You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@kylin.apache.org by ShaoFeng Shi <sh...@apache.org> on 2022/08/10 02:37:20 UTC

[DISCUSS] Move to Spark 3 totally in Kylin 4

Hello Kylin community,

As you know, Kylin 4.0 supports both Spark 2.4 and Spark 3.1 at the very
begining; Recently when we try to fix some security vulnerabilities (e.g,
CVE-2022-22978 <https://github.com/advisories/GHSA-hh32-7344-cg2f>), we
found that Spark 2 is hard to be compitable with recommended version of
Spring-core and Spring security.

Besides, we noticed that the latest Spark 2 release v2.4.8 was released on
May 17, 2021, which is almost 15 months ago. Which means it is not actively
maintained anymore.

So,  I propose Kylin 4 move to Spark 3 totally, and will not release
package for Spark 2 anymore. For the legacy users, please upgrade your
Spark.

Your comments are welcomed.

Best regards,

Shaofeng Shi 史少锋
Apache Kylin PMC,
Apache Incubator PMC,
Email: shaofengshi@apache.org

Apache Kylin FAQ: https://kylin.apache.org/docs/gettingstarted/faq.html
Join Kylin user mail group: user-subscribe@kylin.apache.org
Join Kylin dev mail group: dev-subscribe@kylin.apache.org

Re: [DISCUSS] Move to Spark 3 totally in Kylin 4

Posted by ShaoFeng Shi <sh...@apache.org>.
Thanks for yang's comment. We will move to Spark 3 from next release, which
will be Kylin 4.0.2.

Best regards,

Shaofeng Shi 史少锋
Apache Kylin PMC,
Apache Incubator PMC,
Email: shaofengshi@apache.org

Apache Kylin FAQ: https://kylin.apache.org/docs/gettingstarted/faq.html
Join Kylin user mail group: user-subscribe@kylin.apache.org
Join Kylin dev mail group: dev-subscribe@kylin.apache.org




Yang Li <ya...@kyligence.io> 于2022年8月11日周四 17:36写道:

> +1
>
> Spark 2 is out of maintenance. Due to security concerns, we should
> encourage all Kylin users to move away from Spark 2 and onboard Spark 3 for
> data safety.
>
> The best signal for this purpose is stopping releases that are known to
> contain security vulnerabilities.
>
> Regards
> Yang
>
> From: ShaoFeng Shi <sh...@apache.org>>
> Sent: Wednesday, August 10, 2022 10:37 AM
> To: dev <de...@kylin.apache.org>>; user <
> user@kylin.apache.org<ma...@kylin.apache.org>>
> Subject: [DISCUSS] Move to Spark 3 totally in Kylin 4
>
> Hello Kylin community,
>
> As you know, Kylin 4.0 supports both Spark 2.4 and Spark 3.1 at the very
> begining; Recently when we try to fix some security vulnerabilities (e.g,
> CVE-2022-22978<https://github.com/advisories/GHSA-hh32-7344-cg2f>), we
> found that Spark 2 is hard to be compitable with recommended version of
> Spring-core and Spring security.
>
> Besides, we noticed that the latest Spark 2 release v2.4.8 was released on
> May 17, 2021, which is almost 15 months ago. Which means it is not actively
> maintained anymore.
>
> So,  I propose Kylin 4 move to Spark 3 totally, and will not release
> package for Spark 2 anymore. For the legacy users, please upgrade your
> Spark.
>
> Your comments are welcomed.
>
> Best regards,
>
> Shaofeng Shi 史少锋
> Apache Kylin PMC,
> Apache Incubator PMC,
> Email: shaofengshi@apache.org<ma...@apache.org>
>
> Apache Kylin FAQ: https://kylin.apache.org/docs/gettingstarted/faq.html
> Join Kylin user mail group: user-subscribe@kylin.apache.org<mailto:
> user-subscribe@kylin.apache.org>
> Join Kylin dev mail group: dev-subscribe@kylin.apache.org<mailto:
> dev-subscribe@kylin.apache.org>
>
>
>

Re: [DISCUSS] Move to Spark 3 totally in Kylin 4

Posted by ShaoFeng Shi <sh...@apache.org>.
Thanks for yang's comment. We will move to Spark 3 from next release, which
will be Kylin 4.0.2.

Best regards,

Shaofeng Shi 史少锋
Apache Kylin PMC,
Apache Incubator PMC,
Email: shaofengshi@apache.org

Apache Kylin FAQ: https://kylin.apache.org/docs/gettingstarted/faq.html
Join Kylin user mail group: user-subscribe@kylin.apache.org
Join Kylin dev mail group: dev-subscribe@kylin.apache.org




Yang Li <ya...@kyligence.io> 于2022年8月11日周四 17:36写道:

> +1
>
> Spark 2 is out of maintenance. Due to security concerns, we should
> encourage all Kylin users to move away from Spark 2 and onboard Spark 3 for
> data safety.
>
> The best signal for this purpose is stopping releases that are known to
> contain security vulnerabilities.
>
> Regards
> Yang
>
> From: ShaoFeng Shi <sh...@apache.org>>
> Sent: Wednesday, August 10, 2022 10:37 AM
> To: dev <de...@kylin.apache.org>>; user <
> user@kylin.apache.org<ma...@kylin.apache.org>>
> Subject: [DISCUSS] Move to Spark 3 totally in Kylin 4
>
> Hello Kylin community,
>
> As you know, Kylin 4.0 supports both Spark 2.4 and Spark 3.1 at the very
> begining; Recently when we try to fix some security vulnerabilities (e.g,
> CVE-2022-22978<https://github.com/advisories/GHSA-hh32-7344-cg2f>), we
> found that Spark 2 is hard to be compitable with recommended version of
> Spring-core and Spring security.
>
> Besides, we noticed that the latest Spark 2 release v2.4.8 was released on
> May 17, 2021, which is almost 15 months ago. Which means it is not actively
> maintained anymore.
>
> So,  I propose Kylin 4 move to Spark 3 totally, and will not release
> package for Spark 2 anymore. For the legacy users, please upgrade your
> Spark.
>
> Your comments are welcomed.
>
> Best regards,
>
> Shaofeng Shi 史少锋
> Apache Kylin PMC,
> Apache Incubator PMC,
> Email: shaofengshi@apache.org<ma...@apache.org>
>
> Apache Kylin FAQ: https://kylin.apache.org/docs/gettingstarted/faq.html
> Join Kylin user mail group: user-subscribe@kylin.apache.org<mailto:
> user-subscribe@kylin.apache.org>
> Join Kylin dev mail group: dev-subscribe@kylin.apache.org<mailto:
> dev-subscribe@kylin.apache.org>
>
>
>

RE: [DISCUSS] Move to Spark 3 totally in Kylin 4

Posted by Yang Li <ya...@kyligence.io>.
+1

Spark 2 is out of maintenance. Due to security concerns, we should encourage all Kylin users to move away from Spark 2 and onboard Spark 3 for data safety.

The best signal for this purpose is stopping releases that are known to contain security vulnerabilities.

Regards
Yang

From: ShaoFeng Shi <sh...@apache.org>>
Sent: Wednesday, August 10, 2022 10:37 AM
To: dev <de...@kylin.apache.org>>; user <us...@kylin.apache.org>>
Subject: [DISCUSS] Move to Spark 3 totally in Kylin 4

Hello Kylin community,

As you know, Kylin 4.0 supports both Spark 2.4 and Spark 3.1 at the very begining; Recently when we try to fix some security vulnerabilities (e.g, CVE-2022-22978<https://github.com/advisories/GHSA-hh32-7344-cg2f>), we found that Spark 2 is hard to be compitable with recommended version of Spring-core and Spring security.

Besides, we noticed that the latest Spark 2 release v2.4.8 was released on May 17, 2021, which is almost 15 months ago. Which means it is not actively maintained anymore.

So,  I propose Kylin 4 move to Spark 3 totally, and will not release package for Spark 2 anymore. For the legacy users, please upgrade your Spark.

Your comments are welcomed.

Best regards,

Shaofeng Shi 史少锋
Apache Kylin PMC,
Apache Incubator PMC,
Email: shaofengshi@apache.org<ma...@apache.org>

Apache Kylin FAQ: https://kylin.apache.org/docs/gettingstarted/faq.html
Join Kylin user mail group: user-subscribe@kylin.apache.org<ma...@kylin.apache.org>
Join Kylin dev mail group: dev-subscribe@kylin.apache.org<ma...@kylin.apache.org>