-
Notifications
You must be signed in to change notification settings - Fork 2.3k
Exclude commons-lang and org.jsonschema2pojo from hadoop-miniclusters #19538
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Exclude commons-lang and org.jsonschema2pojo from hadoop-miniclusters #19538
Conversation
Signed-off-by: Craig Perkins <[email protected]>
Signed-off-by: Craig Perkins <[email protected]>
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #19538 +/- ##
============================================
- Coverage 73.00% 72.99% -0.01%
- Complexity 70483 70521 +38
============================================
Files 5717 5719 +2
Lines 323021 323203 +182
Branches 46790 46811 +21
============================================
+ Hits 235826 235928 +102
- Misses 68207 68269 +62
- Partials 18988 19006 +18 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
…#19538) * Exclude commons-lang and org.jsonschema2pojo from hadoop-miniclusters Signed-off-by: Craig Perkins <[email protected]> * Add to CHANGELOG Signed-off-by: Craig Perkins <[email protected]> --------- Signed-off-by: Craig Perkins <[email protected]> (cherry picked from commit 8eb034a) Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
…#19538) (#19541) * Exclude commons-lang and org.jsonschema2pojo from hadoop-miniclusters * Add to CHANGELOG --------- (cherry picked from commit 8eb034a) Signed-off-by: Craig Perkins <[email protected]> Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
…opensearch-project#19538) * Exclude commons-lang and org.jsonschema2pojo from hadoop-miniclusters Signed-off-by: Craig Perkins <[email protected]> * Add to CHANGELOG Signed-off-by: Craig Perkins <[email protected]> --------- Signed-off-by: Craig Perkins <[email protected]>
…opensearch-project#19538) * Exclude commons-lang and org.jsonschema2pojo from hadoop-miniclusters Signed-off-by: Craig Perkins <[email protected]> * Add to CHANGELOG Signed-off-by: Craig Perkins <[email protected]> --------- Signed-off-by: Craig Perkins <[email protected]> Signed-off-by: Gagan Singh Saini <[email protected]>
…opensearch-project#19538) * Exclude commons-lang and org.jsonschema2pojo from hadoop-miniclusters Signed-off-by: Craig Perkins <[email protected]> * Add to CHANGELOG Signed-off-by: Craig Perkins <[email protected]> --------- Signed-off-by: Craig Perkins <[email protected]>
|
The backport to To backport manually, run these commands in your terminal: # Navigate to the root of your repository
cd $(git rev-parse --show-toplevel)
# Fetch latest updates from GitHub
git fetch
# Create a new working tree
git worktree add ../.worktrees/OpenSearch/backport-2.19 2.19
# Navigate to the new working tree
pushd ../.worktrees/OpenSearch/backport-2.19
# Create a new branch
git switch --create backport/backport-19538-to-2.19
# Cherry-pick the merged commit of this pull request and resolve the conflicts
git cherry-pick -x --mainline 1 8eb034a904583cdc5915b96bb26f3ed6ef533ed3
# Push it to GitHub
git push --set-upstream origin backport/backport-19538-to-2.19
# Go back to the original working tree
popd
# Delete the working tree
git worktree remove ../.worktrees/OpenSearch/backport-2.19Then, create a pull request where the |
|
opening manual backport |
…#19538) (#19733) * Exclude commons-lang and org.jsonschema2pojo from hadoop-miniclusters * Add to CHANGELOG --------- (cherry picked from commit 8eb034a) Signed-off-by: Craig Perkins <[email protected]>
…opensearch-project#19538) (opensearch-project#19541) * Exclude commons-lang and org.jsonschema2pojo from hadoop-miniclusters * Add to CHANGELOG --------- (cherry picked from commit 8eb034a) Signed-off-by: Craig Perkins <[email protected]> Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
…opensearch-project#19538) (opensearch-project#19541) * Exclude commons-lang and org.jsonschema2pojo from hadoop-miniclusters * Add to CHANGELOG --------- (cherry picked from commit 8eb034a) Signed-off-by: Craig Perkins <[email protected]> Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Description
Exclude commons-lang and org.jsonschema2pojo from hadoop-miniclusters to address brining in transitive deps with known CVEs. This miniclusters dependency keeps on giving :/
Check List
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.