Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

dependencies? #266

Closed
feefladder opened this issue Mar 30, 2023 · 3 comments · Fixed by #274
Closed

dependencies? #266

feefladder opened this issue Mar 30, 2023 · 3 comments · Fixed by #274

Comments

@feefladder
Copy link

Currently, dependabot has a lot of dependencies that are majorly outdated. Is there any plans to update them or a better library to use?

@kylebarron
Copy link
Owner

I'd accept a PR to update dependencies. The problem is that arrow1 release a new major version every month or so and it's a total pain to keep up with their breaking changes. Arrow2 has fewer breaking changes but enough that I haven't looked into what needs to be changed here.

@feefladder
Copy link
Author

Thanks a lot for the super quick reply!

Ah, ok that's fair! But this does mean that there is no security issues with the current version?
Actually, it would be very nice to have Parquet Modular Encryption somehow working on the client side (so that we can actually end-to-end encrypt columns of a parquet file). But I think this depends on this issue, after which this could be updated? (which would involve additional API, and then this should be a separate issue/PR.

@kylebarron
Copy link
Owner

But this does mean that there is no security issues with the current version?

No way to be sure but I don't know of any specific security vulnerabilities.

Actually, it would be very nice to have Parquet Modular Encryption somehow working on the client side

I've never worked with encrypted parquet files. Similarly it's not implemented in arrow2/parquet2 jorgecarleitao/parquet2#154

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants