opensearch-project / security

🔐 Secure your cluster with TLS, numerous authentication backends, data masking, audit logging as well as role-based access control on indices, documents, and fields
https://opensearch.org/docs/latest/security-plugin/index/
Apache License 2.0
191 stars 272 forks source link

Bump com.google.errorprone:error_prone_annotations from 2.27.1 to 2.28.0 #4389

Closed dependabot[bot] closed 4 months ago

dependabot[bot] commented 4 months ago

Bumps com.google.errorprone:error_prone_annotations from 2.27.1 to 2.28.0.

Release notes

Sourced from com.google.errorprone:error_prone_annotations's releases.

Error Prone 2.28.0

Error Prone nows supports the latest JDK 23 EA builds (#4412, #4415).

Closed issues:

  • Improved errors for invalid check severities (#4306).
  • Fix a crash with nested instanceof patterns (#4349).
  • Fix a crash in JUnitIncompatibleType (#4377).
  • In ObjectEqualsForPrimitives, don't suggest replacing equal with == for floating-point values (#4392).

New checks:

Full Changelog: https://github.com/google/error-prone/compare/v2.27.1...v2.28.0

Commits
  • c71fd4e Release Error Prone 2.28.0
  • 32997f7 Bugfix assignment switch analysis in StatementSwitchToExpressionSwitch: if an...
  • 2dde254 Update references to javadoc APIs after the introduction of Markdown doc comm...
  • 5fef6e0 Yet another JUnitIncompatibleType crash fix.
  • c2df1b6 Refactor comment handling in tokenization to use a new ErrorProneComment clas...
  • 3fff610 Update hamcrest to v2.2
  • 6f265dd Add a disabled regression test for an UnusedVariable bug
  • 5eded87 Add an Error Prone check that reimplements javac sunapi warnings
  • 9e0fbf7 Prepare for a change to the return type of JCCompilationUnit#getImports in ...
  • 13be411 Handle null != CONST_CASE in YodaCondition
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
opensearch-trigger-bot[bot] commented 4 months ago

The backport to 2.x failed:

The process '/usr/bin/git' failed with exit code 128

To backport manually, run these commands in your terminal:

# Navigate to the root of your repository
cd $(git rev-parse --show-toplevel)
# Fetch latest updates from GitHub
git fetch
# Create a new working tree
git worktree add ../.worktrees/security/backport-2.x 2.x
# Navigate to the new working tree
pushd ../.worktrees/security/backport-2.x
# Create a new branch
git switch --create backport/backport-4389-to-2.x
# Cherry-pick the merged commit of this pull request and resolve the conflicts
git cherry-pick -x --mainline 1 f0021823752e67b9310224160857ca38dc770dc4
# Push it to GitHub
git push --set-upstream origin backport/backport-4389-to-2.x
# Go back to the original working tree
popd
# Delete the working tree
git worktree remove ../.worktrees/security/backport-2.x

Then, create a pull request where the base branch is 2.x and the compare/head branch is backport/backport-4389-to-2.x.