Closed zencircle closed 7 months ago
Hi @zencircle, thanks for reporting. The develop
branch already dropped the datasets kedro-org/kedro#2126 so this will be fixed by the upcoming 0.19.0 version.
Said datasets moved to kedro-datasets
, and all the upper bounds of pyarrow have been lifted, except for snowflake https://github.com/kedro-org/kedro-plugins/blob/main/kedro-datasets/setup.py
I'm moving this to the relevant repo.
If I understand correctly, we're still pinning the pyarrow version:
Hi, do we know why we are requiring pyarrow to install the SnowparkTableDataset, which only uses snowpark? I was trying to install the dataset in python 3.11, however pyarrow~=8.0 is only available up to python 3.10.
It was introduced in #148 but I see no rationale for it. @deepyaman do you remember?
Otherwise we could try removing that dependency. @felipemonroy would you like to send a pull request?
Description
Unable to update to
pyarrow>=14.0.1
to fix the vulnerabilities https://nvd.nist.gov/vuln/detail/CVE-2023-47248Context
pyarrow version in the setup file is blocking new version from getting installed https://github.com/kedro-org/kedro/blob/main/setup.py#L47
Steps to Reproduce
Docker compile fails
Expected Result
Actual Result
Your Environment
If I do not specify pyarrow, docker image gets compiled successfully with version 6