Skip to content

Conversation

@kosuruvarunkumar
Copy link

@kosuruvarunkumar kosuruvarunkumar commented Nov 8, 2025

What is the purpose of the change

  • Bumps the version of presto to reduce the vulnerabilities present in the previous version

Brief change log

  • Updated the version in pom.xml
  • Excluded the LICENSE files present in the root directory of flink-s3-fs-presto-2.2 jar
  • Updated JarFileChecker to ignore the license files containing forbidden patterns

Verifying this change

This change is a trivial rework / code cleanup without any test coverage.

Does this pull request potentially affect one of the following parts:

  • Dependencies (does it add or upgrade a dependency): yes
  • The public API, i.e., is any changed class annotated with @Public(Evolving): no
  • The serializers: no
  • The runtime per-record code paths (performance sensitive): no
  • Anything that affects deployment or recovery: JobManager (and its components), Checkpointing, Kubernetes/Yarn, ZooKeeper: no
  • The S3 file system connector: yes

Documentation

  • Does this pull request introduce a new feature? no
  • If yes, how is the feature documented? not applicable

@kosuruvarunkumar kosuruvarunkumar changed the title [FLINK-38557] Bumped presto version from 0.272 to 0.295 [FLINK-38557][FileSystems] Bumped presto version from 0.272 to 0.295 Nov 8, 2025
@flinkbot
Copy link
Collaborator

flinkbot commented Nov 8, 2025

CI report:

Bot commands The @flinkbot bot supports the following commands:
  • @flinkbot run azure re-run the last Azure build

@github-actions github-actions bot added the community-reviewed PR has been reviewed by the community. label Nov 8, 2025
- updated dependency version in NOTICE file as mentioned in https://cwiki.apache.org/confluence/display/FLINK/Licensing
- excluded LICENSE files present in root directory causing CI failures
- filtered the license files containing forbidden patterns causing CI failures
update the comments
@kosuruvarunkumar
Copy link
Author

@zentol , @tisonkun, @MartijnVisser can you please take a look on this PR.
(Taging you as I saw you in the blame of JarFileChecker)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

community-reviewed PR has been reviewed by the community.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants