chore: update lance dependency to v11.0.0-beta.5 - #3921
Conversation
There was a problem hiding this comment.
Claude Code Review
This repository is configured for manual code reviews. Comment @claude review for a one-time review, or @claude review always to subscribe this PR to a review on every future push.
Tip: disable this comment in your organization's Code Review settings.
The smartstring repo was archived on 2026-05-03 and all versions are affected with no safe upgrade available. It reaches us only through the optional polars feature, which is pinned to >=0.37,<0.40.0. Clearing the advisory requires relaxing that pin and bumping polars, so ignore it for now. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
The Maven distribution blocker is cleared, and the beta.5 Rust and Java integration now verifies locally. The exact RustSec ignore is a reasonable short-term boundary for an informational advisory reachable only through optional Polars, but that feature retains an unmaintained transitive dependency. A dedicated Polars >=0.43 migration removes it; versions 0.40–0.42 do not.
Updates the Lance dependencies and Java lance-core to v11.0.0-beta.5. Includes compatibility fixes for the new concrete file-version API. Lance tag: https://github.com/lance-format/lance/releases/tag/v11.0.0-beta.5