Details
-
Technical Debt
-
Status: Closed
-
Major
-
Resolution: Fixed
-
1.20.0, 1.19.1, 2.0-preview
Description
Updates Pekko dependency to 1.1.2 which in turn upgrades Netty 3 to 4 (addressing FLINK-29065 and removing several CVEs from Flink). Pekko 1.1 also upgrades other dependencies such as slf4j and Jackson. For more details see the Pekko 1.1 release notes.
Attachments
Issue Links
- causes
-
FLINK-36979 Revert netty bump for 1.20 and 1.19
- Open
- fixes
-
FLINK-29065 Flink v1.15.1 contains netty(version:3.10.6). There are many vulnerabilities, like CVE-2021-21409 etc. please confirm these version and fix. thx
- Closed
- relates to
-
FLINK-33505 switch away from using netty 3 based Pekko Classic Remoting
- Open
-
FLINK-32683 Update Pekko from 1.0.0 to 1.0.1
- Closed
- links to