Skip to content

Pyarrow <19.0 dependency causes CVE alert #231

@qamasailer

Description

@qamasailer

Hi!

The dependency to pyarrow <19.0 causes the following CVE alert:
GHSA-rgxp-2hwp-jwgg

As the dependency was only introduced because there was the problematic version 19.0.0 and the anaconda channel did not have the bugfix version ready, I think that it is reasonable to drop the dependency now. The new fixed version 23.0.1 that does not cause the CVE alert is also available in https://repo.anaconda.com/pkgs/snowflake/.

Can you please remove this dependency?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions