LegendPei opened a new pull request, #8119:
URL: https://github.com/apache/incubator-seata/pull/8119
<!--
Licensed to the Apache Software Foundation (ASF) under one or more
contributor license agreements. See the NOTICE file distributed with
this work for additional information regarding copyright ownership.
The ASF licenses this file to You under the Apache License, Version 2.0
(the "License"); you may not use this file except in compliance with
the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
-->
<!-- Please make sure you have read and understood the contributing
guidelines -->
- [ ] I have read the
[CONTRIBUTING.md](https://github.com/apache/incubator-seata/blob/2.x/CONTRIBUTING.md)
guidelines.
- [ ] I have registered the PR
[changes](https://github.com/apache/incubator-seata/tree/2.x/changes).
### Ⅰ. Describe what this PR did
This PR removes the vulnerable MySQL Connector/J references from Seata's
dependency and distribution packaging configuration.
Main changes:
- Replace the managed MySQL Connector/J dependency from
`mysql:mysql-connector-java` to `com.mysql:mysql-connector-j`.
- Remove the release/image packaging logic that copied MySQL driver jars
into the Seata server distribution.
- Remove obsolete MySQL driver version properties used only by the removed
copy strategy.
- Update test-scoped MySQL Connector/J usages to the new coordinates.
- Update affected test imports from legacy MySQL 5 internal classes to MySQL
Connector/J 8 classes.
- Update NOTICE and changelog entries.
This keeps the change scoped to the GHSA/CVE cleanup and aligns with the
point that the distributed binary package should not have a hard dependency on
the MySQL driver.
### Ⅱ. Does this pull request fix one issue?
<!-- If that, add "fixes #xxx" below in the next line, for example, fixes
#97. -->
fixes #8101
### Ⅲ. Why don't you add test cases (unit test/integration test)?
No new unit or integration test is added because this PR mainly removes
packaging-time dependency copying and updates dependency coordinates. The
behavioral code path is unchanged.
Existing test compilation was updated where the MySQL Connector/J upgrade
exposed references to legacy MySQL 5 internal classes.
### Ⅳ. Describe how to verify it
### Ⅴ. Special notes for reviews
The remaining mysql-connector-java matches are only historical changelog
entries. Existing com.mysql.jdbc.Driver string defaults are kept for
compatibility and are not bundled driver dependencies.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]