Skip to content

Bump thrift from 0.24.0 to 0.25.0 - #968

Open
thomastunc wants to merge 1 commit into
databricks:mainfrom
thomastunc:thrift-0.25.0-upgrade
Open

thomastunc wants to merge 1 commit into
databricks:mainfrom
thomastunc:thrift-0.25.0-upgrade

Conversation

@thomastunc

Copy link
Copy Markdown

Apache Thrift 0.25.0 fixes a set of CVEs, including CVE-2026-66055 (unbounded resource allocation, affects the Python bindings) and CVE-2026-66858 (missing recursion limit in protocol skip routines). Downstream users whose vulnerability scanners block thrift 0.24.x cannot upgrade without this change.

0.25.0 publishes the same prebuilt wheel set as 0.24.0 (manylinux2014, musllinux, macOS and Windows, cp310-cp314), so the DBR LTS install-safety reasoning from THRIFT-6067 still holds. Updated the pyproject comment, moved the cap to <0.26.0 and regenerated poetry.lock with Poetry 2.2.1.

What type of PR is this?

  • Refactor
  • Feature
  • Bug Fix
  • Other

Description

How is this tested?

  • Unit tests
  • E2E Tests
  • Manually
  • N/A

Related Tickets & Documents

Apache Thrift 0.25.0 fixes a set of CVEs, including CVE-2026-66055
(unbounded resource allocation, affects the Python bindings) and
CVE-2026-66858 (missing recursion limit in protocol skip routines).
Downstream users whose vulnerability scanners block thrift 0.24.x
cannot upgrade without this change.

0.25.0 publishes the same prebuilt wheel set as 0.24.0 (manylinux2014,
musllinux, macOS and Windows, cp310-cp314), so the DBR LTS
install-safety reasoning from THRIFT-6067 still holds. Updated the
pyproject comment, moved the cap to <0.26.0 and regenerated
poetry.lock with Poetry 2.2.1.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017ZsYDtK7BMesAqaiBxpeFC
Signed-off-by: Thomas Tunc <28352452+thomastunc@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 5, 2026 14:00

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

It bumps a core pre-1.0 RPC dependency whose minor releases can carry breaking changes, and runtime compatibility of the connector's heavy thrift usage cannot be fully verified here, so human review is prudent.

Review effort: Balanced
Findings: None

What changed in this PR

This PR bumps the thrift dependency from 0.24.0 to 0.25.0 to clear two newly disclosed Apache Thrift CVEs (CVE-2026-66055 and CVE-2026-66858) that affect the Python bindings, so downstream users whose scanners block thrift 0.24.x can upgrade. It is a dependency-only change with no connector source modifications. The accompanying lockfile regeneration keeps the install graph reproducible, and the existing DBR LTS Install CI workflow remains the authoritative gate verifying that prebuilt wheels (not the sdist) are used on DBR LTS.

Changes:

  • Raise the thrift constraint from ~=0.24.0 to ~=0.25.0 (floor 0.25.0, cap <0.26.0) and update the explanatory comment with the new CVE rationale.
  • Regenerate poetry.lock with thrift 0.25.0 wheels/hashes and an updated content-hash.
File Description
pyproject.toml Bumps the thrift version constraint to ~=0.25.0 and refreshes the install-safety/CVE comment.
poetry.lock Pins thrift 0.25.0 (new wheel set + hashes), updates content-hash, and reorders two python-versions strings from Poetry regeneration.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants