[FLINK-36602][table] Backport: override json-path version for calcite 1.32 #25613
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What is the purpose of the change
This is a backport of #25602.
There is a high severity CVE (CVE-2023-1370) in the json-path version used by Calcite 1.32 used in the
flink-table-calcite-bridge
module.Newer versions of Calcite update to newer versions of
json-path
. However, updating Calcite to the latest version (FLINK-36602) is not straightforward and involves changes to the SQL parsing logic. Following discussion on the dev mailing list, an incremental Calcite upgrade process is preferred. Therefore, this PR simply patches the transitive dependency.Brief change log
This PR overrides the specific transitive
json-path
(version 2.7.0) dependency in theflink-table-calcite-bridge
pom file to version 2.9.0.Verifying this change
This change is already covered by existing tests in the
flink-table
module.Does this pull request potentially affect one of the following parts:
@Public(Evolving)
: noDocumentation