Skip to content

Conversation

dannycranmer
Copy link
Contributor

What is the purpose of the change

Upgrade Guava dependency for Flink Connector Kinesis. The connector was using Guava 18.0 which is quite old and has been flagged by some security tools as noted in another ticket https://issues.apache.org/jira/browse/FLINK-22774

This PR also makes the flink-sql-connector-kinesis use the Guava dependency transitively through the flink-connector-kinesis dependency.

Brief change log

  • Bumped Guava for Flink Connector Kinesis from 18.0 (inherited from parent) to 29.0-jre

Verifying this change

This change is already covered by existing tests, such as FlinkKinesisProducerTest.

Does this pull request potentially affect one of the following parts:

  • Dependencies (does it add or upgrade a dependency): yes
  • The public API, i.e., is any changed class annotated with @Public(Evolving): no
  • The serializers: no
  • The runtime per-record code paths (performance sensitive): no
  • Anything that affects deployment or recovery: JobManager (and its components), Checkpointing, Kubernetes/Yarn/Mesos, ZooKeeper: no
  • The S3 file system connector: no

Documentation

  • Does this pull request introduce a new feature? no
  • If yes, how is the feature documented? not applicable

iemre and others added 2 commits June 25, 2021 22:28
Also make flink-sql-connector-kinesis use the Guava library
coming transitively from the connector-kinesis dependency.
@flinkbot
Copy link
Collaborator

flinkbot commented Jun 25, 2021

Thanks a lot for your contribution to the Apache Flink project. I'm the @flinkbot. I help the community
to review your pull request. We will use this comment to track the progress of the review.

Automated Checks

Last check on commit a39fe2a (Thu Sep 23 17:52:12 UTC 2021)

Warnings:

  • 2 pom.xml files were touched: Check for build and licensing issues.
  • No documentation files were touched! Remember to keep the Flink docs up to date!

Mention the bot in a comment to re-run the automated checks.

Review Progress

  • ❓ 1. The [description] looks good.
  • ❓ 2. There is [consensus] that the contribution should go into to Flink.
  • ❓ 3. Needs [attention] from.
  • ❓ 4. The change fits into the overall [architecture].
  • ❓ 5. Overall code [quality] is good.

Please see the Pull Request Review Guide for a full explanation of the review process.


The Bot is tracking the review progress through labels. Labels are applied according to the order of the review items. For consensus, approval by a Flink committer of PMC member is required Bot commands
The @flinkbot bot supports the following commands:

  • @flinkbot approve description to approve one or more aspects (aspects: description, consensus, architecture and quality)
  • @flinkbot approve all to approve all aspects
  • @flinkbot approve-until architecture to approve everything until architecture
  • @flinkbot attention @username1 [@username2 ..] to require somebody's attention
  • @flinkbot disapprove architecture to remove an approval you gave earlier

@flinkbot
Copy link
Collaborator

flinkbot commented Jun 25, 2021

CI report:

Bot commands The @flinkbot bot supports the following commands:
  • @flinkbot run travis re-run the last Travis build
  • @flinkbot run azure re-run the last Azure build

Copy link
Contributor

@iemre iemre left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

@dannycranmer dannycranmer merged commit d64674f into apache:release-1.13 Jun 28, 2021
@dannycranmer dannycranmer deleted the FLINK-23009 branch June 28, 2021 06:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants