clickhouse-java icon indicating copy to clipboard operation
clickhouse-java copied to clipboard

Cleanup dependencies

Open chernser opened this issue 1 year ago • 0 comments

Describe the bug

There are some confusing dependencies. For example, clickhouse-jdbc (https://mvnrepository.com/artifact/com.clickhouse/clickhouse-jdbc) has:

  • com.clickhouse » org.apache.commons.compress 1.9.2
  • com.clickhouse » io.grpc 1.9.2
  • com.clickhouse » org.roaringbitmap 1.9.2

What confuses:

  • version.
  • org.apache.commons.compress - this package had vulnerabilities in early versions

chernser avatar Jul 24 '24 17:07 chernser