[ https://issues.apache.org/jira/browse/KAFKA-15203?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17849776#comment-17849776 ]
Chia-Ping Tsai commented on KAFKA-15203: ---------------------------------------- It seems to me the deprecation cycle is required if all we want to do is to "remove" `ReflectionScanner`. the deprecation will be addressed in 4.0 and so we can remove `ReflectionScanner` in 5.0 > Remove dependency on Reflections > --------------------------------- > > Key: KAFKA-15203 > URL: https://issues.apache.org/jira/browse/KAFKA-15203 > Project: Kafka > Issue Type: Bug > Components: connect > Reporter: Divij Vaidya > Assignee: Ganesh Sadanala > Priority: Major > Labels: newbie > > We currently depend on reflections library which is EOL. Quoting from the > GitHub site: > _> Please note: Reflections library is currently NOT under active development > or maintenance_ > > This poses a supply chain risk for our project where the security fixes and > other major bugs in underlying dependency may not be addressed timely. > Hence, we should plan to remove this dependency. -- This message was sent by Atlassian Jira (v8.20.10#820010)