diff --git a/management-api-for-apache-cassandra-5.0.yaml b/management-api-for-apache-cassandra-5.0.yaml index 65ecbd12a2f..f99dcaef303 100644 --- a/management-api-for-apache-cassandra-5.0.yaml +++ b/management-api-for-apache-cassandra-5.0.yaml @@ -1,7 +1,7 @@ package: name: management-api-for-apache-cassandra-5.0 - version: "0.1.96" - epoch: 1 + version: "0.1.97" + epoch: 0 description: RESTful / Secure Management Sidecar for Apache Cassandra copyright: - license: Apache-2.0 @@ -25,7 +25,7 @@ pipeline: - uses: git-checkout with: repository: https://github.com/k8ssandra/management-api-for-apache-cassandra - expected-commit: 6ecf51489dca5e348cb36ba225ca214e236b9e14 + expected-commit: fa025a0ba0495ee85ab2ebbbf0b463a975f31d47 tag: v${{package.version}} # We can't (currently), use pombump, as this repo places license info as @@ -33,9 +33,8 @@ pipeline: # to handle this. Internal issue create to track. - uses: patch with: - patches: pom-xml.patch mgmt-api-server-pom-xml.patch mgmt-api-agent-5.0.x-pom-xml.patch - - - uses: maven/pombump + patches: | + 20250221-consolidated-cve-patches.patch - runs: | echo "Running build..." diff --git a/management-api-for-apache-cassandra-5.0/20250221-consolidated-cve-patches.patch b/management-api-for-apache-cassandra-5.0/20250221-consolidated-cve-patches.patch new file mode 100644 index 00000000000..70049cf3b80 --- /dev/null +++ b/management-api-for-apache-cassandra-5.0/20250221-consolidated-cve-patches.patch @@ -0,0 +1,160 @@ +From 0709dae3a8f8d930ecd3472a28584d4dba141405 Mon Sep 17 00:00:00 2001 +From: Kyle Steere +Date: Fri, 21 Feb 2025 10:53:39 -0600 +Subject: [PATCH] consolidated cve patches + +Signed-off-by: Kyle Steere +--- + management-api-agent-4.1.x/pom.xml | 10 ++++++++++ + management-api-agent-4.x/pom.xml | 10 ++++++++++ + management-api-agent-5.0.x/pom.xml | 12 +++++++++++- + management-api-agent-common/pom.xml | 10 ++++++++++ + management-api-server/pom.xml | 12 +++++++++++- + pom.xml | 8 ++++---- + 6 files changed, 56 insertions(+), 6 deletions(-) + +diff --git a/management-api-agent-4.1.x/pom.xml b/management-api-agent-4.1.x/pom.xml +index 3ffe2dd..a0bb29d 100644 +--- a/management-api-agent-4.1.x/pom.xml ++++ b/management-api-agent-4.1.x/pom.xml +@@ -19,6 +19,16 @@ + 4.1.8 + + ++ ++ io.netty ++ netty-common ++ ${netty.version} ++ ++ ++ io.netty ++ netty-handler ++ ${netty.version} ++ + + + org.slf4j +diff --git a/management-api-agent-4.x/pom.xml b/management-api-agent-4.x/pom.xml +index d0deb5d..5d87d29 100644 +--- a/management-api-agent-4.x/pom.xml ++++ b/management-api-agent-4.x/pom.xml +@@ -16,6 +16,16 @@ + ${revision} + datastax-mgmtapi-agent-4.x + ++ ++ io.netty ++ netty-common ++ ${netty.version} ++ ++ ++ io.netty ++ netty-handler ++ ${netty.version} ++ + + + org.slf4j +diff --git a/management-api-agent-5.0.x/pom.xml b/management-api-agent-5.0.x/pom.xml +index 63f9330..2c81dcb 100644 +--- a/management-api-agent-5.0.x/pom.xml ++++ b/management-api-agent-5.0.x/pom.xml +@@ -17,9 +17,19 @@ + datastax-mgmtapi-agent-5.0.x + + 5.0.3 +- 4.1.96.Final ++ 4.1.108.Final + + ++ ++ io.netty ++ netty-common ++ ${netty.version} ++ ++ ++ io.netty ++ netty-handler ++ ${netty.version} ++ + + + org.slf4j +diff --git a/management-api-agent-common/pom.xml b/management-api-agent-common/pom.xml +index b08c09a..907171f 100644 +--- a/management-api-agent-common/pom.xml ++++ b/management-api-agent-common/pom.xml +@@ -22,6 +22,16 @@ + true + + ++ ++ io.netty ++ netty-common ++ ${netty.version} ++ ++ ++ io.netty ++ netty-handler ++ ${netty.version} ++ + + io.k8ssandra + datastax-mgmtapi-common +diff --git a/management-api-server/pom.xml b/management-api-server/pom.xml +index e740a9e..bb63cb0 100644 +--- a/management-api-server/pom.xml ++++ b/management-api-server/pom.xml +@@ -16,7 +16,7 @@ + ${revision} + datastax-mgmtapi-server + +- 30.1.1-jre ++ 32.1.3-jre + 2.7.0 + 2.2.19 + 6.2.10.Final +@@ -26,6 +26,16 @@ + 2.17.0 + + ++ ++ io.netty ++ netty-common ++ ${netty.version} ++ ++ ++ io.netty ++ netty-handler ++ ${netty.version} ++ + + io.k8ssandra + datastax-mgmtapi-common +diff --git a/pom.xml b/pom.xml +index 7006a29..0e1568d 100644 +--- a/pom.xml ++++ b/pom.xml +@@ -16,16 +16,16 @@ + + build_version.sh + 0.1.0-SNAPSHOT +- 4.15.0 ++ 4.17.0 + 4.0.17 + 3.3.6 + 4.13.2 + 3.17.2 + 1.12.19 + build_version.sh +- 2.0.9 +- 1.4.14 +- 4.1.112.Final ++ 2.0.16 ++ 1.5.16 ++ 4.1.118.Final + 3.5.13 + 0.16.0 + +-- +2.43.0 diff --git a/management-api-for-apache-cassandra-5.0/mgmt-api-agent-5.0.x-pom-xml.patch b/management-api-for-apache-cassandra-5.0/mgmt-api-agent-5.0.x-pom-xml.patch deleted file mode 100755 index fa547c4eb76..00000000000 --- a/management-api-for-apache-cassandra-5.0/mgmt-api-agent-5.0.x-pom-xml.patch +++ /dev/null @@ -1,13 +0,0 @@ -diff --git a/management-api-agent-5.0.x/pom.xml b/management-api-agent-5.0.x/pom.xml -index 63f9330..d7fc19b 100644 ---- a/management-api-agent-5.0.x/pom.xml -+++ b/management-api-agent-5.0.x/pom.xml -@@ -17,7 +17,7 @@ - datastax-mgmtapi-agent-5.0.x - - 5.0.3 -- 4.1.96.Final -+ 4.1.108.Final - - - diff --git a/management-api-for-apache-cassandra-5.0/mgmt-api-server-pom-xml.patch b/management-api-for-apache-cassandra-5.0/mgmt-api-server-pom-xml.patch deleted file mode 100644 index e452d65795a..00000000000 --- a/management-api-for-apache-cassandra-5.0/mgmt-api-server-pom-xml.patch +++ /dev/null @@ -1,13 +0,0 @@ -diff --git a/management-api-server/pom.xml b/management-api-server/pom.xml -index e740a9e..4b47216 100644 ---- a/management-api-server/pom.xml -+++ b/management-api-server/pom.xml -@@ -16,7 +16,7 @@ - ${revision} - datastax-mgmtapi-server - -- 30.1.1-jre -+ 32.0.0-jre - 2.7.0 - 2.2.19 - 6.2.10.Final diff --git a/management-api-for-apache-cassandra-5.0/pom-xml.patch b/management-api-for-apache-cassandra-5.0/pom-xml.patch deleted file mode 100644 index 9f98b65bc29..00000000000 --- a/management-api-for-apache-cassandra-5.0/pom-xml.patch +++ /dev/null @@ -1,13 +0,0 @@ -diff --git a/pom.xml b/pom.xml -index bd62cd2..15ed516 100644 ---- a/pom.xml -+++ b/pom.xml -@@ -16,7 +16,7 @@ - - build_version.sh - 0.1.0-SNAPSHOT -- 4.15.0 -+ 4.17.0 - 4.0.16 - 3.3.6 - 4.13.2 \ No newline at end of file diff --git a/management-api-for-apache-cassandra-5.0/pombump-deps.yaml b/management-api-for-apache-cassandra-5.0/pombump-deps.yaml deleted file mode 100644 index c946fdf71c7..00000000000 --- a/management-api-for-apache-cassandra-5.0/pombump-deps.yaml +++ /dev/null @@ -1,4 +0,0 @@ -patches: - - groupId: io.netty - artifactId: netty-handler - version: 4.1.118.Final