vulnerability, we don't make a misleading 
backport because we don't want to be a boy who cried wolf. There are too many 
false alarms already.
   > My only justification is removing the vulnerable dependency
   
   Let me close this PR to prevent accidental merging. We can continue to 
discuss on this topic on this closed PR.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to