LegendPei opened a new pull request, #8119:
URL: https://github.com/apache/incubator-seata/pull/8119

   <!--
       Licensed to the Apache Software Foundation (ASF) under one or more
       contributor license agreements.  See the NOTICE file distributed with
       this work for additional information regarding copyright ownership.
       The ASF licenses this file to You under the Apache License, Version 2.0
       (the "License"); you may not use this file except in compliance with
       the License.  You may obtain a copy of the License at
   
       http://www.apache.org/licenses/LICENSE-2.0
       
       Unless required by applicable law or agreed to in writing, software
       distributed under the License is distributed on an "AS IS" BASIS,
       WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
       See the License for the specific language governing permissions and
       limitations under the License.
   -->
   <!-- Please make sure you have read and understood the contributing 
guidelines -->
   
   - [ ] I have read the 
[CONTRIBUTING.md](https://github.com/apache/incubator-seata/blob/2.x/CONTRIBUTING.md)
 guidelines.
   - [ ] I have registered the PR 
[changes](https://github.com/apache/incubator-seata/tree/2.x/changes).
   
   ### Ⅰ. Describe what this PR did
   This PR removes the vulnerable MySQL Connector/J references from Seata's 
dependency and distribution packaging configuration.
   
   Main changes:
   - Replace the managed MySQL Connector/J dependency from 
`mysql:mysql-connector-java` to `com.mysql:mysql-connector-j`.
   - Remove the release/image packaging logic that copied MySQL driver jars 
into the Seata server distribution.
   - Remove obsolete MySQL driver version properties used only by the removed 
copy strategy.
   - Update test-scoped MySQL Connector/J usages to the new coordinates.
   - Update affected test imports from legacy MySQL 5 internal classes to MySQL 
Connector/J 8 classes.
   - Update NOTICE and changelog entries.
   
   This keeps the change scoped to the GHSA/CVE cleanup and aligns with the 
point that the distributed binary package should not have a hard dependency on 
the MySQL driver.
   
   
   ### Ⅱ. Does this pull request fix one issue?
   <!-- If that, add "fixes #xxx" below in the next line, for example, fixes 
#97. -->
   fixes #8101
   
   ### Ⅲ. Why don't you add test cases (unit test/integration test)? 
   
   No new unit or integration test is added because this PR mainly removes 
packaging-time dependency copying and updates dependency coordinates. The 
behavioral code path is unchanged.
   
   Existing test compilation was updated where the MySQL Connector/J upgrade 
exposed references to legacy MySQL 5 internal classes.
   
   
   ### Ⅳ. Describe how to verify it
   
   
   ### Ⅴ. Special notes for reviews
   
   The remaining mysql-connector-java matches are only historical changelog 
entries. Existing com.mysql.jdbc.Driver string defaults are kept for 
compatibility and are not bundled driver dependencies.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to