Martijn Visser created FLINK-40730:
--------------------------------------

             Summary: Remove the Derby dialect now that Derby is retired and 
replace it with H2
                 Key: FLINK-40730
                 URL: https://issues.apache.org/jira/browse/FLINK-40730
             Project: Flink
          Issue Type: Technical Debt
          Components: Connectors / JDBC
            Reporter: Martijn Visser


The Derby developers voted on 2025-10-10 to retire the project into a read-only 
state, so
development has ended and no further releases will be published:
https://issues.apache.org/jira/browse/DERBY-7177

We ship a Derby dialect. {{DerbyFactory}} is registered in the {{JdbcFactory}} 
service file of
{{flink-connector-jdbc-core}} and Derby is listed in 
{{docs/content/docs/connectors/table/jdbc.md}}.
It is also the embedded database behind roughly twenty test classes in that 
module.

CVE-2022-46337 will not be fixed for us. The fix was backported to the 10.14, 
10.15 and 10.16 branches but no release was ever cut from any of them, and none 
ever will be. The only released artifact carrying it is {{10.17.1.0}}, which 
needs Java 21 while we build and test on JDK 17. Nothing is exposed today, the 
CVE is an LDAP injection in the authenticator and we run {{jdbc:derby:memory:}} 
without authentication, but the dialect now rests on a dead project.

This probably needs a short discussion (not necessarily a FLIP because I think 
no-one uses Derby in production workloads, only for testing) on dev@, but I'd 
be +1 for replacing Derby with H2. There is {{H2Metadata}} already, taht 
implements the same {{DatabaseMetadata}} interface and there is a complete H2 
XA wrapper set in the test tree, so an alternative test database is within 
reach. 



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to