Skip to content

[FLINK-38466] Bump derby from 10.15.2.0 to 10.17.1.0#1165

Open
r-sidd wants to merge 1 commit into
apache:mainfrom
r-sidd:FLINK-38466-bump-derby
Open

[FLINK-38466] Bump derby from 10.15.2.0 to 10.17.1.0#1165
r-sidd wants to merge 1 commit into
apache:mainfrom
r-sidd:FLINK-38466-bump-derby

Conversation

@r-sidd

@r-sidd r-sidd commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

What is the purpose of the change

Bump derby version to 10.17.1.0

Brief change log

The current version 10.15.2.0 has a direct vulnerability - CVE-2022-46337. To remediate this, upgrade to latest 10.17.1.0

Current - Maven Repository: org.apache.derby » derby » 10.15.2.0

Latest - Maven Repository: org.apache.derby » derby » 10.17.1.0

FYI: The derby release notes mentioned that "support for java versions earlier than 21 were removed." Derby's scope is mainly for Integration tests. Local testing showed successful build.

Note: Derby is declared <scope>test</scope> and is not bundled in any release artifact, so no NOTICE update is required per Apache legal guidelines.

Verifying this change

This change is a trivial rework / code cleanup without any test coverage.

Does this pull request potentially affect one of the following parts:

  • Dependencies (does it add or upgrade a dependency): yes
  • The public API, i.e., is any changes to the CustomResourceDescriptors: no
  • Core observer or reconciler logic that is regularly executed: no

Documentation

  • Does this pull request introduce a new feature? no
  • If yes, how is the feature documented? not applicable

Upgrades Apache Derby from 10.15.2.0 to 10.17.1.0 to address
CVE-2022-46337 (LDAP authentication bypass, CVSS 9.8).

Derby is used as a test-scoped embedded database in
flink-autoscaler-standalone and flink-autoscaler-plugin-jdbc.
It is not bundled in any release artifact, so no NOTICE update
is required per Apache legal guidelines.

Note: Derby 10.17.1.0 officially requires Java 21. CI pipelines
running these modules' tests may need to be updated accordingly.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant