Skip to content

Conversation

@smolnar82
Copy link
Contributor

What changes were proposed in this pull request?

During BlackDuck check there were several security vulnerabilities found which we needed to eliminate (or at least mitigate). All of these changes have been reviewed/tested one-by-one on branch-2.6 earlier in the past weeks:

How was this patch tested?

Latest uni test results in ambari-server:

[INFO] ------------------------------------------------------------------------
[INFO] BUILD SUCCESS
[INFO] ------------------------------------------------------------------------
[INFO] Total time: 27:20 min
[INFO] Finished at: 2018-03-04T17:07:30+01:00
[INFO] Final Memory: 212M/916M
[INFO] ------------------------------------------------------------------------

In addition to uni testing I checked Maven's dependency resolution and executed integration testing in my local test environment:
I replaced the content of usr/lib/ambari-server in my vagrant host with the content from ambari-server/target/ambari-server-2.6.0.0.0-dist/usr/lib/ambari-server (where the relevant JAR(s) were replaced/removed with their expected version) and restarted the server; logged in and did some actions (in this case I used the REST API to create a cluster via BPs); there were no any issues.

@smolnar82
Copy link
Contributor Author

@rlevas @adoroszlai @zeroflag @dlysnichenko Could you please review this PR? As I mentioned those changes have already been reviewed and tested. However - due to the large amount of changes on trunk - it was not possible to simply cherry-pick the commits in question.

Thanks!

@asfgit
Copy link

asfgit commented Mar 4, 2018

Refer to this link for build results (access rights to CI server needed):
https://builds.apache.org/job/Ambari-Github-PullRequest-Builder/951/
Test FAILed.
Test FAILured.

@smolnar82 smolnar82 changed the title AMBARI-23123. Fixing BlackDuck found security issues in Ambari Server [AMBARI-23123] Fixing BlackDuck found security issues in Ambari Server Mar 5, 2018
@rlevas
Copy link
Contributor

rlevas commented Mar 5, 2018

retest this please

@asfgit
Copy link

asfgit commented Mar 5, 2018

Refer to this link for build results (access rights to CI server needed):
https://builds.apache.org/job/Ambari-Github-PullRequest-Builder/962/
Test PASSed.

@rlevas rlevas merged commit 5e086e1 into apache:trunk Mar 5, 2018
@smolnar82 smolnar82 deleted the AMBARI-23123 branch March 5, 2018 20:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants