apache / apache/iceberg-rust

request for security bugfix release

Open
#2,439 8 comments 1 reaction 0 assignees View on GitHub
Dominant language
Rust
Stars
1.4k
Forks
567
Avg merge
2d 2h
Merged PRs (30d)
93

Description

jsonwebtoken < v10.3.0 have a security vuln of Medium severity [CVE-2026-25537](https://github.com/advisories/GHSA-h395-gr6q-cpjc)

It is transitive dependency of opendal 55. We migrated to opendal 56 in #2401

It would be nice to have a bugfix release with those changes ( and possibly other RUSTSEC fixes? )

thanks!

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the opendal 56 migration in issue #2401 and the repository's release process. Confirm that a bugfix release includes the dependency update addressing CVE-2026-25537; whether to include other RUSTSEC fixes remains an open question.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
release, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.