Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Require Jenkins 2.426.3 or newer #380

Merged

Conversation

MarkEWaite
Copy link
Contributor

Require Jenkins 2.426.3 or newer

Plugin installation statistics show that 80% of the installations of 787.v665fcf2a_830b_ (6 months old) are already running Jenkins 2.426.3.

SECURITY-3314 advises users to upgrade to Jenkins 2.426.3 or newer to resolve a critical security vulnerability.

This will need to be merged if the experimental upgrade of the promoted builds optional dependency is successful. Refer to:

Testing done

Relying on ci.jenkins.io to run the tests. Tests pass for:

Submitter checklist

https://stats.jenkins.io/pluginversions/parameterized-trigger.html shows
that 80% of the installations of 787.v665fcf2a_830b_ release (6 months
old) are already running Jenkins 2.426.3.

https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3314
advises users to upgrade to Jenkins 2.426.3 or newer to resolve a critical
security vulnerability.
@MarkEWaite MarkEWaite requested a review from a team as a code owner May 6, 2024 01:04
@MarkEWaite MarkEWaite marked this pull request as draft May 6, 2024 01:39
@MarkEWaite MarkEWaite marked this pull request as ready for review May 6, 2024 11:13
@MarkEWaite
Copy link
Contributor Author

Tests pass in the plugin BOM when the optional dependency on promoted builds plugin is updated to the same new value in both the git plugin and the parameterized trigger plugin. That means we'll need a release of git plugin and a release of parameterized trigger plugin in the same plugin BOM release.

@MarkEWaite MarkEWaite merged commit adab97e into jenkinsci:master May 6, 2024
14 checks passed
@MarkEWaite MarkEWaite deleted the require-jenkins-2.426.3-or-newer branch May 6, 2024 11:14
@MarkEWaite MarkEWaite removed the on-hold label May 6, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants