Skip to content

Commit 7fc905b

Browse files
thomastuncclaude
andcommitted
Bump thrift from 0.24.0 to 0.25.0
Apache Thrift 0.25.0 fixes a set of CVEs, including CVE-2026-66055 (unbounded resource allocation, affects the Python bindings) and CVE-2026-66858 (missing recursion limit in protocol skip routines). Downstream users whose vulnerability scanners block thrift 0.24.x cannot upgrade without this change. 0.25.0 publishes the same prebuilt wheel set as 0.24.0 (manylinux2014, musllinux, macOS and Windows, cp310-cp314), so the DBR LTS install-safety reasoning from THRIFT-6067 still holds. Updated the pyproject comment, moved the cap to <0.26.0 and regenerated poetry.lock with Poetry 2.2.1. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017ZsYDtK7BMesAqaiBxpeFC Signed-off-by: Thomas Tunc <28352452+thomastunc@users.noreply.github.com>
1 parent 01564c7 commit 7fc905b

2 files changed

Lines changed: 63 additions & 55 deletions

File tree

‎poetry.lock‎

Lines changed: 45 additions & 40 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎pyproject.toml‎

Lines changed: 18 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -10,21 +10,24 @@ include = ["CHANGELOG.md"]
1010

1111
[tool.poetry.dependencies]
1212
python = "^3.10"
13-
# Floor is 0.24.0 -- the first release that both clears the open Apache Thrift
14-
# CVEs (CVE-2025-48431 + the CVE-2026-41602..41636 set, all fixed in 0.23.0)
15-
# AND is safe to install on DBR LTS. History: 0.23.0 fixed the CVEs but ships
16-
# sdist-only and its setup.py calls sys.exit(0) on the build-success path,
17-
# killing the PEP 517 backend on the OLD setuptools bundled by DBR LTS -- the
18-
# SEV0 ES-1960554 (4.2.7 widened to <0.24.0 and was yanked; PR #840), which is
19-
# why we held at ~=0.22.0. thrift 0.24.0 (THRIFT-6067) resolves this: it ships
20-
# prebuilt manylinux2014 wheels (cp310-cp314) + macOS/musl/Windows, so pip uses
21-
# a wheel and never runs setup.py on DBR LTS -- the build-time break cannot
22-
# trigger. The `DBR LTS Install` CI check (.github/workflows/dbr-lts-install.yml)
23-
# installs the built artifact on real DBR LTS clusters and is the authoritative
24-
# gate for this. Cap at <0.25.0: thrift is pre-1.0, each 0.x minor can carry
25-
# breaking changes or packaging regressions (see 0.23.0), so bump this
26-
# deliberately once a new minor ships and the DBR-LTS gate proves it safe.
27-
thrift = "~=0.24.0"
13+
# Floor is 0.25.0 -- required to clear the Apache Thrift CVEs fixed in that
14+
# release, incl. CVE-2026-66055 (unbounded allocation, Python bindings) and
15+
# CVE-2026-66858 (no recursion limit in protocol skip). Earlier floors already
16+
# covered CVE-2025-48431 + the CVE-2026-41602..41636 set (fixed in 0.23.0).
17+
# DBR LTS install safety: 0.23.0 shipped sdist-only and its setup.py calls
18+
# sys.exit(0) on the build-success path, killing the PEP 517 backend on the OLD
19+
# setuptools bundled by DBR LTS -- the SEV0 ES-1960554 (4.2.7 widened to
20+
# <0.24.0 and was yanked; PR #840), which is why we held at ~=0.22.0.
21+
# thrift 0.24.0 (THRIFT-6067) resolved this by shipping prebuilt manylinux2014
22+
# wheels (cp310-cp314) + macOS/musl/Windows, and 0.25.0 keeps the same wheel
23+
# matrix, so pip uses a wheel and never runs setup.py on DBR LTS -- the
24+
# build-time break cannot trigger. The `DBR LTS Install` CI check
25+
# (.github/workflows/dbr-lts-install.yml) installs the built artifact on real
26+
# DBR LTS clusters and is the authoritative gate for this. Cap at <0.26.0:
27+
# thrift is pre-1.0, each 0.x minor can carry breaking changes or packaging
28+
# regressions (see 0.23.0), so bump this deliberately once a new minor ships
29+
# and the DBR-LTS gate proves it safe.
30+
thrift = "~=0.25.0"
2831
pandas = [
2932
{ version = ">=1.2.5,<4.0.0", python = ">=3.10,<3.13" },
3033
{ version = ">=2.2.3,<4.0.0", python = ">=3.13" }

0 commit comments

Comments
 (0)