[
https://issues.apache.org/jira/browse/FLINK-37672?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Martijn Visser resolved FLINK-37672.
------------------------------------
Fix Version/s: 2.4.0
Resolution: Fixed
Fixed in apache/flink:master 687ef8c43630a1691ba2d87c6430635adce31b86
> Replace protoc-jar and xolstice protobuf plugins with ascopes
> protobuf-maven-plugin
> -----------------------------------------------------------------------------------
>
> Key: FLINK-37672
> URL: https://issues.apache.org/jira/browse/FLINK-37672
> Project: Flink
> Issue Type: Improvement
> Components: Build System
> Reporter: Siddharth R
> Assignee: Martijn Visser
> Priority: Major
> Labels: pull-request-available
> Fix For: 2.4.0
>
>
> Flink generates Java code from .proto files with two Maven plugins that are
> no longer maintained: protoc-jar-maven-plugin in flink-python and
> flink-protobuf (last release 2020), and the xolstice protobuf-maven-plugin in
> flink-parquet (archived, last release 2018). The reported CVEs are in the
> plugin's build-time dependencies only; bumping to 0.6.1 would still leave us
> on an archived plugin.
> We should replace both with https://github.com/ascopes/protobuf-maven-plugin.
> It resolves protoc per platform without os-maven-plugin, registers the
> generated sources itself, and sets the executable bit on protoc every run,
> which removes the workaround from FLINK-11427 and FLINK-19616 in
> flink-parquet and unpack_build_artifact.sh. Versions 4.0.0 and later require
> Java 17, so we stay on 3.10.3 while Flink builds on JDK 11.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)