opensearch-project / opensearch-build-libraries

Apache License 2.0
6 stars 23 forks source link

Update dependency org.jenkins-ci.plugins:script-security to v1336 #422

Open mend-for-github-com[bot] opened 2 months ago

mend-for-github-com[bot] commented 2 months ago

This PR contains the following updates:

Package Type Update Change
org.jenkins-ci.plugins:script-security dependencies major 1229.v4880b_b_e905a_6 -> 1336.vf33a_a_9863911

By merging this PR, the issue #421 will be automatically resolved and closed:

Severity CVSS Score CVE
High High 8.8 CVE-2024-34144
High High 8.8 CVE-2024-34145

Release Notes

jenkinsci/script-security-plugin (org.jenkins-ci.plugins:script-security) ### [`v1336.vf33a_a_9863911`](https://togithub.com/jenkinsci/script-security-plugin/releases/tag/1336.vf33a_a_9863911) [Compare Source](https://togithub.com/jenkinsci/script-security-plugin/compare/1326.vdb_c154de8669...1336.vf33a_a_9863911) #### :lock: Security - Fix [SECURITY-3341](https://www.jenkins.io/security/advisory/2024-05-02/#SECURITY-3341). ### [`v1326.vdb_c154de8669`](https://togithub.com/jenkinsci/script-security-plugin/releases/tag/1326.vdb_c154de8669) [Compare Source](https://togithub.com/jenkinsci/script-security-plugin/compare/1305.v487433146192...1326.vdb_c154de8669) #### 👷 Changes for plugin developers - Bump plugin parent pom to 4.78 ([#​559](https://togithub.com/jenkinsci/script-security-plugin/issues/559)) [@​imonteroperez](https://togithub.com/imonteroperez) #### 🚦 Tests - Restore Windows branch in PRs ([#​556](https://togithub.com/jenkinsci/script-security-plugin/issues/556)) [@​jglick](https://togithub.com/jglick) ### [`v1305.v487433146192`](https://togithub.com/jenkinsci/script-security-plugin/releases/tag/1305.v487433146192) [Compare Source](https://togithub.com/jenkinsci/script-security-plugin/compare/1294.v99333c047434...1305.v487433146192) #### 🚀 New features and improvements - add badge ([#​550](https://togithub.com/jenkinsci/script-security-plugin/issues/550)) [@​mawinter69](https://togithub.com/mawinter69) #### 📝 Documentation updates - Remove word duplication from Script Security UI ([#​551](https://togithub.com/jenkinsci/script-security-plugin/issues/551)) [@​Bananeweizen](https://togithub.com/Bananeweizen) ### [`v1294.v99333c047434`](https://togithub.com/jenkinsci/script-security-plugin/releases/tag/1294.v99333c047434) [Compare Source](https://togithub.com/jenkinsci/script-security-plugin/compare/1275.v23895f409fb_d...1294.v99333c047434) #### 🚀 New features and improvements - Added `toFloat` and `toInteger` to whitelist ([#​544](https://togithub.com/jenkinsci/script-security-plugin/issues/544)) [@​StefanSpieker](https://togithub.com/StefanSpieker) #### 🐛 Bug fixes - Fix reloading configuration from disk ([#​545](https://togithub.com/jenkinsci/script-security-plugin/issues/545)) [@​Vlatombe](https://togithub.com/Vlatombe) - [JENKINS-72325](https://issues.jenkins.io/browse/JENKINS-72325) - Define an executor and scheduler for `SandboxResolvingClassLoader` ([#​543](https://togithub.com/jenkinsci/script-security-plugin/issues/543)) [@​basil](https://togithub.com/basil) - `convertDeprecatedApprovedClasspathEntriesThread` should be `transient` ([#​538](https://togithub.com/jenkinsci/script-security-plugin/issues/538)) [@​jglick](https://togithub.com/jglick) #### 📦 Dependency updates - Bump io.jenkins.tools.bom:bom-2.387.x from 2357.v1043f8578392 to 2543.vfb\_1a\_5fb\_9496d ([#​536](https://togithub.com/jenkinsci/script-security-plugin/issues/536)) [@​dependabot](https://togithub.com/dependabot) ### [`v1275.v23895f409fb_d`](https://togithub.com/jenkinsci/script-security-plugin/releases/tag/1275.v23895f409fb_d) [Compare Source](https://togithub.com/jenkinsci/script-security-plugin/compare/1273.v66c1964f0dfd...1275.v23895f409fb_d) #### 👷 Changes for plugin developers - forward compatibility with core-8418 ([#​522](https://togithub.com/jenkinsci/script-security-plugin/issues/522)) [@​mawinter69](https://togithub.com/mawinter69) #### 🚦 Tests - forward compatibility with core-8418 ([#​522](https://togithub.com/jenkinsci/script-security-plugin/issues/522)) [@​mawinter69](https://togithub.com/mawinter69) ### [`v1273.v66c1964f0dfd`](https://togithub.com/jenkinsci/script-security-plugin/releases/tag/1273.v66c1964f0dfd) [Compare Source](https://togithub.com/jenkinsci/script-security-plugin/compare/1269.v639888f5e366...1273.v66c1964f0dfd) #### 🚀 New features and improvements - Update ScriptApprovalLink icon ([#​521](https://togithub.com/jenkinsci/script-security-plugin/issues/521)) [@​strangelookingnerd](https://togithub.com/strangelookingnerd) ### [`v1269.v639888f5e366`](https://togithub.com/jenkinsci/script-security-plugin/releases/tag/1269.v639888f5e366) [Compare Source](https://togithub.com/jenkinsci/script-security-plugin/compare/1264.vecf66020eb_7d...1269.v639888f5e366) #### 👷 Changes for plugin developers - [JENKINS-71808](https://issues.jenkins.io/browse/JENKINS-71808) - `GenericWhitelistTest#sanity` fails on Java 21 ([#​519](https://togithub.com/jenkinsci/script-security-plugin/issues/519)) [@​basil](https://togithub.com/basil) #### 📦 Dependency updates - Bump org.jenkins-ci.plugins:plugin from 4.71 to 4.72 ([#​518](https://togithub.com/jenkinsci/script-security-plugin/issues/518)) [@​dependabot](https://togithub.com/dependabot) ### [`v1264.vecf66020eb_7d`](https://togithub.com/jenkinsci/script-security-plugin/releases/tag/1264.vecf66020eb_7d) [Compare Source](https://togithub.com/jenkinsci/script-security-plugin/compare/1251.vfe552ed55f8d...1264.vecf66020eb_7d) #### 👷 Changes for plugin developers - Bump plugin from 4.65 to 4.66 ([#​508](https://togithub.com/jenkinsci/script-security-plugin/issues/508)) [@​dependabot](https://togithub.com/dependabot) #### 👻 Maintenance - Remove unnecessary workarounds ([#​517](https://togithub.com/jenkinsci/script-security-plugin/issues/517)) [@​basil](https://togithub.com/basil) #### 📦 Dependency updates - Bump git-changelist-maven-extension from 1.6 to 1.7 ([#​513](https://togithub.com/jenkinsci/script-security-plugin/issues/513)) [@​dependabot](https://togithub.com/dependabot) - Bump plugin from 4.68 to 4.71 ([#​515](https://togithub.com/jenkinsci/script-security-plugin/issues/515)) [@​dependabot](https://togithub.com/dependabot) - Bump plugin from 4.67 to 4.68 ([#​511](https://togithub.com/jenkinsci/script-security-plugin/issues/511)) [@​dependabot](https://togithub.com/dependabot) - Bump plugin from 4.66 to 4.67 ([#​510](https://togithub.com/jenkinsci/script-security-plugin/issues/510)) [@​dependabot](https://togithub.com/dependabot) ### [`v1251.vfe552ed55f8d`](https://togithub.com/jenkinsci/script-security-plugin/releases/tag/1251.vfe552ed55f8d) [Compare Source](https://togithub.com/jenkinsci/script-security-plugin/compare/1229.v4880b_b_e905a_6...1251.vfe552ed55f8d) #### 👷 Changes for plugin developers - Replace Prototype.js with native JavaScript ([#​501](https://togithub.com/jenkinsci/script-security-plugin/issues/501)) [@​basil](https://togithub.com/basil) #### 📦 Dependency updates - Bump plugin from 4.62 to 4.65 ([#​507](https://togithub.com/jenkinsci/script-security-plugin/issues/507)) [@​dependabot](https://togithub.com/dependabot) - Bump plugin from 4.61 to 4.62 ([#​499](https://togithub.com/jenkinsci/script-security-plugin/issues/499)) [@​dependabot](https://togithub.com/dependabot) - Bump plugin from 4.60 to 4.61 ([#​497](https://togithub.com/jenkinsci/script-security-plugin/issues/497)) [@​dependabot](https://togithub.com/dependabot)

mend-for-github-com[bot] commented 1 month ago

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.