-
Notifications
You must be signed in to change notification settings - Fork 1.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bump Tika from 2.4.0 to 2.5.0 addressing CVE-2022-33879. #4791
Bump Tika from 2.4.0 to 2.5.0 addressing CVE-2022-33879. #4791
Conversation
Signed-off-by: Marc Handalian <handalm@amazon.com>
Gradle Check (Jenkins) Run Completed with:
|
Signed-off-by: Marc Handalian <handalm@amazon.com>
CHANGELOG.md
Outdated
@@ -55,6 +55,7 @@ Inspired from [Keep a Changelog](https://keepachangelog.com/en/1.0.0/) | |||
- Bumps `hadoop-hdfs` from 3.3.3 to 3.3.4 ([#4644](https://github.com/opensearch-project/OpenSearch/pull/4644)) | |||
- Bumps `jna` from 5.11.0 to 5.12.1 ([#4656](https://github.com/opensearch-project/OpenSearch/pull/4656)) | |||
- Update Jackson Databind to 2.13.4.2 (addressing CVE-2022-42003) ([#4779](https://github.com/opensearch-project/OpenSearch/pull/4779)) | |||
- Bumps `tika` from 2.4.0 to 2.5.0 ([#]()) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
PR info is missing from the change.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
updated now.
Signed-off-by: Marc Handalian <handalm@amazon.com>
Gradle Check (Jenkins) Run Completed with:
|
Gradle Check (Jenkins) Run Completed with:
|
The backport to
To backport manually, run these commands in your terminal: # Fetch latest updates from GitHub
git fetch
# Create a new working tree
git worktree add .worktrees/backport-2.x 2.x
# Navigate to the new working tree
cd .worktrees/backport-2.x
# Create a new branch
git switch --create backport/backport-4791-to-2.x
# Cherry-pick the merged commit of this pull request and resolve the conflicts
git cherry-pick -x --mainline 1 f1995b951abab34935bf8e5dee91097efbf5503e
# Push it to GitHub
git push --set-upstream origin backport/backport-4791-to-2.x
# Go back to the original working tree
cd ../..
# Delete the working tree
git worktree remove .worktrees/backport-2.x Then, create a pull request where the |
…project#4791) * Bump Tika from 2.4.0 to 2.5.0 addressing CVE-2022-33879. Signed-off-by: Marc Handalian <handalm@amazon.com> * Add missing SHAs. Signed-off-by: Marc Handalian <handalm@amazon.com> * Update changelog with PR info. Signed-off-by: Marc Handalian <handalm@amazon.com> Signed-off-by: Marc Handalian <handalm@amazon.com> (cherry picked from commit f1995b9)
…project#4791) * Bump Tika from 2.4.0 to 2.5.0 addressing CVE-2022-33879. Signed-off-by: Marc Handalian <handalm@amazon.com> * Add missing SHAs. Signed-off-by: Marc Handalian <handalm@amazon.com> * Update changelog with PR info. Signed-off-by: Marc Handalian <handalm@amazon.com> Signed-off-by: Marc Handalian <handalm@amazon.com> (cherry picked from commit f1995b9)
Manual backport to 2.x #4794 |
* Bump Tika from 2.4.0 to 2.5.0 addressing CVE-2022-33879. Signed-off-by: Marc Handalian <handalm@amazon.com> * Add missing SHAs. Signed-off-by: Marc Handalian <handalm@amazon.com> * Update changelog with PR info. Signed-off-by: Marc Handalian <handalm@amazon.com> Signed-off-by: Marc Handalian <handalm@amazon.com> (cherry picked from commit f1995b9) Signed-off-by: Vacha Shah <vachshah@amazon.com>
…project#4791) * Bump Tika from 2.4.0 to 2.5.0 addressing CVE-2022-33879. Signed-off-by: Marc Handalian <handalm@amazon.com> * Add missing SHAs. Signed-off-by: Marc Handalian <handalm@amazon.com> * Update changelog with PR info. Signed-off-by: Marc Handalian <handalm@amazon.com> Signed-off-by: Marc Handalian <handalm@amazon.com> (cherry picked from commit f1995b9) Signed-off-by: Vacha Shah <vachshah@amazon.com>
