Skip to content

Update dependency org.apache.parquet:parquet-avro to v1.15.1#50

Open
dev-mend-for-github-com[bot] wants to merge 1 commit into
mainfrom
whitesource-remediate/org.apache.parquet-parquet-avro-1.x
Open

Update dependency org.apache.parquet:parquet-avro to v1.15.1#50
dev-mend-for-github-com[bot] wants to merge 1 commit into
mainfrom
whitesource-remediate/org.apache.parquet-parquet-avro-1.x

Conversation

@dev-mend-for-github-com

@dev-mend-for-github-com dev-mend-for-github-com Bot commented Feb 25, 2026

Copy link
Copy Markdown

This PR contains the following updates:

Package Type Update Change
org.apache.parquet:parquet-avro (source) compile minor 1.13.11.15.1

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS Score Vulnerability
Critical Critical 10.0 CVE-2025-30065
High High 7.1 CVE-2025-46762

Release Notes

apache/parquet-mr (org.apache.parquet:parquet-avro)

v1.14.1

Release Notes - Parquet - Version 1.14.1

Bug
  • PARQUET-2468 - ParquetMetadata.toPrettyJSON throws exception on file read when LOG.isDebugEnabled()
  • PARQUET-2498 - Hadoop vector IO API doesn't handle empty list of ranges

v1.14.0

Release Notes - Parquet - Version 1.14.0

Bug
  • PARQUET-2260 - Bloom filter bytes size shouldn't be larger than maxBytes size in the configuration
  • PARQUET-2266 - Fix support for files without ColumnIndexes
  • PARQUET-2276 - ParquetReader reads do not work with Hadoop version 2.8.5
  • PARQUET-2300 - Update jackson-core 2.13.4 to a version without CVE PRISMA-2023-0067
  • PARQUET-2325 - Fix parquet-cli's dictionary subcommand to work with FIXED_LEN_BYTE_ARRAY
  • PARQUET-2329 - Fix wrong help messages of parquet-cli subcommands
  • PARQUET-2330 - Fix convert-csv to show the correct position of the invalid record
  • PARQUET-2332 - Fix unexpectedly disabled tests to be executed
  • PARQUET-2336 - Add caching key to CodecFactory
  • PARQUET-2342 - Parquet writer produced a corrupted file due to page value count overflow
  • PARQUET-2343 - Fixes NPE when rewriting file with multiple rowgroups
  • PARQUET-2348 - Recompression/Re-encrypt should rewrite bloomfilter
  • PARQUET-2354 - Apparent race condition in CharsetValidator
  • PARQUET-2363 - ParquetRewriter should encrypt the V2 page header
  • PARQUET-2365 - Fixes NPE when rewriting column without column index
  • PARQUET-2408 - Fix license header in .gitattributes
  • PARQUET-2420 - ThriftParquetWriter converts thrift byte to int32 without adding logical type
  • PARQUET-2429 - Direct buffer churn in NonBlockedDecompressor
  • PARQUET-2438 - Fixes minMaxSize for BinaryColumnIndexBuilder
  • PARQUET-2442 - Remove Parquet Site from parquet-mr
  • PARQUET-2448 - parquet-avro does not support nested logical-type for avro <= 1.8
  • PARQUET-2449 - Writing using LocalOutputFile creates a large buffer
  • PARQUET-2450 - ParquetAvroReader throws exception projecting a single field of a repeated record type
  • PARQUET-2456 - avro schema conversion may fail with name conflict when using fixed types
  • PARQUET-2457 - Missing maven-scala-plugin version
  • PARQUET-2458 - Java compiler should use release instead of source/target
  • PARQUET-2465 - Fall back to Hadoop Configuration
New Feature
Improvement
Test
  • PARQUET-2361 - Reduce failure rate of unit test testParquetFileWithBloomFilterWithFpp
Task

  • If you want to rebase/retry this PR, check this box

@dev-mend-for-github-com dev-mend-for-github-com Bot added the security fix Security fix generated by Mend label Feb 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants