r-sidd opened a new pull request, #1165: URL: https://github.com/apache/flink-kubernetes-operator/pull/1165
Upgrades Apache Derby from 10.15.2.0 to 10.17.1.0 to address CVE-2022-46337 (LDAP authentication bypass, CVSS 9.8). **Re: NOTICE file** — Derby is declared `<scope>test</scope>` in `flink-autoscaler-standalone` and `flink-autoscaler-plugin-jdbc`. It is not bundled in any release artifact, so no NOTICE update is required per Apache legal guidelines. **Re: Java compatibility** — Derby 10.17.1.0 officially requires Java 21. The modules using Derby are test-only; CI pipelines running these tests may need a Java 21 JDK configured for those modules. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
