Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update spotless and eclipse dependencies #1450

Merged
merged 5 commits into from
Feb 5, 2024

Conversation

ryanbogan
Copy link
Member

Description

Updates dependencies to fix CVEs

Check List

  • New functionality includes testing.
    • All tests pass
  • New functionality has been documented.
    • New functionality has javadoc added
  • Commits are signed as per the DCO using --signoff

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

@ryanbogan ryanbogan changed the title Update dependencies Update spotless and eclipse dependencies Feb 5, 2024
Copy link

codecov bot commented Feb 5, 2024

Codecov Report

All modified and coverable lines are covered by tests ✅

Comparison is base (5f9511b) 85.07% compared to head (8eac24f) 85.05%.
Report is 2 commits behind head on main.

Additional details and impacted files
@@             Coverage Diff              @@
##               main    #1450      +/-   ##
============================================
- Coverage     85.07%   85.05%   -0.02%     
+ Complexity     1278     1277       -1     
============================================
  Files           167      167              
  Lines          5207     5207              
  Branches        493      493              
============================================
- Hits           4430     4429       -1     
  Misses          570      570              
- Partials        207      208       +1     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

Signed-off-by: Ryan Bogan <[email protected]>
Signed-off-by: Ryan Bogan <[email protected]>
Copy link
Member

@vamshin vamshin left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! Thanks

@ryanbogan ryanbogan merged commit fceb8f8 into opensearch-project:main Feb 5, 2024
49 checks passed
opensearch-trigger-bot bot pushed a commit that referenced this pull request Feb 5, 2024
* Update spotless and eclipse dependencies

Signed-off-by: Ryan Bogan <[email protected]>

* Update dependencies for spotless and eclipse

Signed-off-by: Ryan Bogan <[email protected]>

* Add Changelog

Signed-off-by: Ryan Bogan <[email protected]>

* Add comment

Signed-off-by: Ryan Bogan <[email protected]>

* Add resources force resolution for eclipse

Signed-off-by: Ryan Bogan <[email protected]>

---------

Signed-off-by: Ryan Bogan <[email protected]>
(cherry picked from commit fceb8f8)
@ryanbogan ryanbogan deleted the update_dependencies branch February 5, 2024 21:29
ryanbogan added a commit that referenced this pull request Feb 5, 2024
* Update spotless and eclipse dependencies

Signed-off-by: Ryan Bogan <[email protected]>

* Update dependencies for spotless and eclipse

Signed-off-by: Ryan Bogan <[email protected]>

* Add Changelog

Signed-off-by: Ryan Bogan <[email protected]>

* Add comment

Signed-off-by: Ryan Bogan <[email protected]>

* Add resources force resolution for eclipse

Signed-off-by: Ryan Bogan <[email protected]>

---------

Signed-off-by: Ryan Bogan <[email protected]>
(cherry picked from commit fceb8f8)

Co-authored-by: Ryan Bogan <[email protected]>
@dbwiddis
Copy link
Member

A bit late to review this as it's been merged/released but only really effects running spotless.

The GHSA stating 4.29 is in error. The latest version of eclipse runtime is 3.30, the latest of eclipse resources is 3.20. I suspect spotless would fail if you tried to run it on this branch now :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants