+1! On Wed, Sep 23, 2026 at 8:46 AM Szehon Ho <[email protected]> wrote:
> +1 > Sure, thanks for thinking of these branches as well. We can target 4.2.1 > and 4.1.4 first and I can work with Uros on the others as well, or see if > any other volunteers for those. > Thanks > Szehon > > On Tue, Sep 22, 2026 at 10:16 AM huaxin gao <[email protected]> > wrote: > >> +1 >> >> On Tue, Sep 22, 2026 at 7:58 AM Kousuke Saruta <[email protected]> >> wrote: >> >>> +1 >>> >>> 2026年9月22日(火) 22:28 Peter Toth <[email protected]>: >>> >>>> +1 >>>> >>>> On Tue, Sep 22, 2026 at 11:23 AM Uroš Bojanić <[email protected]> wrote: >>>> >>>>> Hi all, >>>>> >>>>> Following Szehon's 4.2.1 release discussion, I would like to propose >>>>> the next maintenance releases for the older maintained lines as well, and >>>>> I >>>>> would be happy to start off by volunteering to drive 4.1.4 release. >>>>> >>>>> All of 3.5.x / 4.0.x / 4.1.x / 4.2.x were last released together in >>>>> mid-July 2026, which is about ~10 weeks ago. Since then: >>>>> >>>>> - branch-4.1 has accumulated 63 JIRAs (82 commits), including >>>>> wrong-results correctness fixes (SPARK-59050 SPJ multi-join, SPARK-58341 >>>>> positional parameters, SPARK-57932 regexp on supplementary chars, >>>>> SPARK-59602 float normalization), stability fixes (SPARK-58323 >>>>> StackOverflow, SPARK-58886 Int overflow, SPARK-55271/SPARK-59008 NPEs), >>>>> and >>>>> resource-leak fixes (SPARK-58714, SPARK-58751). >>>>> >>>>> - branch-4.0 has 48 JIRAs (60 commits), sharing most of the above >>>>> correctness fixes. Please note that 4.0.x reaches ~18 months this >>>>> November, >>>>> so this would likely be one of its final maintenance releases. >>>>> >>>>> - branch-3.5 (extended LTS, security-only) has 14 JIRAs of accumulated >>>>> security hardening (XSS, Zip-Slip, credential logging, path-traversal, >>>>> info-disclosure fixes) that are not yet in any 3.5 release; we should >>>>> perhaps consider getting these out to LTS users. >>>>> >>>>> Concretely, I propose that I drive the 4.1.4 release, but we can also >>>>> coordinate this with 4.0.5 (they share most cherry-picks), and possibly >>>>> follow with a security-focused 3.5.10. >>>>> >>>>> In any case, I would be happy to pair / coordinate with Szehon in this >>>>> process. What do you folks think? Also, please mention if you have any >>>>> additional must-have backports for any these releases (4.1.4, 4.0.5, >>>>> 3.5.10). >>>>> >>>>> Best, >>>>> Uroš >>>>> >>>>> --------------------------------------------------------------------- >>>>> To unsubscribe e-mail: [email protected] >>>>> >>>>>
