- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
2 weeks ago
Hello Databricks Support Team,
We are currently using:
- databricks-sql-connector==4.3.0
- thrift==0.22.0
Our organization's security scanning tool (Prisma) is flagging Thrift 0.22.0 and requires us to upgrade to a newer version (0.23.0 or later).
As part of our analysis, we upgraded Thrift to 0.23.0; however, the application was no longer able to establish a connection using the Databricks SQL Connector. Reverting to Thrift 0.22.0 restored connectivity.
We have also noticed that Apache Thrift 0.24.0 has been released. Since our security requirements mandate the use of a newer Thrift version, the current dependency constraint is creating a compliance challenge.
Could you please advise on the following:
- Are there plans to update the Databricks SQL Connector to support Thrift 0.24.0?
- Is there a newer Databricks SQL Connector version that already supports Thrift 0.24.0 (or later)?
- Is there an estimated timeline for support of newer Thrift versions?
- Do you recommend any workaround that would allow us to remain compliant with security requirements while maintaining Databricks SQL connectivity?
Any guidance or official recommendation would be greatly appreciated, as we need to determine the appropriate remediation path for our security findings.