databricks-sqlalchemy depends on pyarrow versions with CVE-2024-52338
envgap__databricks__databricks-sqlalchemy-13
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
dd7b15266e6fed0be186447c21b1ef5409c8b3fa- Manifest
pyproject.toml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
databricks/databricks-sqlalchemy #13 · read the original issue
`databricks-sqlalchemy` version `2.0.3` has: ``` Requires-Dist: databricks_sql_connector (==4.0.0.b4) Requires-Dist: pyarrow (>=14.0.1,<17) Requires-Dist: sqlalchemy (>=2.0.21) ``` However, CVE-2024-52338 is only resolved in versions of pyarrow `17.0.0` and later.
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]