rmetzger commented on PR #165: URL: https://github.com/apache/flink-shaded/pull/165#issuecomment-5346354891
Flink 1.20 relies on Shaded 17 Flink 2.2 on 20 Flink 2.3 on 21 Technically speaking, Flink 2.2 is still supported by the Flink community, and relies on Flink shaded 20. So if there's a request for fixing a CVE in Flink shaded, it is very helpful that flink-shaded 20 is maintained with bugfix versions. But we intend to maintain the branches even beyond the community support for Flink 2.2 here, because we want to provide the source code to the CVE fixes. There are a number of vendors maintaining Flink distributions (Cloudera, Confluent, AWS, maybe Google, MSFT Azure, Alibaba) and also private companies using Flink that are building their own distros. Sharing the source code of CVE fixes is a totally legitimate thing to do in an open source project. AWS has historically (I don't know if they still do it) provided CVE fixes for unmaintained branches of Flink versions. I find it nice that companies are collaborating on maintaining security fixes for old Flink versions, and I want to lead by giving a good example in the community for how collaboration works in open source. I don't think there is harm for the community in this. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
