Skip to content

HADOOP-19945. Update to commons-configuration2 2.15.0 due to CVE-2026-45205#8634

Open
ankithpraveen wants to merge 1 commit into
apache:trunkfrom
ankithpraveen:HADOOP-19945-commons-dependency-bumps
Open

HADOOP-19945. Update to commons-configuration2 2.15.0 due to CVE-2026-45205#8634
ankithpraveen wants to merge 1 commit into
apache:trunkfrom
ankithpraveen:HADOOP-19945-commons-dependency-bumps

Conversation

@ankithpraveen

Copy link
Copy Markdown

Update commons-lang3 and commons-io along with commons-configuration2 because commons-configuration2 2.15.0 is built against newer related Commons library versions.

Description of PR

HADOOP-19945

Updates commons-configuration2 along with related Apache Commons dependencies commons-lang3 and commons-io. The related dependency bumps are included because updating only commons-configuration2 caused the shaded client CI check to fail in #8505. commons-configuration2 2.15.0 declares newer related Commons versions, so this keeps Hadoop's managed dependency set aligned. Also updates LICENSE-binary accordingly.

How was this patch tested?

CI build

For code changes:

  • Does the title or this PR starts with the corresponding JIRA issue id (e.g. 'HADOOP-17799. Your PR title ...')?
  • Object storage: have the integration tests been executed and the endpoint declared according to the connector-specific documentation?
  • If adding new dependencies to the code, are these dependencies licensed in a way that is compatible for inclusion under ASF 2.0?
  • If applicable, have you updated the LICENSE, LICENSE-binary, NOTICE-binary files?

AI Tooling

If an AI tool was used:

…-45205

Update commons-lang3 and commons-io along with commons-configuration2 because commons-configuration2 2.15.0 is built against newer related Commons library versions.
@ankithpraveen
ankithpraveen force-pushed the HADOOP-19945-commons-dependency-bumps branch from 152b40c to f1ebdaf Compare July 27, 2026 09:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants