-
Notifications
You must be signed in to change notification settings - Fork 416
wildfly/35.0.1-r0: cve remediation #42897
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
wildfly/35.0.1-r0: cve remediation #42897
Conversation
|
Please use 👍 or 👎 on this comment to indicate if you agree or disagree with the recommendation. To provide more detailed feedback please comment on the recommendation prefixed with /ai-verify: e.g. /ai-verify partially helpful but I also added bash to the build environment Gen AI suggestions to solve the build error: Based on the build error output, I'll analyze and provide a solution: • Detected Error: • Error Category: Dependency • Failure Point: Maven dependency resolution during build process • Root Cause Analysis: • Suggested Fix: environment:
contents:
packages:
- build-base
- busybox
- ca-certificates-bundle
- curl
- maven
- openjdk-17
- openjdk-21
pipeline:
- uses: git-checkout
with:
repository: https://github.com/wildfly/wildfly
tag: ${{package.version}}.Final
expected-commit: 1ffef94b7a7ababb767b0dd20f7c0d754388ad12
- uses: maven/pombump
with:
pomFile: pom.xml
dependencies:
- groupId: io.netty
artifactId: netty-common
version: 4.1.116.Final• Explanation: • Additional Notes:
• References: |
Signed-off-by: hbh7 <[email protected]>
Signed-off-by: hbh7 <[email protected]>
Signed-off-by: hbh7 <[email protected]>
Signed-off-by: hbh7 <[email protected]>
Signed-off-by: hbh7 <[email protected]>
|
Epoch is so high due to several failed remediation attempts, a withdraw (54cc832) and readd, and maybe a third thing I'm forgetting. This'll ensure it's actually the latest used build. |
jamonation
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
|
Happy to help out and get to the bottom of everything, great teaching moment too haha :) |
wildfly/35.0.1-r0: fix GHSA-389x-839f-4rhx
Advisory data: https://github.com/wolfi-dev/advisories/blob/main/wildfly.advisories.yaml
Source code for this service: https://go/cve-remedy-automation-source
Logs for this execution: https://go/cve-remedy-automation-logs
Docs for this service: (not provided yet)