-
Notifications
You must be signed in to change notification settings - Fork 277
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Possible CVE fixes by Jenkins core upgrade #3727
Labels
enhancement
New Enhancement
Comments
jordarlu
added
enhancement
New Enhancement
untriaged
Issues that have not yet been triaged
labels
Jul 12, 2023
Thanks Jeff. |
github-project-automation
bot
moved this to Backlog
in OpenSearch Engineering Effectiveness
Jul 12, 2023
jordarlu
changed the title
CVE fix by Jenkins core upgrade
Possible CVE fixes by Jenkins core upgrade
Aug 28, 2023
Updating the possible CVE fixes list in case description by upgrading the Jenkins Core to the latest version. |
Need to also upgrade the Jenkins with monitoring plugin: |
Plan to add monitoring plugin in the week of 25th-Sept. |
list has been updated |
4 tasks
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Is your feature request related to a problem? Please describe
This is a consolidated issue to aggregate all CVEs that could be resolved by next Jenkins core upgrade
The list could be updated accordingly...
#3338 - spring-expression-5.3.24.jar
#3396 - spring-expression-5.3.24.jar
#3672 - jenkins-core-2.387.1.jar
#3673 - guava-31.1-jre.jar
#3832 - jenkins-core-2.387.1.jar
#4082 - jenkins-core-2.387.1.jar
#4081 - jenkins-core-2.387.1.jar
#4080 - jenkins-core-2.387.1.jar
#4078 - jenkins-core-2.387.1.jar
#4077 - jenkins-core-2.387.1.jar
#4406 - jenkins-core-2.387.1.jar
#4404 - jenkins-core-2.387.1.jar
#4589 - jenkins-core-2.387.1.jar
#4630 - jenkins-core-2.387.1.jar
Describe the solution you'd like
Next Jenkins core upgrade https://www.jenkins.io/changelog/
Determine the breaking changes with respect to jenkins as well as all its plugins in use.
See opensearch-project/opensearch-ci#333 for details on upgrade cycle.
Describe alternatives you've considered
No response
Acceptance Criteria
The text was updated successfully, but these errors were encountered: