From 4e9f17a5ce61a48edc064f371b9e7d75e8f96cde Mon Sep 17 00:00:00 2001 From: Pavan Yekbote Date: Mon, 2 Mar 2026 17:46:42 -0800 Subject: [PATCH 1/6] chore fix cve CVE-2025-67735 Signed-off-by: Pavan Yekbote --- build.gradle | 18 +++++++++--------- 1 file changed, 9 insertions(+), 9 deletions(-) diff --git a/build.gradle b/build.gradle index 2e13216f10..8bab533be9 100644 --- a/build.gradle +++ b/build.gradle @@ -83,15 +83,15 @@ subprojects { resolutionStrategy.force "org.apache.commons:commons-lang3:${versions.commonslang}" resolutionStrategy.force 'software.amazon.awssdk:bom:2.32.29' - resolutionStrategy.force 'io.netty:netty-buffer:4.1.125.Final' - resolutionStrategy.force 'io.netty:netty-codec:4.1.125.Final' - resolutionStrategy.force 'io.netty:netty-codec-http:4.1.125.Final' - resolutionStrategy.force 'io.netty:netty-codec-http2:4.1.125.Final' - resolutionStrategy.force 'io.netty:netty-common:4.1.125.Final' - resolutionStrategy.force 'io.netty:netty-handler:4.1.125.Final' - resolutionStrategy.force 'io.netty:netty-resolver:4.1.125.Final' - resolutionStrategy.force 'io.netty:netty-transport:4.1.125.Final' - resolutionStrategy.force 'io.netty:netty-transport-native-unix-common:4.1.125.Final' + resolutionStrategy.force "io.netty:netty-buffer:${versions.netty}" + resolutionStrategy.force "io.netty:netty-codec:${versions.netty}" + resolutionStrategy.force "io.netty:netty-codec-http:${versions.netty}" + resolutionStrategy.force "io.netty:netty-codec-http2:${versions.netty}" + resolutionStrategy.force "io.netty:netty-common:${versions.netty}" + resolutionStrategy.force "io.netty:netty-handler:${versions.netty}" + resolutionStrategy.force "io.netty:netty-resolver:${versions.netty}" + resolutionStrategy.force "io.netty:netty-transport:${versions.netty}" + resolutionStrategy.force "io.netty:netty-transport-native-unix-common:${versions.netty}" } } From df2fca16ab7a9929d0be6a45208eeb784b70ef43 Mon Sep 17 00:00:00 2001 From: Pavan Yekbote Date: Mon, 2 Mar 2026 17:57:51 -0800 Subject: [PATCH 2/6] force log4j to use version from core Signed-off-by: Pavan Yekbote --- plugin/build.gradle | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/plugin/build.gradle b/plugin/build.gradle index 969e647288..486f551e64 100644 --- a/plugin/build.gradle +++ b/plugin/build.gradle @@ -81,7 +81,7 @@ dependencies { implementation group: 'com.google.code.gson', name: 'gson', version: '2.11.0' implementation group: 'org.apache.commons', name: 'commons-lang3', version: '3.18.0' implementation group: 'org.apache.commons', name: 'commons-math3', version: '3.6.1' - implementation "org.apache.logging.log4j:log4j-slf4j-impl:2.19.0" + implementation "org.apache.logging.log4j:log4j-slf4j-impl:${versions.log4j}" testImplementation group: 'commons-io', name: 'commons-io', version: '2.15.1' implementation group: 'org.apache.commons', name: 'commons-text', version: '1.10.0' implementation ('com.jayway.jsonpath:json-path:2.9.0') { From cc0fa69a9242de65c1c84ab90fa219498e17a1db Mon Sep 17 00:00:00 2001 From: Pavan Yekbote Date: Mon, 2 Mar 2026 18:11:26 -0800 Subject: [PATCH 3/6] chore: fix log4j dependency version to use version from core Signed-off-by: Pavan Yekbote --- plugin/build.gradle | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/plugin/build.gradle b/plugin/build.gradle index 486f551e64..23af5667d2 100644 --- a/plugin/build.gradle +++ b/plugin/build.gradle @@ -415,8 +415,8 @@ configurations.all { resolutionStrategy.force "org.apache.httpcomponents.client5:httpclient5:5.4.3" resolutionStrategy.force "com.fasterxml.jackson.core:jackson-databind:${versions.jackson_databind}" resolutionStrategy.force "com.fasterxml.jackson.core:jackson-core:${versions.jackson_databind}" - resolutionStrategy.force "org.apache.logging.log4j:log4j-api:2.24.2" - resolutionStrategy.force "org.apache.logging.log4j:log4j-core:2.24.2" + resolutionStrategy.force "org.apache.logging.log4j:log4j-api:${versions.log4j}" + resolutionStrategy.force "org.apache.logging.log4j:log4j-core:${versions.log4j}" resolutionStrategy.force "jakarta.json:jakarta.json-api:2.1.3" resolutionStrategy.force 