-
Notifications
You must be signed in to change notification settings - Fork 113
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Force using snakeyaml version 1.32 to fix CVE issue #535
Force using snakeyaml version 1.32 to fix CVE issue #535
Conversation
Signed-off-by: Angie Zhang <[email protected]>
Signed-off-by: Angie Zhang <[email protected]>
Signed-off-by: Angie Zhang <[email protected]>
Signed-off-by: Angie Zhang <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Can you add the issue number to the PR description ?
The build is failing Execution failed for task ':compileKotlin'.
Did the local gradle build pass?
Signed-off-by: Angie Zhang <[email protected]>
851f832
Signed-off-by: Angie Zhang <[email protected]>
Signed-off-by: Angie Zhang <[email protected]>
Signed-off-by: Angie Zhang <[email protected]>
Signed-off-by: Angie Zhang <[email protected]>
Signed-off-by: Angie Zhang <[email protected]>
f93ee3c
Signed-off-by: Angie Zhang <[email protected]>
Signed-off-by: Angie Zhang <[email protected]>
34f2bab
Signed-off-by: Angie Zhang <[email protected]>
Signed-off-by: Angie Zhang <[email protected]>
Signed-off-by: Angie Zhang <[email protected]>
The backport to
To backport manually, run these commands in your terminal: # Fetch latest updates from GitHub
git fetch
# Create a new working tree
git worktree add .worktrees/backport-1.x 1.x
# Navigate to the new working tree
cd .worktrees/backport-1.x
# Create a new branch
git switch --create backport/backport-535-to-1.x
# Cherry-pick the merged commit of this pull request and resolve the conflicts
git cherry-pick -x --mainline 1 b72eeaa7c54c1a55d167a8a29d3f4bef18df9ca8
# Push it to GitHub
git push --set-upstream origin backport/backport-535-to-1.x
# Go back to the original working tree
cd ../..
# Delete the working tree
git worktree remove .worktrees/backport-1.x Then, create a pull request where the |
…ct#535) * Force using snakeyaml version 1.32 to fix CVE issue Signed-off-by: Angie Zhang <[email protected]> * Force using snakeyaml version 1.32 to fix CVE issue Signed-off-by: Angie Zhang <[email protected]> * Force using snakeyaml version 1.32 to fix CVE issue Signed-off-by: Angie Zhang <[email protected]> * Force using snakeyaml version 1.32 to fix CVE issue Signed-off-by: Angie Zhang <[email protected]> * Kotlin version upgrade compatibility and jackson version upgrade Signed-off-by: Angie Zhang <[email protected]> * Kotlin version upgrade compatibility Signed-off-by: Angie Zhang <[email protected]> * detekt error fixing Signed-off-by: Angie Zhang <[email protected]> * Update detekt setting Signed-off-by: Angie Zhang <[email protected]> * Update detekt setting Signed-off-by: Angie Zhang <[email protected]> * Update gradle typo Signed-off-by: Angie Zhang <[email protected]> * Fix ktlint Signed-off-by: Angie Zhang <[email protected]> * Update gradle Signed-off-by: Angie Zhang <[email protected]> * Update gradle Signed-off-by: Angie Zhang <[email protected]> * Fix build.gradle Signed-off-by: Angie Zhang <[email protected]> * Fix jacoco tool version Signed-off-by: Angie Zhang <[email protected]> Signed-off-by: Angie Zhang <[email protected]> (cherry picked from commit b72eeaa) Signed-off-by: Siddhant Deshmukh [email protected]
) * Force using snakeyaml version 1.32 to fix CVE issue (#535) * Force using snakeyaml version 1.32 to fix CVE issue Signed-off-by: Angie Zhang <[email protected]> * Force using snakeyaml version 1.32 to fix CVE issue Signed-off-by: Angie Zhang <[email protected]> * Force using snakeyaml version 1.32 to fix CVE issue Signed-off-by: Angie Zhang <[email protected]> * Force using snakeyaml version 1.32 to fix CVE issue Signed-off-by: Angie Zhang <[email protected]> * Kotlin version upgrade compatibility and jackson version upgrade Signed-off-by: Angie Zhang <[email protected]> * Kotlin version upgrade compatibility Signed-off-by: Angie Zhang <[email protected]> * detekt error fixing Signed-off-by: Angie Zhang <[email protected]> * Update detekt setting Signed-off-by: Angie Zhang <[email protected]> * Update detekt setting Signed-off-by: Angie Zhang <[email protected]> * Update gradle typo Signed-off-by: Angie Zhang <[email protected]> * Fix ktlint Signed-off-by: Angie Zhang <[email protected]> * Update gradle Signed-off-by: Angie Zhang <[email protected]> * Update gradle Signed-off-by: Angie Zhang <[email protected]> * Fix build.gradle Signed-off-by: Angie Zhang <[email protected]> * Fix jacoco tool version Signed-off-by: Angie Zhang <[email protected]> Signed-off-by: Angie Zhang <[email protected]> (cherry picked from commit b72eeaa) Signed-off-by: Siddhant Deshmukh [email protected] * Force snakeyml 1.32 in spi/build Signed-off-by: Siddhant Deshmukh <[email protected]> * Fix typo Signed-off-by: Siddhant Deshmukh <[email protected]> Signed-off-by: Siddhant Deshmukh [email protected] Signed-off-by: Siddhant Deshmukh <[email protected]> Co-authored-by: Angie Zhang <[email protected]>
Signed-off-by: Angie Zhang [email protected]
Issue #, if available:
#493
#525
Description of changes:
CheckList:
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.