Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

upgrade CXF to v3.4.3 #1210

Merged
merged 1 commit into from
Jun 14, 2021
Merged

Conversation

cjcjameson
Copy link
Contributor

  1. Category:

Maintenance

  1. Github Issue # or road-map entry, if available:

#1208

  1. Description of changes:

upgrade CXF to v3.4.3

  1. Why these changes are required?

According to https://github.com/opensearch-project/.github/edit/main/SECURITY.md , I'm not supposed to say.

  1. What is the old behavior before changes and new behavior after changes? (Please add any example/logs/screen-shot if available)

  2. Testing done: (Please provide details of testing done: Unit testing, integration testing and manual testing)

mvn package on my local machine

  1. TO-DOs, if any: (Please describe pending items and provide Github issues# for each of them)

  2. Is it backport from main branch? (If yes, please add backport PR # and commits #)

By making a contribution to this project, I certify that:

(a) The contribution was created in whole or in part by me and I
have the right to submit it under the open source license
indicated in the file; or

(b) The contribution is based upon previous work that, to the best
of my knowledge, is covered under an appropriate open source
license and I have the right under that license to submit that
work with modifications, whether created in whole or in part
by me, under the same open source license (unless I am
permitted to submit under a different license), as indicated
in the file; or

(c) The contribution was provided directly to me by some other
person who certified (a), (b) or (c) and I have not modified
it.

(d) I understand and agree that this project and the contribution
are public and that a record of the contribution (including all
personal information I submit with it, including my sign-off) is
maintained indefinitely and may be redistributed consistent with
this project or the open source license(s) involved.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

Signed-off-by: C.J. Jameson <cjcjameson@gmail.com>
@cjcjameson cjcjameson requested a review from a team May 28, 2021 04:02
Copy link
Contributor

@vrozov vrozov left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

OK to upgrade with note that CVE-2021-22696 does not impact cxf-rt-rs-security-jose used by the security plugin

@cjcjameson
Copy link
Contributor Author

@peterzhuamazon @debjanibnrj @hardik-k-shah can one of you also approve?

@cjcjameson
Copy link
Contributor Author

@vrozov @hardik-k-shah thanks for the approval. Who can be an official second approver?
image

@hardik-k-shah hardik-k-shah merged commit 70e93cf into opensearch-project:main Jun 14, 2021
@cliu123 cliu123 added the maintenance Project maintenance label Jun 29, 2021
lbreinig pushed a commit to lbreinig/security that referenced this pull request Dec 23, 2021
Signed-off-by: C.J. Jameson <cjcjameson@gmail.com>
wuychn pushed a commit to ochprince/security that referenced this pull request Mar 16, 2023
Signed-off-by: C.J. Jameson <cjcjameson@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
maintenance Project maintenance
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants