Skip to content

Build against datasketches-cpp 5.3.0 - #72

Merged
leerho merged 1 commit into
mainfrom
cpp-5.3.0
Oct 10, 2026
Merged

leerho merged 1 commit into
mainfrom
cpp-5.3.0

Conversation

@leerho

@leerho leerho commented Oct 10, 2026

Copy link
Copy Markdown
Member

Moves the bundled C++ library from 5.2.0 to 5.3.0 (GIT_TAG in CMakeLists.txt).

C++ 5.3.0 fixes five vulnerabilities in sketch deserialization (CVE-2026-103501, CVE-2026-103513, CVE-2026-103634, CVE-2026-103635, CVE-2026-103636; see https://datasketches.apache.org/docs/Community/Security.html). The Python package compiles that C++ code in, so current datasketches-python releases are affected until a release built on 5.3.0 ships.

Binding changes required by 5.3.0

Two C++ member functions gained a defaulted parameter. Default arguments are not part of a member-function pointer, so the bindings that take their address broke:

Also

Built locally on macOS with Python 3.12; all 37 tests pass.

🤖 Generated with Claude Code

C++ 5.3.0 fixes five deserialization vulnerabilities (CVE-2026-103501,
-103513, -103634, -103635, -103636), which this package inherits.

Two C++ member functions gained a defaulted parameter, which breaks the
bindings that take their address:
- update_theta_sketch::compact(ordered, trim): expose trim=False. Without
  a second nb::arg the build fails.
- hll_sketch::reset(full_size): expose full_size=False. Without an
  nb::arg, reset() required an argument and test_hll_* failed.

Also bind the new frequent_items_sketch::reset(). Adds tests for all three.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@leerho
leerho requested review from proost and tisonkun October 10, 2026 17:34
@leerho
leerho merged commit 9db62ef into main Oct 10, 2026
6 checks passed
@leerho
leerho deleted the cpp-5.3.0 branch October 10, 2026 19:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants