-
Notifications
You must be signed in to change notification settings - Fork 95
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Backport 1.3] Forced ktlint to use logback-core:1.2.13, and logback-classic:1.2.13 to address CVE. #602 #603
Merged
AWSHurneyt
merged 30 commits into
opensearch-project:1.3
from
AWSHurneyt:1.3-pr602-backport
Feb 29, 2024
Merged
[Backport 1.3] Forced ktlint to use logback-core:1.2.13, and logback-classic:1.2.13 to address CVE. #602 #603
AWSHurneyt
merged 30 commits into
opensearch-project:1.3
from
AWSHurneyt:1.3-pr602-backport
Feb 29, 2024
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
AWSHurneyt
requested review from
lezzago,
qreshi,
bowenlan-amzn,
rishabhmaurya,
getsaurabh02,
eirsep,
sbcd90,
engechas and
riysaxen-amzn
as code owners
February 29, 2024 00:28
…ct#42) * Update Release Notes for GA (opensearch-project#36) * Update Release Notes for GA * Update Release Notes for GA include RC1 Changes as well. Signed-off-by: Aditya Jindal <aditjind@amazon.com> * add method type in CustomWebhook data model (opensearch-project#39) Signed-off-by: Zhongnan Su <szhongna@amazon.com> * Fix class loader issue for notifications response (opensearch-project#40) * Fix class loader issue for notifications Signed-off-by: Joshua Li <joshuali925@gmail.com> * Fix formatting Signed-off-by: Joshua Li <joshuali925@gmail.com> * Refactor creation of action listener object Signed-off-by: Joshua Li <joshuali925@gmail.com> * Fix indentation Signed-off-by: Joshua Li <joshuali925@gmail.com> * Remove unused suppresses Signed-off-by: Joshua Li <joshuali925@gmail.com> * Add UT for notification API Signed-off-by: Chen Dai <daichen@amazon.com> * Add UT for notification API Signed-off-by: Chen Dai <daichen@amazon.com> * Add UT for send notification API Signed-off-by: Chen Dai <daichen@amazon.com> * Fix Github workflow failure Signed-off-by: Chen Dai <daichen@amazon.com> * Fix Github workflow failure Signed-off-by: Chen Dai <daichen@amazon.com> * Refactor UT code Signed-off-by: Chen Dai <daichen@amazon.com> Co-authored-by: Joshua Li <joshuali925@gmail.com> Co-authored-by: Zhongnan Su <szhongna@amazon.com> Co-authored-by: Chen Dai <46505291+dai-chen@users.noreply.github.com> Co-authored-by: Joshua Li <joshuali925@gmail.com> Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
…earch-project#52) * Bumping common-utils to build with OpenSearch(main) 1.1.0 (opensearch-project#48) Signed-off-by: Sarat Vemulapalli <vemulapallisarat@gmail.com> * Updating 1.x to work with OpenSearch 1.x Signed-off-by: Sarat Vemulapalli <vemulapallisarat@gmail.com> Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
* Add Commits related to Snapshot build of Common Utils on 1.1 (opensearch-project#67) * Using 1.1 snapshot version for OpenSearch (opensearch-project#57) Signed-off-by: Vacha <vachshah@amazon.com> * Build snapshot build by default with the same version as OpenSearch. (opensearch-project#58) Signed-off-by: dblock <dblock@amazon.com> * Update build.gradle to reflect 1.1.0.0 version Co-authored-by: Vacha <vachshah@amazon.com> Co-authored-by: Daniel Doubrovkine (dB.) <dblock@dblock.org> * Build snapshot build by default with the same version as OpenSearch. (opensearch-project#58) (opensearch-project#69) Signed-off-by: dblock <dblock@amazon.com> * Adding an utility method that allows consumers to set custom thread context property in InjectSecurity class (opensearch-project#47) (opensearch-project#70) Signed-off-by: Ravi Thaluru <ravi1092@gmail.com> Co-authored-by: Ravi <6005951+thalurur@users.noreply.github.com> * Add release notes for version 1.1.0.0 * Add release notes for version 1.1.0.0 Co-authored-by: Aditya Jindal <13850971+aditjind@users.noreply.github.com> Co-authored-by: Vacha <vachshah@amazon.com> Co-authored-by: Daniel Doubrovkine (dB.) <dblock@dblock.org> Co-authored-by: Bowen Lan <62091230+bowenlan-amzn@users.noreply.github.com> Co-authored-by: Ravi <6005951+thalurur@users.noreply.github.com> Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
