-
Notifications
You must be signed in to change notification settings - Fork 406
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[RHPAM-4734] [CVE-2023-33201] bouncycastle upgraded to 1.74 #2324
Conversation
Jenkins run fdb |
Jenkins run fdb |
@Ginxo i can see the problem with artifact we are trying to upgrade?
|
it seems bouncycastle stopped to release the artifacts with artifact id E.g bcprov-jdk15on was released until version 1.70 and bcprov-jdk15to18 is released for version 1.74. |
Jenkins run fdb |
Jenkins run fdb |
1 similar comment
Jenkins run fdb |
jenkins retest this please |
jenkins do fdb |
Jenkins run fdb |
2 similar comments
Jenkins run fdb |
Jenkins run fdb |
some of the tests from jbpm-workitems are failing, need further investigation:
|
already solved by kiegroup/jbpm-work-items#288 |
* bouncycastle upgraded to 1.74 * org.bouncycastle.bcp.*-jdk15on to org.bouncycastle.bcp.*-jdk15to18
* bouncycastle upgraded to 1.74 * org.bouncycastle.bcp.*-jdk15on to org.bouncycastle.bcp.*-jdk15to18
…2362) * bouncycastle upgraded to 1.74 * org.bouncycastle.bcp.*-jdk15on to org.bouncycastle.bcp.*-jdk15to18 Co-authored-by: Enrique Mingorance Cano <ginxaco@gmail.com>
…2361) * bouncycastle upgraded to 1.74 * org.bouncycastle.bcp.*-jdk15on to org.bouncycastle.bcp.*-jdk15to18 Co-authored-by: Enrique Mingorance Cano <ginxaco@gmail.com>
Thank you for submitting this pull request
JIRA:
referenced Pull Requests: (please edit the URLs of referenced pullrequests if they exist)
How to replicate CI configuration locally?
Build Chain tool does "simple" maven build(s), the builds are just Maven commands, but because the repositories relates and depends on each other and any change in API or class method could affect several of those repositories there is a need to use build-chain tool to handle cross repository builds and be sure that we always use latest version of the code for each repository.
build-chain tool is a build tool which can be used locally on command line or in Github Actions workflow(s), in case you need to change multiple repositories and send multiple dependent pull requests related with a change you can easily reproduce the same build by executing it on Github hosted environment or locally in your development environment. See local execution details to get more information about it.
A general local execution could be the following one, where the tool clones all dependent projects starting from the
-sp
one and it locally applies the pull request (if it exists) in order to reproduce a complete build scenario for the provided Pull Request.How to retest this PR or trigger a specific build:
a pull request please add comment: Jenkins retest (using this e.g. Jenkins retest this optional but no longer required)
for a full downstream build
run_fdb
a compile downstream build please add comment: Jenkins run cdb
a full production downstream build please add comment: Jenkins execute product fdb
an upstream build please add comment: Jenkins run upstream
for windows-specific os job add the label
windows_check
How to backport a pull request to a different branch?
In order to automatically create a backporting pull request please add one or more labels having the following format
backport-<branch-name>
, where<branch-name>
is the name of the branch where the pull request must be backported to (e.g.,backport-7.67.x
to backport the original PR to the7.67.x
branch).Once the original pull request is successfully merged, the automated action will create one backporting pull request per each label (with the previous format) that has been added.
If something goes wrong, the author will be notified and at this point a manual backporting is needed.