airbyte-platform icon indicating copy to clipboard operation
airbyte-platform copied to clipboard

Dependencies upgrades to fix several vulnerabilities reported - Premium support

Open mauricioalarcon opened this issue 2 years ago • 14 comments
trafficstars

Bringing selective changes from this PR into latest upstream origin/main.

As per comment from Marcos this includes only the changes "upgrade the packages and addition of jsonsmart library."

What

Simple version bumping to fix several reported vulnerarbilities in several packages and modules

How

Bump accordingly to deps.toml file and adjusted one shaded dependency that's not longer part of guava, added original JetBrains NotNull annotation for airbyte-commons-worker/src/main/java/io/airbyte/workers/process/KubeProcessFactory.java

Recommended reading order

n/a

Can this PR be safely reverted / rolled back?

If you know that your PR is backwards-compatible and can be simply reverted or rolled back, check the YES box.

Otherwise if your PR has a breaking change, like a database migration for example, check the NO box.

If unsure, leave it blank.

  • [x] YES 💚
  • [ ] NO ❌

🚨 User Impact 🚨

Are there any breaking changes? What is the end result perceived by the user? If yes, please merge this PR with the 🚨🚨 emoji so changelog authors can further highlight this if needed.

Not to our knowledge, all of these changes and bumps seems to pass all the tests on our side.

mauricioalarcon avatar Jun 29 '23 23:06 mauricioalarcon

Hello @mauricioalarcon the engineers will take a look later this week in your contribution.

marcosmarxm avatar Jul 04 '23 14:07 marcosmarxm

Your branch is not currently up-to-date with main. Please update your branch before attempting to snapshot your PR.

github-actions[bot] avatar Jul 04 '23 14:07 github-actions[bot]

/create-oss-pr

supertopher avatar Jul 07 '23 16:07 supertopher

Your branch is not currently up-to-date with main. Please update your branch before attempting to snapshot your PR.

github-actions[bot] avatar Jul 07 '23 17:07 github-actions[bot]

/create-oss-pr

supertopher avatar Jul 10 '23 15:07 supertopher

Your branch is not currently up-to-date with main. Please update your branch before attempting to snapshot your PR.

github-actions[bot] avatar Jul 10 '23 15:07 github-actions[bot]

it's all coming back to me now.

I copypasta-ed this PR over here so I could update it to work with snapshots which is how we merge OSS PRs with our shared cloud/OSS code

then the create-a-pr code was broken due to a version mismatch, now to should work. I'll update here when I get the results of testing

supertopher avatar Jul 10 '23 15:07 supertopher

Your branch is not currently up-to-date with main. Please update your branch before attempting to snapshot your PR.

github-actions[bot] avatar Jul 10 '23 15:07 github-actions[bot]

We test theses OSS PR against our internal cloud product as well.

Keeping these in sync helps to make sure changes we make to cloud work in OSS and visa versa.

This PR failed our internal tests. I'm pushing for the team whose test is broken by these changes to take a look. It is very likely that our team will work to fix this without the need for your intervention @mauricioalarcon

Thanks again for your contribution.

I will tell you when I have more to report. For now waiting on an internal team to review a test failure only seen in the cloud test suite.

supertopher avatar Jul 13 '23 14:07 supertopher

Your branch is not currently up-to-date with main. Please update your branch before attempting to snapshot your PR.

github-actions[bot] avatar Jul 13 '23 14:07 github-actions[bot]

That's excellent news; thank you, @supertopher - I'm looking forward to the following report, and I'll let up to you close this one once we're done.

mauricioalarcon avatar Jul 13 '23 18:07 mauricioalarcon

Your branch is not currently up-to-date with main. Please update your branch before attempting to snapshot your PR.

github-actions[bot] avatar Jul 13 '23 18:07 github-actions[bot]

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.


mauricioalarcon seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account.
You have signed the CLA already but the status is still pending? Let us recheck it.

CLAassistant avatar May 07 '24 21:05 CLAassistant

Your branch is not currently up-to-date with main. Please update your branch before attempting to snapshot your PR.

github-actions[bot] avatar May 07 '24 21:05 github-actions[bot]

Old

davinchia avatar Jul 12 '24 01:07 davinchia

Your branch is not currently up-to-date with main. Please update your branch before attempting to snapshot your PR.

github-actions[bot] avatar Jul 12 '24 01:07 github-actions[bot]