…project#4791) * Bump Tika from 2.4.0 to 2.5.0 addressing CVE-2022-33879. Signed-off-by: Marc Handalian <handalm@amazon.com> * Add missing SHAs. Signed-off-by: Marc Handalian <handalm@amazon.com> * Update changelog with PR info. Signed-off-by: Marc Handalian <handalm@amazon.com> Signed-off-by: Marc Handalian <handalm@amazon.com> Signed-off-by: Vacha Shah <vachshah@amazon.com>
…project#4791) * Bump Tika from 2.4.0 to 2.5.0 addressing CVE-2022-33879. Signed-off-by: Marc Handalian <handalm@amazon.com> * Add missing SHAs. Signed-off-by: Marc Handalian <handalm@amazon.com> * Update changelog with PR info. Signed-off-by: Marc Handalian <handalm@amazon.com> Signed-off-by: Marc Handalian <handalm@amazon.com> Signed-off-by: Vacha Shah <vachshah@amazon.com>
* Bump Tika from 2.4.0 to 2.5.0 addressing CVE-2022-33879. Signed-off-by: Marc Handalian <handalm@amazon.com> * Add missing SHAs. Signed-off-by: Marc Handalian <handalm@amazon.com> * Update changelog with PR info. Signed-off-by: Marc Handalian <handalm@amazon.com> Signed-off-by: Marc Handalian <handalm@amazon.com> (cherry picked from commit f1995b9) Signed-off-by: Vacha Shah <vachshah@amazon.com> Signed-off-by: Marc Handalian <handalm@amazon.com> Signed-off-by: Vacha Shah <vachshah@amazon.com>
#4929) * Bump Tika from 2.4.0 to 2.5.0 addressing CVE-2022-33879. (#4791) * Bump Tika from 2.4.0 to 2.5.0 addressing CVE-2022-33879. Signed-off-by: Marc Handalian <handalm@amazon.com> * Add missing SHAs. Signed-off-by: Marc Handalian <handalm@amazon.com> * Update changelog with PR info. Signed-off-by: Marc Handalian <handalm@amazon.com> Signed-off-by: Marc Handalian <handalm@amazon.com> Signed-off-by: Vacha Shah <vachshah@amazon.com> * Update CHANGELOG Signed-off-by: Vacha Shah <vachshah@amazon.com> Signed-off-by: Marc Handalian <handalm@amazon.com> Signed-off-by: Vacha Shah <vachshah@amazon.com> Co-authored-by: Marc Handalian <handalm@amazon.com>
…project#4791) * Bump Tika from 2.4.0 to 2.5.0 addressing CVE-2022-33879. Signed-off-by: Marc Handalian <handalm@amazon.com> * Add missing SHAs. Signed-off-by: Marc Handalian <handalm@amazon.com> * Update changelog with PR info. Signed-off-by: Marc Handalian <handalm@amazon.com> Signed-off-by: Marc Handalian <handalm@amazon.com>
The backport to
To backport manually, run these commands in your terminal: # Fetch latest updates from GitHub
git fetch
# Create a new working tree
git worktree add ../.worktrees/backport-1.3 1.3
# Navigate to the new working tree
pushd ../.worktrees/backport-1.3
# Create a new branch
git switch --create backport/backport-4791-to-1.3
# Cherry-pick the merged commit of this pull request and resolve the conflicts
git cherry-pick -x --mainline 1 f1995b951abab34935bf8e5dee91097efbf5503e
# Push it to GitHub
git push --set-upstream origin backport/backport-4791-to-1.3
# Go back to the original working tree
popd
# Delete the working tree
git worktree remove ../.worktrees/backport-1.3 Then, create a pull request where the |
Signed-off-by: Marc Handalian handalm@amazon.com
Description
Address CVE-2022-33879 and bump to latest Tika version.
Issues Resolved
N/A
Check List
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.