Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Backport 2.x]Bump version of jgit to 6.7.0.202309050840-r to fix CVE-2023-4759 (#1… #10166

Merged
merged 3 commits into from
Sep 22, 2023

Conversation

Poojita-Raj
Copy link
Contributor

…0147)

  • change dependency version of jgit

  • add changelog


Description

[Describe what this change achieves]

Related Issues

Resolves #[Issue number to be closed when this PR is merged]

Check List

  • New functionality includes testing.
    • All tests pass
  • New functionality has been documented.
    • New functionality has javadoc added
  • Commits are signed per the DCO using --signoff
  • Commit changes are listed out in CHANGELOG.md file (See: Changelog)

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

…ensearch-project#10147)

* change dependency version of jgit

Signed-off-by: Poojita Raj <poojiraj@amazon.com>

* add changelog

Signed-off-by: Poojita Raj <poojiraj@amazon.com>

---------

Signed-off-by: Poojita Raj <poojiraj@amazon.com>
@Poojita-Raj Poojita-Raj changed the title Bump version of jgit to 6.7.0.202309050840-r to fix CVE-2023-4759 (#1… [Backport 2.x]Bump version of jgit to 6.7.0.202309050840-r to fix CVE-2023-4759 (#1… Sep 21, 2023
@github-actions
Copy link
Contributor

github-actions bot commented Sep 21, 2023

Compatibility status:

Checks if related components are compatible with change 97553a2

Incompatible components

Skipped components

Compatible components

Compatible components: [https://github.com/opensearch-project/security.git, https://github.com/opensearch-project/security-analytics.git, https://github.com/opensearch-project/custom-codecs.git, https://github.com/opensearch-project/geospatial.git, https://github.com/opensearch-project/index-management.git, https://github.com/opensearch-project/notifications.git, https://github.com/opensearch-project/sql.git, https://github.com/opensearch-project/neural-search.git, https://github.com/opensearch-project/job-scheduler.git, https://github.com/opensearch-project/observability.git, https://github.com/opensearch-project/k-nn.git, https://github.com/opensearch-project/cross-cluster-replication.git, https://github.com/opensearch-project/alerting.git, https://github.com/opensearch-project/anomaly-detection.git, https://github.com/opensearch-project/asynchronous-search.git, https://github.com/opensearch-project/common-utils.git, https://github.com/opensearch-project/ml-commons.git, https://github.com/opensearch-project/performance-analyzer.git, https://github.com/opensearch-project/reporting.git, https://github.com/opensearch-project/performance-analyzer-rca.git]

@github-actions
Copy link
Contributor

Gradle Check (Jenkins) Run Completed with:

@codecov
Copy link

codecov bot commented Sep 21, 2023

Codecov Report

Merging #10166 (97553a2) into 2.x (ad9355f) will not change coverage.
Report is 8 commits behind head on 2.x.
The diff coverage is 90.29%.

@@            Coverage Diff             @@
##                2.x   #10166    +/-   ##
==========================================
  Coverage     70.83%   70.83%            
- Complexity    58250    58305    +55     
==========================================
  Files          4811     4812     +1     
  Lines        275316   275412    +96     
  Branches      40464    40489    +25     
==========================================
+ Hits         195033   195101    +68     
- Misses        63576    63697   +121     
+ Partials      16707    16614    -93     
Files Changed Coverage Δ
...ava/org/opensearch/index/mapper/MapperService.java 74.79% <ø> (ø)
...arch/index/recovery/RemoteStoreRestoreService.java 12.03% <0.00%> (ø)
...g/opensearch/index/query/BoostingQueryBuilder.java 87.25% <66.66%> (-1.29%) ⬇️
...rg/opensearch/index/query/SpanNotQueryBuilder.java 90.43% <66.66%> (-1.31%) ⬇️
...nsearch/index/query/SpanMultiTermQueryBuilder.java 82.02% <75.00%> (-0.34%) ⬇️
...org/opensearch/index/query/DisMaxQueryBuilder.java 88.00% <85.71%> (-0.18%) ⬇️
...g/opensearch/index/query/SpanNearQueryBuilder.java 82.60% <85.71%> (+0.12%) ⬆️
...org/opensearch/index/query/SpanOrQueryBuilder.java 89.33% <85.71%> (-0.38%) ⬇️
...a/org/opensearch/gateway/ClusterStateUpdaters.java 80.82% <87.50%> (+0.51%) ⬆️
...ibs/core/src/main/java/org/opensearch/Version.java 83.04% <100.00%> (+0.07%) ⬆️
... and 10 more

... and 458 files with indirect coverage changes

Signed-off-by: Poojita Raj <poojiraj@amazon.com>
@github-actions
Copy link
Contributor

Gradle Check (Jenkins) Run Completed with:

Signed-off-by: Poojita Raj <poojiraj@amazon.com>
@github-actions
Copy link
Contributor

Gradle Check (Jenkins) Run Completed with:

@github-actions
Copy link
Contributor

Gradle Check (Jenkins) Run Completed with:

@Rishikesh1159 Rishikesh1159 merged commit c1c1cee into opensearch-project:2.x Sep 22, 2023
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants