MINOR: Bump logback.version from 1.5.34 to 1.5.37 (#1209)

Bumps `logback.version` from 1.5.34 to 1.5.37.
Updates `ch.qos.logback:logback-classic` from 1.5.34 to 1.5.37
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/qos-ch/logback/releases">ch.qos.logback:logback-classic's
releases</a>.</em></p>
<blockquote>
<h2>Logback 1.5.37</h2>
<p><strong>2026-06-26 Release of logback version 1.5.37</strong></p>
<ol>
<li>• Given the numerous vulnerabilities related to conditional
configuration processing based on the evaluation of Java expressions
using the Janino library, support for such expressions has been removed.
Users are offered the an <a
href="https://logback.qos.ch/translator/services/conditionalConfigMigrator.html">online
migration service</a> or the <code>&lt;condition&gt;</code> element
introduced in version 1.5.20. See the <a
href="https://logback.qos.ch/manual/configuration.html#conditional">relevant
documentation</a> for more details.</li>
</ol>
<p>• A bitwise identical binary of this version can be reproduced by
building from source code at commit
c1df7f522e648eec7b4ef6a12c8758fec0f00048 associated with the tag
v_1.5.37. Release built using Java &quot;21&quot; 2023-10-17 LTS build
21.0.1.+12-LTS-29 under Linux Debian 11.6.</p>
<h2>Logback 1.5.36</h2>
<p><strong>2026-06-25 Release of logback version 1.5.36</strong></p>
<p>• The 'condition' attribute in <code>&lt;if&gt;</code> elements now
reject certain references that are associated with ACE attacks. This
issue was reported by &quot;yulate&quot; (<a
href="mailto:yulate531@gmail.com.com">yulate531@gmail.com.com</a>) and
registered as <a
href="https://www.cve.org/cverecord?id=CVE-2026-13006">CVE-2026-13006</a>.
<strong>Please note that version 1.5.37 provides the full fix to this
vulnerability.</strong></p>
<p>• A bitwise identical binary of this version can be reproduced by
building from source code at commit
9b94c37562bf25a6a944146701d42ee6c4eee888 associated with the tag
v_1.5.36. Release built using Java &quot;21&quot; 2023-10-17 LTS build
21.0.1.+12-LTS-29 under Linux Debian 11.6.</p>
<h2>Logback 1.5.35</h2>
<p><strong>026-06-23 Release of logback version 1.5.35</strong></p>
<p>• The 'condition' attribute in <code>&lt;if&gt;</code> elements now
rejects unicode escape sequences (\u and \U). This closes a bypass of
the existing prohibition on the new operator in Janino-evaluated
conditions. This issue was reported by IcySun (<a
href="mailto:icysun@qq.com">icysun@qq.com</a>) and registered as <a
href="https://www.cve.org/cverecord?id=CVE-2026-13006">CVE-2026-13006</a>.
<strong>Please note that version 1.5.37 provides the full fix to this
vulnerability.</strong></p>
<p>• Added <code>ConfiguratorRank.AUTHENTICATING</code> (rank 100), the
highest configurator rank, for certified/authenticating configurators
discovered via the ServiceLoader mechanism.
<code>ContextInitializer</code> now requires that at most one such
configurator exist on the classpath; if more than one is found,
initialization aborts with an error.</p>
<p>• <code>ConsoleCharsetPropertyDefiner</code> is no longer shipped.
The Java 21 multi-release compilation of logback-core has been disabled,
which removes this class from the published artifact. Configurations
that referenced
<code>ch.qos.logback.core.property.ConsoleCharsetPropertyDefiner</code>
will need an alternative approach for console charset detection.</p>
<p>• The logback-examples module is now included in artifacts published
to Maven Central.</p>
<p>• <code>JoranConfigurator.makeAnotherInstance()</code> and
<code>DefaultJoranConfigurator.performMultiStepConfigurationFileSearch()</code>
are now protected, allowing derived configurators to override these
methods.</p>
<p>• A bitwise identical binary of this version can be reproduced by
building from source code at commit
08bd1598d565d83444f72983935e7da4746783b7 associated with the tag
v_1.5.35. Release built using Java &quot;21&quot; 2023-10-17 LTS build
21.0.1.+12-LTS-29 under Linux Debian 11.6.</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/qos-ch/logback/commit/c1df7f522e648eec7b4ef6a12c8758fec0f00048"><code>c1df7f5</code></a>
prepare release 1.5.37</li>
<li><a
href="https://github.com/qos-ch/logback/commit/a1899674579c67711a4fff6bdc569f4bfb25ead5"><code>a189967</code></a>
remove conditional based on janino</li>
<li><a
href="https://github.com/qos-ch/logback/commit/aaa905292dc24235a0cd7514c4815d0eeb6c0446"><code>aaa9052</code></a>
start work on 1.5.37-SNAPSHOT</li>
<li><a
href="https://github.com/qos-ch/logback/commit/9b94c37562bf25a6a944146701d42ee6c4eee888"><code>9b94c37</code></a>
prepare release 1.5.36</li>
<li><a
href="https://github.com/qos-ch/logback/commit/e6a8280ba2c61a448226bccbced70444aaa6e7eb"><code>e6a8280</code></a>
prevent attacks using disallowed references</li>
<li><a
href="https://github.com/qos-ch/logback/commit/24c4b63f60e5bbfa591c20cf39f2ce50ff8cff4f"><code>24c4b63</code></a>
start work on 1.5.36-SNAPSHOT</li>
<li><a
href="https://github.com/qos-ch/logback/commit/08bd1598d565d83444f72983935e7da4746783b7"><code>08bd159</code></a>
preapre release 1.5.35</li>
<li><a
href="https://github.com/qos-ch/logback/commit/37d256b825fc62b4a3908fa29d8b4e34acf79ed0"><code>37d256b</code></a>
indentation changes only</li>
<li><a
href="https://github.com/qos-ch/logback/commit/d3d73078afbb0691423f60a066d77503fdf05fc3"><code>d3d7307</code></a>
minor comment</li>
<li><a
href="https://github.com/qos-ch/logback/commit/fa0411a9393282ba69396ce65f122d281c079ac0"><code>fa0411a</code></a>
radomize file location</li>
<li>Additional commits viewable in <a
href="https://github.com/qos-ch/logback/compare/v_1.5.34...v_1.5.37">compare
view</a></li>
</ul>
</details>
<br />

Updates `ch.qos.logback:logback-core` from 1.5.34 to 1.5.37
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/qos-ch/logback/releases">ch.qos.logback:logback-core's
releases</a>.</em></p>
<blockquote>
<h2>Logback 1.5.37</h2>
<p><strong>2026-06-26 Release of logback version 1.5.37</strong></p>
<ol>
<li>• Given the numerous vulnerabilities related to conditional
configuration processing based on the evaluation of Java expressions
using the Janino library, support for such expressions has been removed.
Users are offered the an <a
href="https://logback.qos.ch/translator/services/conditionalConfigMigrator.html">online
migration service</a> or the <code>&lt;condition&gt;</code> element
introduced in version 1.5.20. See the <a
href="https://logback.qos.ch/manual/configuration.html#conditional">relevant
documentation</a> for more details.</li>
</ol>
<p>• A bitwise identical binary of this version can be reproduced by
building from source code at commit
c1df7f522e648eec7b4ef6a12c8758fec0f00048 associated with the tag
v_1.5.37. Release built using Java &quot;21&quot; 2023-10-17 LTS build
21.0.1.+12-LTS-29 under Linux Debian 11.6.</p>
<h2>Logback 1.5.36</h2>
<p><strong>2026-06-25 Release of logback version 1.5.36</strong></p>
<p>• The 'condition' attribute in <code>&lt;if&gt;</code> elements now
reject certain references that are associated with ACE attacks. This
issue was reported by &quot;yulate&quot; (<a
href="mailto:yulate531@gmail.com.com">yulate531@gmail.com.com</a>) and
registered as <a
href="https://www.cve.org/cverecord?id=CVE-2026-13006">CVE-2026-13006</a>.
<strong>Please note that version 1.5.37 provides the full fix to this
vulnerability.</strong></p>
<p>• A bitwise identical binary of this version can be reproduced by
building from source code at commit
9b94c37562bf25a6a944146701d42ee6c4eee888 associated with the tag
v_1.5.36. Release built using Java &quot;21&quot; 2023-10-17 LTS build
21.0.1.+12-LTS-29 under Linux Debian 11.6.</p>
<h2>Logback 1.5.35</h2>
<p><strong>026-06-23 Release of logback version 1.5.35</strong></p>
<p>• The 'condition' attribute in <code>&lt;if&gt;</code> elements now
rejects unicode escape sequences (\u and \U). This closes a bypass of
the existing prohibition on the new operator in Janino-evaluated
conditions. This issue was reported by IcySun (<a
href="mailto:icysun@qq.com">icysun@qq.com</a>) and registered as <a
href="https://www.cve.org/cverecord?id=CVE-2026-13006">CVE-2026-13006</a>.
<strong>Please note that version 1.5.37 provides the full fix to this
vulnerability.</strong></p>
<p>• Added <code>ConfiguratorRank.AUTHENTICATING</code> (rank 100), the
highest configurator rank, for certified/authenticating configurators
discovered via the ServiceLoader mechanism.
<code>ContextInitializer</code> now requires that at most one such
configurator exist on the classpath; if more than one is found,
initialization aborts with an error.</p>
<p>• <code>ConsoleCharsetPropertyDefiner</code> is no longer shipped.
The Java 21 multi-release compilation of logback-core has been disabled,
which removes this class from the published artifact. Configurations
that referenced
<code>ch.qos.logback.core.property.ConsoleCharsetPropertyDefiner</code>
will need an alternative approach for console charset detection.</p>
<p>• The logback-examples module is now included in artifacts published
to Maven Central.</p>
<p>• <code>JoranConfigurator.makeAnotherInstance()</code> and
<code>DefaultJoranConfigurator.performMultiStepConfigurationFileSearch()</code>
are now protected, allowing derived configurators to override these
methods.</p>
<p>• A bitwise identical binary of this version can be reproduced by
building from source code at commit
08bd1598d565d83444f72983935e7da4746783b7 associated with the tag
v_1.5.35. Release built using Java &quot;21&quot; 2023-10-17 LTS build
21.0.1.+12-LTS-29 under Linux Debian 11.6.</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/qos-ch/logback/commit/c1df7f522e648eec7b4ef6a12c8758fec0f00048"><code>c1df7f5</code></a>
prepare release 1.5.37</li>
<li><a
href="https://github.com/qos-ch/logback/commit/a1899674579c67711a4fff6bdc569f4bfb25ead5"><code>a189967</code></a>
remove conditional based on janino</li>
<li><a
href="https://github.com/qos-ch/logback/commit/aaa905292dc24235a0cd7514c4815d0eeb6c0446"><code>aaa9052</code></a>
start work on 1.5.37-SNAPSHOT</li>
<li><a
href="https://github.com/qos-ch/logback/commit/9b94c37562bf25a6a944146701d42ee6c4eee888"><code>9b94c37</code></a>
prepare release 1.5.36</li>
<li><a
href="https://github.com/qos-ch/logback/commit/e6a8280ba2c61a448226bccbced70444aaa6e7eb"><code>e6a8280</code></a>
prevent attacks using disallowed references</li>
<li><a
href="https://github.com/qos-ch/logback/commit/24c4b63f60e5bbfa591c20cf39f2ce50ff8cff4f"><code>24c4b63</code></a>
start work on 1.5.36-SNAPSHOT</li>
<li><a
href="https://github.com/qos-ch/logback/commit/08bd1598d565d83444f72983935e7da4746783b7"><code>08bd159</code></a>
preapre release 1.5.35</li>
<li><a
href="https://github.com/qos-ch/logback/commit/37d256b825fc62b4a3908fa29d8b4e34acf79ed0"><code>37d256b</code></a>
indentation changes only</li>
<li><a
href="https://github.com/qos-ch/logback/commit/d3d73078afbb0691423f60a066d77503fdf05fc3"><code>d3d7307</code></a>
minor comment</li>
<li><a
href="https://github.com/qos-ch/logback/commit/fa0411a9393282ba69396ce65f122d281c079ac0"><code>fa0411a</code></a>
radomize file location</li>
<li>Additional commits viewable in <a
href="https://github.com/qos-ch/logback/compare/v_1.5.34...v_1.5.37">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: JB Onofré <jbonofre@apache.org>
1 file changed
tree: a2d1b30bd501a00b8b0bb4dd673f34f285715b1f
  1. .github/
  2. .mvn/
  3. adapter/
  4. algorithm/
  5. arrow-format/
  6. arrow-variant/
  7. bom/
  8. c/
  9. ci/
  10. compression/
  11. dataset/
  12. dev/
  13. docs/
  14. flight/
  15. format/
  16. gandiva/
  17. memory/
  18. performance/
  19. tools/
  20. vector/
  21. .asf.yaml
  22. .cmake-format.py
  23. .editorconfig
  24. .env
  25. .gitattributes
  26. .gitignore
  27. .gitmodules
  28. .pre-commit-config.yaml
  29. api-changes.md
  30. Brewfile
  31. CMakeLists.txt
  32. CODE_OF_CONDUCT.md
  33. compose.yaml
  34. CONTRIBUTING.md
  35. LICENSE.txt
  36. NOTICE.txt
  37. pom.xml
  38. README.md
README.md

Arrow Java

Getting Started

The following guides explain the fundamental data structures used in the Java implementation of Apache Arrow.

  • ValueVector is an abstraction that is used to store a sequence of values having the same type in an individual column.
  • VectorSchemaRoot is a container that can hold multiple vectors based on a schema.
  • The Reading/Writing IPC formats guide explains how to stream record batches as well as serializing record batches to files.

Generated javadoc documentation is available here.

Building from source

Refer to Building Apache Arrow for documentation of environment setup and build instructions.

Flatbuffers dependency

Arrow uses Google's Flatbuffers to transport metadata. The java version of the library requires the generated flatbuffer classes can only be used with the same version that generated them. Arrow packages a version of the arrow-vector module that shades flatbuffers and arrow-format into a single JAR. Using the classifier “shade-format-flatbuffers” in your pom.xml will make use of this JAR, you can then exclude/resolve the original dependency to a version of your choosing.

Updating the flatbuffers generated code

  1. Verify that your version of flatc matches the declared dependency:
$ flatc --version
flatc version 25.1.24

$ grep "dep.fbs.version" pom.xml
    <dep.fbs.version>25.1.24</dep.fbs.version>
  1. Generate the flatbuffer java files by performing the following:
cd $ARROW_HOME

# remove the existing files
rm -rf format/src

# regenerate from the .fbs files
flatc --java -o format/src/main/java arrow-format/*.fbs

# prepend license header
mvn spotless:apply -pl :arrow-format

Performance Tuning

There are several system/environmental variables that users can configure. These trade off safety (they turn off checking) for speed. Typically they are only used in production settings after the code has been thoroughly tested without using them.

  • Bounds Checking for memory accesses: Bounds checking is on by default. You can disable it by setting either the system property(arrow.enable_unsafe_memory_access) or the environmental variable (ARROW_ENABLE_UNSAFE_MEMORY_ACCESS) to true. When both the system property and the environmental variable are set, the system property takes precedence.

  • null checking for gets: ValueVector get methods (not getObject) methods by default verify the slot is not null. You can disable it by setting either the system property(arrow.enable_null_check_for_get) or the environmental variable (ARROW_ENABLE_NULL_CHECK_FOR_GET) to false. When both the system property and the environmental variable are set, the system property takes precedence.

Java Properties

  • -Dio.netty.tryReflectionSetAccessible=true should be set. This fixes java.lang.UnsupportedOperationException: sun.misc.Unsafe or java.nio.DirectByteBuffer.(long, int) not available. thrown by Netty.
  • To support duplicate fields in a StructVector enable -Darrow.struct.conflict.policy=CONFLICT_APPEND. Duplicate fields are ignored (CONFLICT_REPLACE) by default and overwritten. To support different policies for conflicting or duplicate fields set this JVM flag or use the correct static constructor methods for StructVectors.

Java Code Style Guide

Arrow Java follows the Google Java Style Guide with the following differences:

  • Imports are grouped, from top to bottom, in this order: static imports, standard Java, org.*, com.*
  • Line length can be up to 120 characters
  • Operators for line wrapping are at end-of-line
  • Naming rules for methods, parameters, etc. have been relaxed
  • Disabled NoFinalizer, OverloadMethodsDeclarationOrder, and VariableDeclarationUsageDistance due to the existing code base. These rules should be followed when possible.

Refer to checkstyle.xml for rule specifics.

Test Logging Configuration

When running tests, Arrow Java uses the Logback logger with SLF4J. By default, it uses the logback.xml present in the corresponding module's src/test/resources directory, which has the default log level set to INFO. Arrow Java can be built with an alternate logback configuration file using the following command run in the project root directory:

mvn -Dlogback.configurationFile=file:<path-of-logback-file>

See Logback Configuration for more details.

Integration Tests

Integration tests which require more time or more memory can be run by activating the integration-tests profile. This activates the Maven Failsafe plugin and any class prefixed with IT will be run during the testing phase. The integration tests currently require a larger amount of memory (>4GB) and time to complete. To activate the profile:

mvn -Pintegration-tests <rest of mvn arguments>