Bump thrift from 0.24.0 to 0.25.0 - #968
thomastunc wants to merge 1 commit into
Conversation
Apache Thrift 0.25.0 fixes a set of CVEs, including CVE-2026-66055 (unbounded resource allocation, affects the Python bindings) and CVE-2026-66858 (missing recursion limit in protocol skip routines). Downstream users whose vulnerability scanners block thrift 0.24.x cannot upgrade without this change. 0.25.0 publishes the same prebuilt wheel set as 0.24.0 (manylinux2014, musllinux, macOS and Windows, cp310-cp314), so the DBR LTS install-safety reasoning from THRIFT-6067 still holds. Updated the pyproject comment, moved the cap to <0.26.0 and regenerated poetry.lock with Poetry 2.2.1. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017ZsYDtK7BMesAqaiBxpeFC Signed-off-by: Thomas Tunc <28352452+thomastunc@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
It bumps a core pre-1.0 RPC dependency whose minor releases can carry breaking changes, and runtime compatibility of the connector's heavy thrift usage cannot be fully verified here, so human review is prudent.
Review effort: Balanced
Findings: None
What changed in this PR
This PR bumps the thrift dependency from 0.24.0 to 0.25.0 to clear two newly disclosed Apache Thrift CVEs (CVE-2026-66055 and CVE-2026-66858) that affect the Python bindings, so downstream users whose scanners block thrift 0.24.x can upgrade. It is a dependency-only change with no connector source modifications. The accompanying lockfile regeneration keeps the install graph reproducible, and the existing DBR LTS Install CI workflow remains the authoritative gate verifying that prebuilt wheels (not the sdist) are used on DBR LTS.
Changes:
- Raise the thrift constraint from
~=0.24.0to~=0.25.0(floor 0.25.0, cap<0.26.0) and update the explanatory comment with the new CVE rationale. - Regenerate
poetry.lockwith thrift 0.25.0 wheels/hashes and an updated content-hash.
| File | Description |
|---|---|
| pyproject.toml | Bumps the thrift version constraint to ~=0.25.0 and refreshes the install-safety/CVE comment. |
| poetry.lock | Pins thrift 0.25.0 (new wheel set + hashes), updates content-hash, and reorders two python-versions strings from Poetry regeneration. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Apache Thrift 0.25.0 fixes a set of CVEs, including CVE-2026-66055 (unbounded resource allocation, affects the Python bindings) and CVE-2026-66858 (missing recursion limit in protocol skip routines). Downstream users whose vulnerability scanners block thrift 0.24.x cannot upgrade without this change.
0.25.0 publishes the same prebuilt wheel set as 0.24.0 (manylinux2014, musllinux, macOS and Windows, cp310-cp314), so the DBR LTS install-safety reasoning from THRIFT-6067 still holds. Updated the pyproject comment, moved the cap to <0.26.0 and regenerated poetry.lock with Poetry 2.2.1.
What type of PR is this?
Description
How is this tested?
Related Tickets & Documents