r-sidd opened a new pull request, #1165:
URL: https://github.com/apache/flink-kubernetes-operator/pull/1165

   Upgrades Apache Derby from 10.15.2.0 to 10.17.1.0 to address CVE-2022-46337 
(LDAP authentication bypass, CVSS 9.8).
   
   **Re: NOTICE file** — Derby is declared `<scope>test</scope>` in 
`flink-autoscaler-standalone` and `flink-autoscaler-plugin-jdbc`. It is not 
bundled in any release artifact, so no NOTICE update is required per Apache 
legal guidelines.
   
   **Re: Java compatibility** — Derby 10.17.1.0 officially requires Java 21. 
The modules using Derby are test-only; CI pipelines running these tests may 
need a Java 21 JDK configured for those modules.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to