Hi all, Thank you for chiming in on this DISCUSS thread for Apache Spark 4.1.4! Synced with Szehon, we will proceed with 4.2.1 and 4.1.4, respectively.
Also, 5 merged patches were missing the 4.1.4 Fix Version label, so I added them: SPARK-58529, SPARK-57635, SPARK-57638, SPARK-58834, and SPARK-59334. With this, 4.1.4 is now sitting at 68 JIRAs (https://issues.apache.org/jira/projects/SPARK/versions/12357252). At this time, Spark Version 4.1.4 doesn't have any outstanding JIRA issues; SPARK-59405 and SPARK-59406 are "to do" - but they have been resolved in branch-4.1, thank you Holden Karau! However, if anyone has some additional 4.1 backports, please feel free to reach out. Best, Uroš On 2026/09/22 09:22:22 Uroš Bojanić wrote: > Hi all, > > Following Szehon's 4.2.1 release discussion, I would like to propose the next > maintenance releases for the older maintained lines as well, and I would be > happy to start off by volunteering to drive 4.1.4 release. > > All of 3.5.x / 4.0.x / 4.1.x / 4.2.x were last released together in mid-July > 2026, which is about ~10 weeks ago. Since then: > > - branch-4.1 has accumulated 63 JIRAs (82 commits), including wrong-results > correctness fixes (SPARK-59050 SPJ multi-join, SPARK-58341 positional > parameters, SPARK-57932 regexp on supplementary chars, SPARK-59602 float > normalization), stability fixes (SPARK-58323 StackOverflow, SPARK-58886 Int > overflow, SPARK-55271/SPARK-59008 NPEs), and resource-leak fixes > (SPARK-58714, SPARK-58751). > > - branch-4.0 has 48 JIRAs (60 commits), sharing most of the above correctness > fixes. Please note that 4.0.x reaches ~18 months this November, so this would > likely be one of its final maintenance releases. > > - branch-3.5 (extended LTS, security-only) has 14 JIRAs of accumulated > security hardening (XSS, Zip-Slip, credential logging, path-traversal, > info-disclosure fixes) that are not yet in any 3.5 release; we should perhaps > consider getting these out to LTS users. > > Concretely, I propose that I drive the 4.1.4 release, but we can also > coordinate this with 4.0.5 (they share most cherry-picks), and possibly > follow with a security-focused 3.5.10. > > In any case, I would be happy to pair / coordinate with Szehon in this > process. What do you folks think? Also, please mention if you have any > additional must-have backports for any these releases (4.1.4, 4.0.5, 3.5.10). > > Best, > Uroš > > --------------------------------------------------------------------- > To unsubscribe e-mail: [email protected] > > --------------------------------------------------------------------- To unsubscribe e-mail: [email protected]
