Hi all, I'd like to start a discussion on FLIP-607, which proposes migrating Flink off the end-of-life OkHttp 3.x line and keeping OkHttp off the core classpath [1]
Motivation, in short: - Flink is pinned on OkHttp 3.14.9. It bundles okio 1.17.2, which carries CVE-2023-3635 and flags on every scanner/SBOM. - The pin blocks dependency modernization: the Fabric8 Kubernetes client can't advance past 7.5, because from Fabric8 7.6.0 the OkHttp adapter is compiled against the OkHttp 5 API. So flink-kubernetes is stuck on Fabric8 7.3.1. Proposal, in short: - Switch flink-kubernetes from kubernetes-httpclient-okhttp to kubernetes-httpclient-jdk (the built-in java.net.http client) - Add Maven enforcer rules that forbid OkHttp on the core / flink-dist classpath and ban EOL OkHttp 3.x globally, while allowing isolated plugin/uber-jars to keep a maintained OkHttp where genuinely needed. One point worth flagging up front for reviewers: the JDK HttpClient has a documented limitation where WebSocket requests, which is explained in more detail in the FLIP. That's why the FLIP proposes a minimum Java 11.0.19. Looking forward to your feedback. Thanks, Martijn [1] https://cwiki.apache.org/confluence/spaces/FLINK/pages/449282641/FLIP-607+Migrate+Flink+off+end-of-life+OkHttp+keep+it+off+the+core+classpath
