Hi all,

Thank you for chiming in on this DISCUSS thread for Apache Spark 4.1.4! Synced 
with Szehon, we will proceed with 4.2.1 and 4.1.4, respectively.

Also, 5 merged patches were missing the 4.1.4 Fix Version label, so I added 
them: SPARK-58529, SPARK-57635, SPARK-57638, SPARK-58834, and SPARK-59334. With 
this, 4.1.4 is now sitting at 68 JIRAs 
(https://issues.apache.org/jira/projects/SPARK/versions/12357252).

At this time, Spark Version 4.1.4 doesn't have any outstanding JIRA issues; 
SPARK-59405 and SPARK-59406 are "to do" - but they have been resolved in 
branch-4.1, thank you Holden Karau! However, if anyone has some additional 4.1 
backports, please feel free to reach out.

Best,
Uroš

On 2026/09/22 09:22:22 Uroš Bojanić wrote:
> Hi all,
> 
> Following Szehon's 4.2.1 release discussion, I would like to propose the next 
> maintenance releases for the older maintained lines as well, and I would be 
> happy to start off by volunteering to drive 4.1.4 release.
> 
> All of 3.5.x / 4.0.x / 4.1.x / 4.2.x were last released together in mid-July 
> 2026, which is about ~10 weeks ago. Since then:
> 
> - branch-4.1 has accumulated 63 JIRAs (82 commits), including wrong-results 
> correctness fixes (SPARK-59050 SPJ multi-join, SPARK-58341 positional 
> parameters, SPARK-57932 regexp on supplementary chars, SPARK-59602 float 
> normalization), stability fixes (SPARK-58323 StackOverflow, SPARK-58886 Int 
> overflow, SPARK-55271/SPARK-59008 NPEs), and resource-leak fixes 
> (SPARK-58714, SPARK-58751).
> 
> - branch-4.0 has 48 JIRAs (60 commits), sharing most of the above correctness 
> fixes. Please note that 4.0.x reaches ~18 months this November, so this would 
> likely be one of its final maintenance releases.
> 
> - branch-3.5 (extended LTS, security-only) has 14 JIRAs of accumulated 
> security hardening (XSS, Zip-Slip, credential logging, path-traversal, 
> info-disclosure fixes) that are not yet in any 3.5 release; we should perhaps 
> consider getting these out to LTS users.
> 
> Concretely, I propose that I drive the 4.1.4 release, but we can also 
> coordinate this with 4.0.5 (they share most cherry-picks), and possibly 
> follow with a security-focused 3.5.10.
> 
> In any case, I would be happy to pair / coordinate with Szehon in this 
> process. What do you folks think? Also, please mention if you have any 
> additional must-have backports for any these releases (4.1.4, 4.0.5, 3.5.10).
> 
> Best,
> Uroš
> 
> ---------------------------------------------------------------------
> To unsubscribe e-mail: [email protected]
> 
> 

---------------------------------------------------------------------
To unsubscribe e-mail: [email protected]

Reply via email to