rmetzger commented on PR #165:
URL: https://github.com/apache/flink-shaded/pull/165#issuecomment-5346354891

   Flink 1.20 relies on Shaded 17
   Flink 2.2 on 20
   Flink 2.3 on 21
   
   Technically speaking, Flink 2.2 is still supported by the Flink community, 
and relies on Flink shaded 20. So if there's a request for fixing a CVE in 
Flink shaded, it is very helpful that flink-shaded 20 is maintained with bugfix 
versions.
   
   But we intend to maintain the branches even beyond the community support for 
Flink 2.2 here, because we want to provide the source code to the CVE fixes. 
There are a number of vendors maintaining Flink distributions (Cloudera, 
Confluent, AWS, maybe Google, MSFT Azure, Alibaba) and also private companies 
using Flink that are building their own distros. Sharing the source code of CVE 
fixes is a totally legitimate thing to do in an open source project.
   AWS has historically (I don't know if they still do it) provided CVE fixes 
for unmaintained branches of Flink versions. I find it nice that companies are 
collaborating on maintaining security fixes for old Flink versions, and I want 
to lead by giving a good example in the community for how collaboration works 
in open source.
   I don't think there is harm for the community in this.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to