* Add themed logo to README (opensearch-project#41) Signed-off-by: Miki <mehranb@amazon.com> * Updates common-utils version to 1.2 (opensearch-project#77) * Updates common-utils version to 1.2 and Uses Maven for 1.2 dependencies Signed-off-by: Clay Downs <downsrob@amazon.com> * Publish .md5 and .sha1 signatures. (opensearch-project#79) (opensearch-project#80) * Publish .md5 and .sha1 signatures. Signed-off-by: dblock <dblock@dblock.org> * Use OpenSearch 1.1. Signed-off-by: dblock <dblock@dblock.org> * Publish source and javadoc checksums. (opensearch-project#81) Signed-off-by: dblock <dblock@dblock.org> * Update copyright notice (opensearch-project#90) Signed-off-by: Mohammad Qureshi <qreshi@amazon.com> * Update maven publication to include cksums. (opensearch-project#91) This change adds a local staging repo task that will include cksums. It will also update build.sh to use this new task and copy the contents of the staging repo to the output directory. The maven publish plugin will not include these cksums when publishing to maven local but will when published to a separate folder. Signed-off-by: Marc Handalian <handalm@amazon.com> * Add release notes for version 1.2.0.0 (opensearch-project#92) * Add release notes for version 1.2.0.0 Signed-off-by: Ashish Agrawal <ashisagr@amazon.com> Co-authored-by: Miki <mehranb@amazon.com> Co-authored-by: Clay Downs <89109232+downsrob@users.noreply.github.com> Co-authored-by: Daniel Doubrovkine (dB.) <dblock@dblock.org> Co-authored-by: Mohammad Qureshi <47198598+qreshi@users.noreply.github.com> Co-authored-by: Marc Handalian <handalm@amazon.com> Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
* Fix copyright notice and add DCO check workflow (opensearch-project#94) Signed-off-by: Ashish Agrawal <ashisagr@amazon.com> * Update build.sh script to include optional platform param. (opensearch-project#95) Signed-off-by: Marc Handalian <handalm@amazon.com> * Add codeowners support for repo (opensearch-project#96) Signed-off-by: Ryan Bogan <10944539+ryanbogan@users.noreply.github.com> * Bump version to 1.3 (opensearch-project#99) Signed-off-by: Ashish Agrawal <ashisagr@amazon.com> * Auto-increment version on new release tags. (opensearch-project#106) Signed-off-by: Daniel Doubrovkine (dB.) <dblock@dblock.org> * Remove jcenter repository (opensearch-project#115) Signed-off-by: Peter Nied <peternied@hotmail.com> * Using Github App token to trigger CI for version increment PRs (opensearch-project#116) Signed-off-by: Vacha Shah <vachshah@amazon.com> * Fixes copyright headers (opensearch-project#117) Signed-off-by: Drew Baugher <46505179+dbbaughe@users.noreply.github.com> * Remove jcenter repository missed on first pass (opensearch-project#118) Signed-off-by: Peter Nied <petern@amazon.com> * Run CI/CD on Java 8, 11, 14 and 17. (opensearch-project#121) * Run CI/CD on Java 8, 11, 14 and 17. Signed-off-by: Daniel Doubrovkine (dB.) <dblock@dblock.org> * Add JDK 17. Signed-off-by: Daniel Doubrovkine (dB.) <dblock@dblock.org> * Add .whitesource configuration file (opensearch-project#109) Co-authored-by: whitesource-for-github-com[bot] <50673670+whitesource-for-github-com[bot]@users.noreply.github.com> Co-authored-by: Ashish Agrawal <ashisagr@amazon.com> Co-authored-by: Marc Handalian <handalm@amazon.com> Co-authored-by: Ryan Bogan <10944539+ryanbogan@users.noreply.github.com> Co-authored-by: Daniel Doubrovkine (dB.) <dblock@dblock.org> Co-authored-by: Peter Nied <peternied@hotmail.com> Co-authored-by: Vacha Shah <vachshah@amazon.com> Co-authored-by: Drew Baugher <46505179+dbbaughe@users.noreply.github.com> Co-authored-by: Peter Nied <petern@amazon.com> Co-authored-by: whitesource-for-github-com[bot] <50673670+whitesource-for-github-com[bot]@users.noreply.github.com> Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
Signed-off-by: Saurabh Singh <sisurab@amazon.com> Co-authored-by: Saurabh Singh <sisurab@amazon.com> Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
Signed-off-by: Sayali Gaikawad <gaiksaya@amazon.com> Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
Signed-off-by: Sayali Gaikawad <gaiksaya@amazon.com> Co-authored-by: opensearch-ci-bot <opensearch-ci-bot@users.noreply.github.com> Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
opensearch-project#150) Signed-off-by: Vacha Shah <vachshah@amazon.com> (cherry picked from commit 6e78f69) Co-authored-by: Vacha Shah <vachshah@amazon.com> Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
Signed-off-by: dblock <dblock@amazon.com> Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
Signed-off-by: Zelin Hao <zelinhao@amazon.com> Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
