NIFI-9008 Added Jetty modules to managed dependencies#5281
Closed
exceptionfactory wants to merge 1 commit intoapache:mainfrom
Closed
NIFI-9008 Added Jetty modules to managed dependencies#5281exceptionfactory wants to merge 1 commit intoapache:mainfrom
exceptionfactory wants to merge 1 commit intoapache:mainfrom
Conversation
- Updated OWASP dependency check suppressions with jetty-test-helper
pvillard31
approved these changes
Aug 5, 2021
Contributor
|
Merged, thanks @exceptionfactory |
krisztina-zsihovszki
pushed a commit
to krisztina-zsihovszki/nifi
that referenced
this pull request
Jun 28, 2022
- Updated OWASP dependency check suppressions with jetty-test-helper Signed-off-by: Pierre Villard <pierre.villard.fr@gmail.com> This closes apache#5281.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description of PR
NIFI-9008 Adds additional Jetty modules to the list of managed dependencies in the main Maven configuration.
The current configuration specifies a common version of Jetty across all components, but some components depend on additional Jetty libraries. The result of the current configuration is that extension bundles such as Solr and Hive 3 include one version of
jetty-serverand a different version ofjetty-httporjetty-io. For example,jetty-serverhas version 9.4.43 andjetty-iomay have version 9.4.20. This update lists additional Jetty modules to ensure extension components include the same Jetty version for all dependencies.This update also includes updates to the OWASP dependency check suppression configuration to avoid false positives related to
org.eclipse.jetty.toolchain:jetty-test-helper, which is currently version 5.5.In order to streamline the review of the contribution we ask you
to ensure the following steps have been taken:
For all changes:
Is there a JIRA ticket associated with this PR? Is it referenced
in the commit message?
Does your PR title start with NIFI-XXXX where XXXX is the JIRA number you are trying to resolve? Pay particular attention to the hyphen "-" character.
Has your PR been rebased against the latest commit within the target branch (typically
main)?Is your initial contribution a single, squashed commit? Additional commits in response to PR reviewer feedback should be made on this branch and pushed to allow change tracking. Do not
squashor use--forcewhen pushing to allow for clean monitoring of changes.For code changes:
mvn -Pcontrib-check clean installat the rootnififolder?LICENSEfile, including the mainLICENSEfile undernifi-assembly?NOTICEfile, including the mainNOTICEfile found undernifi-assembly?.displayNamein addition to .name (programmatic access) for each of the new properties?For documentation related changes:
Note:
Please ensure that once the PR is submitted, you check GitHub Actions CI for build issues and submit an update to your PR as soon as possible.