openshift / jenkins

Apache License 2.0
260 stars 446 forks source link

OCPBUGS-13869: Mitigate CVEs and other updates #1673

Closed coreydaley closed 1 year ago

coreydaley commented 1 year ago
openshift-ci[bot] commented 1 year ago

@coreydaley: all tests passed!

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available [here](https://git.k8s.io/community/contributors/guide/pull-requests.md). If you have questions or suggestions related to my behavior, please file an issue against the [kubernetes/test-infra](https://github.com/kubernetes/test-infra/issues/new?title=Prow%20issue:) repository. I understand the commands that are listed [here](https://go.k8s.io/bot-commands).
coreydaley commented 1 year ago

/assign @divyansh42 @mbharatk @apoorvajagtap for lgtm /label px-approved /label docs-approved /label qe-approved

openshift-ci-robot commented 1 year ago

@coreydaley: This pull request references Jira Issue OCPBUGS-13869, which is valid. The bug has been moved to the POST state.

3 validation(s) were run on this bug * bug is open, matching expected state (open) * bug target version (4.14.0) matches configured target version for branch (4.14.0) * bug is in the state New, which is one of the valid states (NEW, ASSIGNED, POST)

Requesting review from QA contact: /cc @coreydaley

The bug has been updated to refer to the pull request using the external bug tracker.

In response to [this](https://github.com/openshift/jenkins/pull/1673): >- Mitigate CVEs >- Fix jar command >- disable dependency checking for plugins >- update plugins to latest versions Instructions for interacting with me using PR comments are available [here](https://git.k8s.io/community/contributors/guide/pull-requests.md). If you have questions or suggestions related to my behavior, please file an issue against the [kubernetes/test-infra](https://github.com/kubernetes/test-infra/issues/new?title=Prow%20issue:) repository.
openshift-ci[bot] commented 1 year ago

@openshift-ci-robot: GitHub didn't allow me to request PR reviews from the following users: coreydaley.

Note that only openshift members and repo collaborators can review this PR, and authors cannot review their own PRs.

In response to [this](https://github.com/openshift/jenkins/pull/1673#issuecomment-1555966930): >@coreydaley: This pull request references [Jira Issue OCPBUGS-13869](https://issues.redhat.com//browse/OCPBUGS-13869), which is valid. The bug has been moved to the POST state. > >
3 validation(s) were run on this bug > >* bug is open, matching expected state (open) >* bug target version (4.14.0) matches configured target version for branch (4.14.0) >* bug is in the state New, which is one of the valid states (NEW, ASSIGNED, POST)

Requesting review from QA contact: /cc @coreydaley

The bug has been updated to refer to the pull request using the external bug tracker.

In response to [this](https://github.com/openshift/jenkins/pull/1673): >- Mitigate CVEs >- Fix jar command >- disable dependency checking for plugins >- update plugins to latest versions Instructions for interacting with me using PR comments are available [here](https://git.k8s.io/community/contributors/guide/pull-requests.md). If you have questions or suggestions related to my behavior, please file an issue against the [kubernetes/test-infra](https://github.com/kubernetes/test-infra/issues/new?title=Prow%20issue:) repository.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

openshift-ci[bot] commented 1 year ago

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: coreydaley, divyansh42

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files: - ~~[OWNERS](https://github.com/openshift/jenkins/blob/master/OWNERS)~~ [coreydaley,divyansh42] Approvers can indicate their approval by writing `/approve` in a comment Approvers can cancel approval by writing `/approve cancel` in a comment
openshift-ci-robot commented 1 year ago

@coreydaley: Jira Issue OCPBUGS-13869: All pull requests linked via external trackers have merged:

Jira Issue OCPBUGS-13869 has been moved to the MODIFIED state.

In response to [this](https://github.com/openshift/jenkins/pull/1673): >- Mitigate CVEs >- Fix jar command >- disable dependency checking for plugins >- update plugins to latest versions Instructions for interacting with me using PR comments are available [here](https://git.k8s.io/community/contributors/guide/pull-requests.md). If you have questions or suggestions related to my behavior, please file an issue against the [kubernetes/test-infra](https://github.com/kubernetes/test-infra/issues/new?title=Prow%20issue:) repository.
coreydaley commented 1 year ago

/cherry-pick release-4.13

openshift-cherrypick-robot commented 1 year ago

@coreydaley: new pull request created: #1674

In response to [this](https://github.com/openshift/jenkins/pull/1673#issuecomment-1556198915): >/cherry-pick release-4.13 Instructions for interacting with me using PR comments are available [here](https://git.k8s.io/community/contributors/guide/pull-requests.md). If you have questions or suggestions related to my behavior, please file an issue against the [kubernetes/test-infra](https://github.com/kubernetes/test-infra/issues/new?title=Prow%20issue:) repository.
jlebon commented 1 year ago

A bit late but, OOC what was the reasoning behind disabling dependency resolution? Is it to ensure that every dependent plugin is manually added at a specific version?