>From what I can see, the Jackson version bump fixes quite a few
vulnerabilities. Therefore, I'd be +1 to release flink-shaded 9.0.

Thanks for all the work to verify this on master already.

– Ufuk


On Fri, Nov 15, 2019 at 2:26 PM Chesnay Schepler <ches...@apache.org> wrote:

> Hello,
>
> I'd like to kick off the next release for flink-shaded. Background is
> that we recently bumped jackson to 2.10.1 to fix a variety of security
> vulnerabilities, and it would be good to include them in the upcoming
> 1.8.3/1.9.2 releases.
>
> The release would contain few changes beyond the jackson changes;
> flink-shaded can now be compiled on Java 11 and an encoding issue for
> the NOTICE files was fixed.
>
> So overall this should be very little overhead.
>
> I have already verified that the master would work with this version
> (this being a reasonable indicator for it also working in previous
> version).
>
> I'd also appreciate it if someone would volunteer to handle the release;
> I'm quite bogged down at the moment :(
>
> Regards,
>
> Chesnay
>
>

Reply via email to