Skip to content

Conversation

@cwperks
Copy link
Member

@cwperks cwperks commented Oct 6, 2025

Description

Exclude commons-lang and org.jsonschema2pojo from hadoop-miniclusters to address brining in transitive deps with known CVEs. This miniclusters dependency keeps on giving :/

Check List

  • Functionality includes testing.
  • API changes companion pull request created, if applicable.
  • Public documentation issue/PR created, if applicable.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

@cwperks cwperks requested a review from a team as a code owner October 6, 2025 14:13
Signed-off-by: Craig Perkins <[email protected]>
@cwperks cwperks added the backport 3.3 Backport to 3.3 branch label Oct 6, 2025
@github-actions
Copy link
Contributor

github-actions bot commented Oct 6, 2025

✅ Gradle check result for 017555a: SUCCESS

@codecov
Copy link

codecov bot commented Oct 6, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 72.99%. Comparing base (cb65261) to head (017555a).
⚠️ Report is 73 commits behind head on main.

Additional details and impacted files
@@             Coverage Diff              @@
##               main   #19538      +/-   ##
============================================
- Coverage     73.00%   72.99%   -0.01%     
- Complexity    70483    70521      +38     
============================================
  Files          5717     5719       +2     
  Lines        323021   323203     +182     
  Branches      46790    46811      +21     
============================================
+ Hits         235826   235928     +102     
- Misses        68207    68269      +62     
- Partials      18988    19006      +18     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@peterzhuamazon peterzhuamazon merged commit 8eb034a into opensearch-project:main Oct 6, 2025
37 checks passed
opensearch-trigger-bot bot pushed a commit that referenced this pull request Oct 6, 2025
…#19538)

* Exclude commons-lang and org.jsonschema2pojo from hadoop-miniclusters

Signed-off-by: Craig Perkins <[email protected]>

* Add to CHANGELOG

Signed-off-by: Craig Perkins <[email protected]>

---------

Signed-off-by: Craig Perkins <[email protected]>
(cherry picked from commit 8eb034a)
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
peterzhuamazon pushed a commit that referenced this pull request Oct 6, 2025
…#19538) (#19541)

* Exclude commons-lang and org.jsonschema2pojo from hadoop-miniclusters



* Add to CHANGELOG



---------


(cherry picked from commit 8eb034a)

Signed-off-by: Craig Perkins <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
rgsriram pushed a commit to rgsriram/OpenSearch that referenced this pull request Oct 11, 2025
…opensearch-project#19538)

* Exclude commons-lang and org.jsonschema2pojo from hadoop-miniclusters

Signed-off-by: Craig Perkins <[email protected]>

* Add to CHANGELOG

Signed-off-by: Craig Perkins <[email protected]>

---------

Signed-off-by: Craig Perkins <[email protected]>
Gagan6164 pushed a commit to Gagan6164/OpenSearch that referenced this pull request Oct 13, 2025
…opensearch-project#19538)

* Exclude commons-lang and org.jsonschema2pojo from hadoop-miniclusters

Signed-off-by: Craig Perkins <[email protected]>

* Add to CHANGELOG

Signed-off-by: Craig Perkins <[email protected]>

---------

Signed-off-by: Craig Perkins <[email protected]>
Signed-off-by: Gagan Singh Saini <[email protected]>
peteralfonsi pushed a commit to peteralfonsi/OpenSearch that referenced this pull request Oct 15, 2025
…opensearch-project#19538)

* Exclude commons-lang and org.jsonschema2pojo from hadoop-miniclusters

Signed-off-by: Craig Perkins <[email protected]>

* Add to CHANGELOG

Signed-off-by: Craig Perkins <[email protected]>

---------

Signed-off-by: Craig Perkins <[email protected]>
@opensearch-trigger-bot
Copy link
Contributor

The backport to 2.19 failed:

The process '/usr/bin/git' failed with exit code 128

To backport manually, run these commands in your terminal:

# Navigate to the root of your repository
cd $(git rev-parse --show-toplevel)
# Fetch latest updates from GitHub
git fetch
# Create a new working tree
git worktree add ../.worktrees/OpenSearch/backport-2.19 2.19
# Navigate to the new working tree
pushd ../.worktrees/OpenSearch/backport-2.19
# Create a new branch
git switch --create backport/backport-19538-to-2.19
# Cherry-pick the merged commit of this pull request and resolve the conflicts
git cherry-pick -x --mainline 1 8eb034a904583cdc5915b96bb26f3ed6ef533ed3
# Push it to GitHub
git push --set-upstream origin backport/backport-19538-to-2.19
# Go back to the original working tree
popd
# Delete the working tree
git worktree remove ../.worktrees/OpenSearch/backport-2.19

Then, create a pull request where the base branch is 2.19 and the compare/head branch is backport/backport-19538-to-2.19.

@cwperks
Copy link
Member Author

cwperks commented Oct 22, 2025

opening manual backport

cwperks added a commit that referenced this pull request Oct 23, 2025
…#19538) (#19733)

* Exclude commons-lang and org.jsonschema2pojo from hadoop-miniclusters



* Add to CHANGELOG



---------


(cherry picked from commit 8eb034a)

Signed-off-by: Craig Perkins <[email protected]>
peterzhuamazon pushed a commit to peterzhuamazon/OpenSearch that referenced this pull request Nov 4, 2025
…opensearch-project#19538) (opensearch-project#19541)

* Exclude commons-lang and org.jsonschema2pojo from hadoop-miniclusters



* Add to CHANGELOG



---------


(cherry picked from commit 8eb034a)

Signed-off-by: Craig Perkins <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
peterzhuamazon pushed a commit to peterzhuamazon/OpenSearch that referenced this pull request Nov 4, 2025
…opensearch-project#19538) (opensearch-project#19541)

* Exclude commons-lang and org.jsonschema2pojo from hadoop-miniclusters



* Add to CHANGELOG



---------


(cherry picked from commit 8eb034a)

Signed-off-by: Craig Perkins <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants