flyway / flyway-docker

Official Flyway Docker images
Apache License 2.0
215 stars 82 forks source link

Fix vulnerability CVE-2022-46337 #131

Closed sanchayata-jain-cko closed 10 months ago

sanchayata-jain-cko commented 11 months ago

Docker image is affected by a Fixable https://github.com/advisories/GHSA-rcjc-c4pj-xxrp in library 'org.apache.derby:derby' (version 10.16.1.1), resolved by version 10.17.1.0

jmcruz1983 commented 10 months ago

Any update here?

Barry-RG commented 10 months ago

Please see the release notes for Flyway 10.7.1 and details added to the Derby support page. Unfortunately since Flyway cannot currently upgrade to support Java 21 and Derby have not released a fix for their versions which support Java 17, we have had to remove the Derby driver and leave it to the user to make their decision on how to approach this.