[
https://issues.apache.org/jira/browse/FLINK-40729?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
ASF GitHub Bot updated FLINK-40729:
-----------------------------------
Labels: pull-request-available (was: )
> Refresh the JDBC driver and test dependency versions raised by Dependabot
> -------------------------------------------------------------------------
>
> Key: FLINK-40729
> URL: https://issues.apache.org/jira/browse/FLINK-40729
> Project: Flink
> Issue Type: Technical Debt
> Components: Connectors / JDBC
> Reporter: Martijn Visser
> Assignee: Martijn Visser
> Priority: Major
> Labels: pull-request-available
> Fix For: jdbc-6.0.0
>
>
> FLINK-40249 overtook the assertj, log4j and PostgreSQL bumps Dependabot
> filed, but {{mssql-jdbc}} and {{derby}} are still open and several drivers
> have drifted as far without Dependabot watching them.
> {{mssql-jdbc}} is on {{10.2.1.jre8}}, inside the affected range of
> CVE-2025-59250, and so is the {{11.2.0.jre8}} that
> apache/flink-connector-jdbc#208 proposes; that branch is fixed from
> {{11.2.4}}. It goes to {{13.6.0.jre8}}, keeping the jre8 classifier so the
> module still builds to Java 8 bytecode. Also {{mysql-connector-j}} 8.2.0 to
> 26.7.0, {{ojdbc8}} 21.8.0.0 to 23.26.3.0.0, {{trino-jdbc}} 418 and its test
> image 451 both to 483, {{oceanbase-client}} 2.4.8 to 2.4.19, {{h2}} 2.2.224
> to 2.5.250, and {{openlineage}} 1.32.0 to 1.53.0 with {{META-INF/NOTICE}}.
> One commit each.
> {{mockito-core}} is removed rather than bumped: the code style guide asks for
> reusable test implementations, it had three users and one was dead code. That
> also settles what blocked a bump, mockito 5 wanting {{objenesis}} 3.3 against
> the 2.1 we pin for {{kryo}}.
> The Trino tests are re-enabled; they were disabled for a Jenkins container
> problem and we run on GitHub Actions. Derby stays at {{10.14.2.0}}
--
This message was sent by Atlassian Jira
(v8.20.10#820010)