'commons-beanutils:commons-beanutils:1.11.0' } From a24986e253aa08e0642cb7cbaadfeb166d712eaf Mon Sep 17 00:00:00 2001 From: Pavan Yekbote Date: Mon, 2 Mar 2026 22:26:37 -0800 Subject: [PATCH 4/6] test: ci fix Signed-off-by: Pavan Yekbote --- .github/workflows/CI-workflow.yml | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/.github/workflows/CI-workflow.yml b/.github/workflows/CI-workflow.yml index 7b29205afd..eb92eae0a0 100644 --- a/.github/workflows/CI-workflow.yml +++ b/.github/workflows/CI-workflow.yml @@ -77,14 +77,14 @@ jobs: id: step-build-test-linux run: | chown -R 1000:1000 `pwd` - su `id -un 1000` -c 'whoami && java -version && - export OPENAI_KEY=`aws secretsmanager get-secret-value --secret-id github_openai_key --query SecretString --output text` && - export COHERE_KEY=`aws secretsmanager get-secret-value --secret-id github_cohere_key --query SecretString --output text` && - echo "::add-mask::$OPENAI_KEY" && - echo "::add-mask::$COHERE_KEY" && - echo "build and run tests" && ./gradlew build -x spotlessJava && - echo "Publish to Maven Local" && ./gradlew publishToMavenLocal -x spotlessJava && - echo "Multi Nodes Integration Testing" && ./gradlew integTest -PnumNodes=3 -x spotlessJava' + su `id -un 1000` -c "export JAVA_HOME=$JAVA_HOME && export PATH=\$JAVA_HOME/bin:\$PATH && whoami && java -version && + export OPENAI_KEY=\`aws secretsmanager get-secret-value --secret-id github_openai_key --query SecretString --output text\` && + export COHERE_KEY=\`aws secretsmanager get-secret-value --secret-id github_cohere_key --query SecretString --output text\` && + echo '::add-mask::'\$OPENAI_KEY && + echo '::add-mask::'\$COHERE_KEY && + echo 'build and run tests' && ./gradlew build -x spotlessJava && + echo 'Publish to Maven Local' && ./gradlew publishToMavenLocal -x spotlessJava && + echo 'Multi Nodes Integration Testing' && ./gradlew integTest -PnumNodes=3 -x spotlessJava" plugin=`basename $(ls plugin/build/distributions/*.zip)` echo $plugin mv -v plugin/build/distributions/$plugin ./ From aa75b7d324fced08810a509c399470c7b1d10f9b Mon Sep 17 00:00:00 2001 From: Pavan Yekbote Date: Tue, 3 Mar 2026 12:18:30 -0800 Subject: [PATCH 5/6] Revert "test: ci fix" This reverts commit a24986e253aa08e0642cb7cbaadfeb166d712eaf. Signed-off-by: Pavan Yekbote --- .github/workflows/CI-workflow.yml | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/.github/workflows/CI-workflow.yml b/.github/workflows/CI-workflow.yml index eb92eae0a0..7b29205afd 100644 --- a/.github/workflows/CI-workflow.yml +++ b/.github/workflows/CI-workflow.yml @@ -77,14 +77,14 @@ jobs: id: step-build-test-linux run: | chown -R 1000:1000 `pwd` - su `id -un 1000` -c "export JAVA_HOME=$JAVA_HOME && export PATH=\$JAVA_HOME/bin:\$PATH && whoami && java -version && - export OPENAI_KEY=\`aws secretsmanager get-secret-value --secret-id github_openai_key --query SecretString --output text\` && - export COHERE_KEY=\`aws secretsmanager get-secret-value --secret-id github_cohere_key --query SecretString --output text\` && - echo '::add-mask::'\$OPENAI_KEY && - echo '::add-mask::'\$COHERE_KEY && - echo 'build and run tests' && ./gradlew build -x spotlessJava && - echo 'Publish to Maven Local' && ./gradlew publishToMavenLocal -x spotlessJava && - echo 'Multi Nodes Integration Testing' && ./gradlew integTest -PnumNodes=3 -x spotlessJava" + su `id -un 1000` -c 'whoami && java -version && + export OPENAI_KEY=`aws secretsmanager get-secret-value --secret-id github_openai_key --query SecretString --output text` && + export COHERE_KEY=`aws secretsmanager get-secret-value --secret-id github_cohere_key --query SecretString --output text` && + echo "::add-mask::$OPENAI_KEY" && + echo "::add-mask::$COHERE_KEY" && + echo "build and run tests" && ./gradlew build -x spotlessJava && + echo "Publish to Maven Local" && ./gradlew publishToMavenLocal -x spotlessJava && + echo "Multi Nodes Integration Testing" && ./gradlew integTest -PnumNodes=3 -x spotlessJava' plugin=`basename $(ls plugin/build/distributions/*.zip)` echo $plugin mv -v plugin/build/distributions/$plugin ./ From 6680113364a97adecdea512af4196df0a0ff0261 Mon Sep 17 00:00:00 2001 From: Pavan Yekbote Date: Tue, 3 Mar 2026 13:36:32 -0800 Subject: [PATCH 6/6] fix: shadow build issue after change in core and upgrade gradle to work with java 25 Signed-off-by: Pavan Yekbote --- client/build.gradle | 2 +- common/build.gradle | 6 +++--- gradle/wrapper/gradle-wrapper.properties | 9 ++------- gradlew.bat | 20 ++++++++++---------- spi/build.gradle | 4 ++-- 5 files changed, 18 insertions(+), 23 deletions(-) diff --git a/client/build.gradle b/client/build.gradle index a2d9d466c8..e67a0ceaad 100644 --- a/client/build.gradle +++ b/client/build.gradle @@ -7,7 +7,7 @@ plugins { id 'java' id "io.freefair.lombok" id 'jacoco' - id 'com.github.johnrengelman.shadow' + id 'com.gradleup.shadow' id 'maven-publish' id 'com.diffplug.spotless' version '6.23.0' id 'signing' diff --git a/common/build.gradle b/common/build.gradle index 799401d18b..3af28fe243 100644 --- a/common/build.gradle +++ b/common/build.gradle @@ -6,7 +6,7 @@ //TODO: cleanup gradle config file, some overlap plugins { id 'java' - id 'com.github.johnrengelman.shadow' + id 'com.gradleup.shadow' id 'jacoco' id "io.freefair.lombok" id 'com.diffplug.spotless' version '6.25.0' @@ -90,12 +90,12 @@ spotless { } } -shadowJar { +tasks.named('shadowJar') { destinationDirectory = file("${project.buildDir}/distributions") archiveClassifier.set(null) exclude 'META-INF/maven/com.google.guava/**' exclude 'com/google/thirdparty/**' - relocate 'com.google.common', 'org.opensearch.ml.repackage.com.google.common' // dependency of cron-utils + relocate 'com.google.common', 'org.opensearch.ml.repackage.com.google.common' } jar { diff --git a/gradle/wrapper/gradle-wrapper.properties b/gradle/wrapper/gradle-wrapper.properties index 142d400f41..b11741a1ad 100644 --- a/gradle/wrapper/gradle-wrapper.properties +++ b/gradle/wrapper/gradle-wrapper.properties @@ -1,13 +1,8 @@ -# -# Copyright OpenSearch Contributors -# SPDX-License-Identifier: Apache-2.0 -# - distributionBase=GRADLE_USER_HOME distributionPath=wrapper/dists -distributionUrl=https\://services.gradle.org/distributions/gradle-8.11.1-bin.zip +distributionSha256Sum=16f2b95838c1ddcf7242b1c39e7bbbb43c842f1f1a1a0dc4959b6d4d68abcac3 +distributionUrl=https\://services.gradle.org/distributions/gradle-9.2.0-all.zip networkTimeout=10000 validateDistributionUrl=true zipStoreBase=GRADLE_USER_HOME zipStorePath=wrapper/dists -distributionSha256Sum=f397b287023acdba1e9f6fc5ea72d22dd63669d59ed4a289a29b1a76eee151c6 diff --git a/gradlew.bat b/gradlew.bat index 0ebb4c6c76..9b42019c79 100644 --- a/gradlew.bat +++ b/gradlew.bat @@ -45,11 +45,11 @@ set JAVA_EXE=java.exe %JAVA_EXE% -version >NUL 2>&1 if %ERRORLEVEL% equ 0 goto execute -echo. -echo ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH. -echo. -echo Please set the JAVA_HOME variable in your environment to match the -echo location of your Java installation. +echo. 1>&2 +echo ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH. 1>&2 +echo. 1>&2 +echo Please set the JAVA_HOME variable in your environment to match the 1>&2 +echo location of your Java installation. 1>&2 goto fail @@ -59,11 +59,11 @@ set JAVA_EXE=%JAVA_HOME%/bin/java.exe if exist "%JAVA_EXE%" goto execute -echo. -echo ERROR: JAVA_HOME is set to an invalid directory: %JAVA_HOME% -echo. -echo Please set the JAVA_HOME variable in your environment to match the -echo location of your Java installation. +echo. 1>&2 +echo ERROR: JAVA_HOME is set to an invalid directory: %JAVA_HOME% 1>&2 +echo. 1>&2 +echo Please set the JAVA_HOME variable in your environment to match the 1>&2 +echo location of your Java installation. 1>&2 goto fail diff --git a/spi/build.gradle b/spi/build.gradle index d9d30407fa..e911622873 100644 --- a/spi/build.gradle +++ b/spi/build.gradle @@ -7,7 +7,7 @@ import com.github.jengelman.gradle.plugins.shadow.ShadowBasePlugin import org.opensearch.gradle.test.RestIntegTestTask plugins { - id 'com.github.johnrengelman.shadow' + id 'com.gradleup.shadow' id 'jacoco' id 'maven-publish' id 'signing' @@ -56,7 +56,7 @@ configurations.all { } } -shadowJar { +tasks.named('shadowJar') { archiveClassifier = null }