…ensearch-project#208) * Version increment automation Signed-off-by: pgodithi <pgodithi@amazon.com> * Version increment automation: task rename updateVersion Signed-off-by: pgodithi <pgodithi@amazon.com> (cherry picked from commit 366bf16) Signed-off-by: prudhvigodithi <pgodithi@amazon.com> Signed-off-by: pgodithi <pgodithi@amazon.com> Signed-off-by: prudhvigodithi <pgodithi@amazon.com> Co-authored-by: Prudhvi Godithi <pgodithi@amazon.com> Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
Signed-off-by: prudhvigodithi <pgodithi@amazon.com> Signed-off-by: prudhvigodithi <pgodithi@amazon.com> Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
Signed-off-by: opensearch-ci-bot <opensearch-infra@amazon.com> Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
…pensearch-project#258) (opensearch-project#260) Signed-off-by: Peter Zhu <zhujiaxi@amazon.com> Signed-off-by: Peter Zhu <zhujiaxi@amazon.com> (cherry picked from commit 7dcb3a0) Co-authored-by: Peter Zhu <zhujiaxi@amazon.com> Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
…ect#266) * disable detekt so that snakeyaml <= 1.31 is not used Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
Signed-off-by: Subhobrata Dey <sbcd90@gmail.com> Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
* Increment version to 1.3.7-SNAPSHOT Signed-off-by: opensearch-ci-bot <opensearch-infra@amazon.com> * empty commit trigger Signed-off-by: Peter Zhu <zhujiaxi@amazon.com> Signed-off-by: opensearch-ci-bot <opensearch-infra@amazon.com> Signed-off-by: Peter Zhu <zhujiaxi@amazon.com> Co-authored-by: opensearch-ci-bot <opensearch-infra@amazon.com> Co-authored-by: Peter Zhu <zhujiaxi@amazon.com> Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
Signed-off-by: Subhobrata Dey <sbcd90@gmail.com> Signed-off-by: Subhobrata Dey <sbcd90@gmail.com> Co-authored-by: Surya Sashank Nistala <sashank.nistala@gmail.com> Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
Signed-off-by: opensearch-ci-bot <opensearch-infra@amazon.com> Signed-off-by: opensearch-ci-bot <opensearch-infra@amazon.com> Co-authored-by: opensearch-ci-bot <opensearch-infra@amazon.com> Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
Signed-off-by: opensearch-ci-bot <opensearch-infra@amazon.com> Co-authored-by: opensearch-ci-bot <opensearch-infra@amazon.com> Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
Signed-off-by: GitHub <noreply@github.com> Co-authored-by: opensearch-ci-bot <opensearch-ci-bot@users.noreply.github.com> Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
Signed-off-by: opensearch-ci-bot <opensearch-infra@amazon.com> Co-authored-by: opensearch-ci-bot <opensearch-infra@amazon.com> Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
Signed-off-by: opensearch-ci-bot <opensearch-infra@amazon.com> Co-authored-by: opensearch-ci-bot <opensearch-infra@amazon.com> Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
Signed-off-by: opensearch-ci-bot <opensearch-infra@amazon.com> Co-authored-by: opensearch-ci-bot <opensearch-infra@amazon.com> Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
Signed-off-by: opensearch-ci-bot <opensearch-infra@amazon.com> Co-authored-by: opensearch-ci-bot <opensearch-infra@amazon.com> Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
* Increment version to 1.3.15-SNAPSHOT Signed-off-by: opensearch-ci-bot <opensearch-infra@amazon.com> * Empty-Commit Signed-off-by: Ashish Agrawal <ashisagr@amazon.com> * Remove jdk 8 CI test Signed-off-by: Ashish Agrawal <ashisagr@amazon.com> --------- Signed-off-by: opensearch-ci-bot <opensearch-infra@amazon.com> Signed-off-by: Ashish Agrawal <ashisagr@amazon.com> Co-authored-by: opensearch-ci-bot <opensearch-infra@amazon.com> Co-authored-by: Ashish Agrawal <ashisagr@amazon.com> Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
…to address CVE. (opensearch-project#602) Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
AWSHurneyt
force-pushed
the
1.3-pr602-backport
branch
from
February 29, 2024 00:34
a611e3c
to
10966b8
Compare
Signed-off-by: AWSHurneyt <hurneyt@amazon.com>
engechas
approved these changes
Feb 29, 2024
lezzago
approved these changes
Feb 29, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
Manual backport of PR #602
Issues Resolved
[List any issues this PR will resolve]
Check List
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.