nodejs / build

Better build and test infra for Node.
504 stars 165 forks source link

Jenkins security update Jan 12th #2845

Closed rvagg closed 2 years ago

rvagg commented 2 years ago

The Jenkins project plans to publish new Jenkins releases (weekly and LTS 2.319.2) on Wednesday, January 12. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "Medium". The security advisory will be issued at the same time to provide further information.

Additionally, we will announce security issues in plugins in this security advisory. The highest severity is "High" and these issues affect plugins installed on more than 75% of known instances.

I suppose I'll handle this one.

targos commented 2 years ago

The releases are out and we have some warnings on ci.nodejs.org now.

rvagg commented 2 years ago

A bit delayed, but they're both upgraded now:

ci-release

Jenkins: 2.303.3 -> 2.319.2

Plugins

ci

Jenkins: 2.303.3 -> 2.319.2

Plugins

targos commented 2 years ago

What about "PUBLISH OVER SSH 1.22" ?

richardlau commented 2 years ago

What about "PUBLISH OVER SSH 1.22" ?

No available fixes at this time: https://www.jenkins.io/security/advisory/2022-01-12/