Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade jackson databind to 2.13.2.2 to match core's version.properties #2000

Merged

Conversation

cwperks
Copy link
Member

@cwperks cwperks commented Aug 8, 2022

Description

Upgrade of jackson-databind to address CVE-2020-36518. The version now matches the version in core's version.properties. This should be backported to 1.3.

  • Category (Enhancement, New feature, Bug fix, Test fix, Refactoring, Maintenance, Documentation)

Maintenance

Check List

  • New functionality includes testing
  • New functionality has been documented
  • Commits are signed per the DCO using --signoff

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

@cwperks cwperks requested a review from a team August 8, 2022 18:21
@codecov-commenter
Copy link

codecov-commenter commented Aug 8, 2022

Codecov Report

Merging #2000 (997dc40) into 1.x (b6dbb49) will decrease coverage by 0.01%.
The diff coverage is n/a.

@@             Coverage Diff              @@
##                1.x    #2000      +/-   ##
============================================
- Coverage     64.59%   64.58%   -0.02%     
  Complexity     3215     3215              
============================================
  Files           247      247              
  Lines         17358    17358              
  Branches       3085     3085              
============================================
- Hits          11213    11210       -3     
- Misses         4594     4597       +3     
  Partials       1551     1551              
Impacted Files Coverage Δ
...security/auditlog/sink/InternalOpenSearchSink.java 69.23% <0.00%> (-11.54%) ⬇️

Help us with your feedback. Take ten seconds to tell us how you rate us. Have a feature suggestion? Share it here.

@cwperks cwperks force-pushed the upgrade-jackson-databind-1.x branch from a4302be to 95ef4a8 Compare August 8, 2022 20:37
@cwperks
Copy link
Member Author

cwperks commented Aug 8, 2022

The org.opensearch.plugin:transport-netty4-client:1.4.0-SNAPSHOT has not been updated since March and includes outdated netty 4.1.73.Final. The latest version of 1.3 which is 1.3.5-SNAPSHOT includes netty 4.1.79.Final so the whitesource error can be ignored.

peternied
peternied previously approved these changes Aug 8, 2022
…ion.properties and upgrade kafka dependencies

Signed-off-by: Craig Perkins <cwperx@amazon.com>
@cwperks cwperks force-pushed the upgrade-jackson-databind-1.x branch from bb1c0d1 to 997dc40 Compare August 9, 2022 15:06
@cwperks cwperks added the backport 1.3 backport to 1.3 branch label Aug 9, 2022
@cliu123
Copy link
Member

cliu123 commented Aug 9, 2022

@cwperks Sorry if I missed any discussion related to the question. Is it possible to get the versions from OpenSearch core directly, so security plugin wouldn't have to handle the versions?

@peternied peternied merged commit da24100 into opensearch-project:1.x Aug 9, 2022
@cwperks
Copy link
Member Author

cwperks commented Aug 9, 2022

@cliu123 I was wondering the same thing and initially tried matching the main branch by using references to versions like ${versions.jackson_databind}, but the reference could not be found. Prior to 2.1 we do not have any references to versions. I believe this change enabled us to reference versions from core.

@opensearch-trigger-bot
Copy link
Contributor

The backport to 1.3 failed:

The process '/usr/bin/git' failed with exit code 1

To backport manually, run these commands in your terminal:

# Fetch latest updates from GitHub
git fetch
# Create a new working tree
git worktree add .worktrees/backport-1.3 1.3
# Navigate to the new working tree
cd .worktrees/backport-1.3
# Create a new branch
git switch --create backport/backport-2000-to-1.3
# Cherry-pick the merged commit of this pull request and resolve the conflicts
git cherry-pick -x --mainline 1 da24100ccc373dedb50d20ba18be96b5eb2d8b01
# Push it to GitHub
git push --set-upstream origin backport/backport-2000-to-1.3
# Go back to the original working tree
cd ../..
# Delete the working tree
git worktree remove .worktrees/backport-1.3

Then, create a pull request where the base branch is 1.3 and the compare/head branch is backport/backport-2000-to-1.3.

cwperks added a commit to cwperks/security that referenced this pull request Aug 9, 2022
…ion.properties and upgrade kafka dependencies (opensearch-project#2000)

Signed-off-by: Craig Perkins <cwperx@amazon.com>
(cherry picked from commit da24100)
peternied pushed a commit that referenced this pull request Aug 12, 2022
…ion.properties and upgrade kafka dependencies (#2000) (#2004)

Signed-off-by: Craig Perkins <cwperx@amazon.com>
(cherry picked from commit da24100)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
backport 1.3 backport to 1.3 branch
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants