Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Removes benchmark folder from 2.x branch to resolve CVEs coming from the folder #1875

Merged
merged 1 commit into from
Jul 24, 2024

Conversation

shatejas
Copy link
Collaborator

Description

Addressing advisories https://advisories.aws.barahmand.com/vulnerabilities/k-NN:%20OpenSearch%20Plugin/origin/main

Related Issues

Check List

  • New functionality includes testing.
  • New functionality has been documented.
  • API changes companion pull request created.
  • Commits are signed per the DCO using --signoff.
  • Public documentation issue/PR created.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

Copy link
Member

@VijayanB VijayanB left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

@heemin32
Copy link
Collaborator

Are the CVEs coming only from 2.x branch but not main branch? How is that?

@VijayanB
Copy link
Member

Are the CVEs coming only from 2.x branch but not main branch? How is that?

@heemin32 You are right. The CVEs are at both main and 2.x. I believe, during release we have strict guideline that no CVEs should be present. Ideally we should fix at main and backport. However, given the issues are with benchmarks/* ( not part of k-nn and they won't be shipped with product ) and imo, we don't need this code at 2.x branch , so it is safe to delete from 2.x branch. We are also working on permanently moving all features from this folder to OSB, so that we can remove from main itself.

@shatejas
Copy link
Collaborator Author

Are the CVEs coming only from 2.x branch but not main branch? How is that?

I did not remove it as perf test are needed during release testing. Can remove it once osb is ready

@heemin32
Copy link
Collaborator

As long as we are also going to remove benchmark folder from main as well I am fine.

@navneet1v navneet1v merged commit deea892 into opensearch-project:2.x Jul 24, 2024
86 of 100 checks passed
@navneet1v
Copy link
Collaborator

@shatejas lets port this PR to main branch too, if not already done.

@naveentatikonda
Copy link
Member

@shatejas Shouldn't we backport this PR to 2.16 branch to fix the CVEs in 2.16 ?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants