[jira] [Created] (FLINK-22706) The NOTICE file of Flink repo should be updated

classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view
|

[jira] [Created] (FLINK-22706) The NOTICE file of Flink repo should be updated

Shang Yuanchun (Jira)
Fuyao Li created FLINK-22706:
--------------------------------

             Summary: The NOTICE file of Flink repo should be updated
                 Key: FLINK-22706
                 URL: https://issues.apache.org/jira/browse/FLINK-22706
             Project: Flink
          Issue Type: Bug
    Affects Versions: 1.12.3, 1.13.0, 1.12.2, 1.12.1
            Reporter: Fuyao Li


With the PR introduced in [1], flink documentation is upgraded to Hugo instead of Jekyll. However, we fail to update the NOTICE file. [2]

 

The jQuery, bootstrap dependencies are not used anymore and AnchorJS JS library path should also be updated.

 

In addition, bootstrap version 3.3.4 is known to have security vulnerabilities. See link [3]. This could cause legal approval rejection while adopting Apache Flink. (I am facing such a issue.)

 

I can create a pull request to fix this. Please assign the task to me.

 

[1] https://issues.apache.org/jira/browse/FLINK-21193

[2] [https://github.com/apache/flink/blob/master/NOTICE#L10]

[3]https://snyk.io/test/npm/bootstrap/3.3.4



--
This message was sent by Atlassian Jira
(v8.3.4#803005)