Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Require Jenkins 2.426.3 or newer #97

Merged

Conversation

MarkEWaite
Copy link
Contributor

Require Jenkins 2.426.3 or newer

Installation statistics show that 67% of the installations of the 2.5 release are already using Jenkins 2.426.3.

SECURITY-3314 is a critical vulnerability that is resolved in 2.426.3. The advisory recommends that all users upgrade to 2.426.3 or newer.

Users should upgrade to 2.426.3 and most of the users of the current release have already upgraded.

Also includes additional changes to reduce maintenance.

  • d36bf2c - Use deep cloning library 1.11.1 as released in 2022
  • 36d0580 - Remove maintainers that have exited
  • fbfd544 - Reduce commons-vfs2 exclusions

Testing done

Automated tests pass.

Interactive testing not yet performed.

Submitter checklist

Repository moved from uk.com.robust-it to io.github.kostaskougios and
then forked to https://github.com/chadlwilson/cloning and then forked
to https://github.com/aem-design/cloning

https://mvnrepository.com/artifact/uk.com.robust-it/cloning
shows that it has moved to
https://mvnrepository.com/artifact/io.github.kostaskougios/cloning with
releases after 2019 in the https://github.com/kostaskougios/cloning/
repository.  Last release in 2020.

Forked to https://github.com/chadlwilson/cloning and then forked
to https://github.com/chadlwilson/cloning and then forked to
https://github.com/aem-design/cloning where version 1.11.1 was released
to Apache Maven Central.

https://github.com/aem-design/cloning/releases/tag/1.11.1 is from Dec 2022.
The commons-lang3 plugin does not require an exclusion.
https://stats.jenkins.io/pluginversions/ivy.html shows that 67% of the
installations of the 2.5 release are already using Jenkins 2.426.3.

https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3314 is
a critical vulnerability that is resolved in 2.426.3.  The advisory
recommends that all users upgrade to 2.426.3 or newer.
@MarkEWaite MarkEWaite requested a review from a team as a code owner May 10, 2024 01:40
@MarkEWaite MarkEWaite added the chore Reduce maintenance or improve infrastructure label May 10, 2024
@MarkEWaite MarkEWaite merged commit 4068e79 into jenkinsci:master May 10, 2024
16 checks passed
@MarkEWaite MarkEWaite deleted the require-jenkins-2.426.3-or-newer branch May 10, 2024 02:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
chore Reduce maintenance or improve infrastructure
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant