[ 
https://issues.apache.org/jira/browse/FLINK-37672?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Martijn Visser resolved FLINK-37672.
------------------------------------
    Fix Version/s: 2.4.0
       Resolution: Fixed

Fixed in apache/flink:master 687ef8c43630a1691ba2d87c6430635adce31b86

> Replace protoc-jar and xolstice protobuf plugins with ascopes 
> protobuf-maven-plugin
> -----------------------------------------------------------------------------------
>
>                 Key: FLINK-37672
>                 URL: https://issues.apache.org/jira/browse/FLINK-37672
>             Project: Flink
>          Issue Type: Improvement
>          Components: Build System
>            Reporter: Siddharth R
>            Assignee: Martijn Visser
>            Priority: Major
>              Labels: pull-request-available
>             Fix For: 2.4.0
>
>
> Flink generates Java code from .proto files with two Maven plugins that are 
> no longer maintained: protoc-jar-maven-plugin in flink-python and 
> flink-protobuf (last release 2020), and the xolstice protobuf-maven-plugin in 
> flink-parquet (archived, last release 2018). The reported CVEs are in the 
> plugin's build-time dependencies only; bumping to 0.6.1 would still leave us 
> on an archived plugin.
> We should replace both with https://github.com/ascopes/protobuf-maven-plugin. 
> It resolves protoc per platform without os-maven-plugin, registers the 
> generated sources itself, and sets the executable bit on protoc every run, 
> which removes the workaround from FLINK-11427 and FLINK-19616 in 
> flink-parquet and unpack_build_artifact.sh. Versions 4.0.0 and later require 
> Java 17, so we stay on 3.10.3 while Flink builds on JDK 11.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to