tez icon indicating copy to clipboard operation
tez copied to clipboard

TEZ-4419: Upgrade node and yarn version and fix npm security issues in Tez UI module

Open amanraj2520 opened this issue 2 years ago • 4 comments

Upgrade node and yarn version and fix npm security issues in Tez UI module Track this issue: https://issues.apache.org/jira/browse/TEZ-4419

The RFC documentation which adds selective dependency resolution in the description : https://github.com/yarnpkg/rfcs/blob/master/implemented/0000-selective-versions-resolutions.md

amanraj2520 avatar Jun 06 '22 11:06 amanraj2520

:broken_heart: -1 overall

Vote Subsystem Runtime Comment
+0 :ok: reexec 17m 36s Docker mode activated.
_ Prechecks _
+1 :green_heart: dupname 0m 0s No case conflicting files found.
+1 :green_heart: @author 0m 0s The patch does not contain any @author tags.
-1 :x: test4tests 0m 0s The patch doesn't appear to include any new or modified tests. Please justify why no new tests are needed for this patch. Also please list what manual steps were performed to verify this patch.
_ master Compile Tests _
+0 :ok: mvndep 6m 40s Maven dependency ordering for branch
+1 :green_heart: mvninstall 10m 38s master passed
+1 :green_heart: compile 3m 39s master passed with JDK Private Build-11.0.15+10-Ubuntu-0ubuntu0.20.04.1
+1 :green_heart: compile 3m 30s master passed with JDK Private Build-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07
+1 :green_heart: javadoc 2m 55s master passed with JDK Private Build-11.0.15+10-Ubuntu-0ubuntu0.20.04.1
+1 :green_heart: javadoc 2m 21s master passed with JDK Private Build-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07
_ Patch Compile Tests _
+0 :ok: mvndep 0m 16s Maven dependency ordering for patch
+1 :green_heart: mvninstall 5m 42s the patch passed
+1 :green_heart: compile 3m 31s the patch passed with JDK Private Build-11.0.15+10-Ubuntu-0ubuntu0.20.04.1
+1 :green_heart: javac 3m 31s the patch passed
+1 :green_heart: compile 3m 13s the patch passed with JDK Private Build-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07
+1 :green_heart: javac 3m 13s the patch passed
+1 :green_heart: whitespace 0m 0s The patch has no whitespace issues.
+1 :green_heart: xml 0m 3s The patch has no ill-formed XML file.
+1 :green_heart: javadoc 2m 46s the patch passed with JDK Private Build-11.0.15+10-Ubuntu-0ubuntu0.20.04.1
+1 :green_heart: javadoc 2m 24s the patch passed with JDK Private Build-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07
_ Other Tests _
+1 :green_heart: unit 1m 57s tez-ui in the patch passed.
+1 :green_heart: unit 66m 51s root in the patch passed.
+1 :green_heart: asflicense 1m 25s The patch does not generate ASF License warnings.
136m 40s
Subsystem Report/Notes
Docker ClientAPI=1.41 ServerAPI=1.41 base: https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-215/1/artifact/out/Dockerfile
GITHUB PR https://github.com/apache/tez/pull/215
JIRA Issue TEZ-4419
Optional Tests dupname asflicense javac javadoc unit xml compile
uname Linux 5aeefad56750 4.15.0-175-generic #184-Ubuntu SMP Thu Mar 24 17:48:36 UTC 2022 x86_64 x86_64 x86_64 GNU/Linux
Build tool maven
Personality personality/tez.sh
git revision master / cf9e3ff30
Default Java Private Build-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07
Multi-JDK versions /usr/lib/jvm/java-11-openjdk-amd64:Private Build-11.0.15+10-Ubuntu-0ubuntu0.20.04.1 /usr/lib/jvm/java-8-openjdk-amd64:Private Build-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07
Test Results https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-215/1/testReport/
Max. process+thread count 2089 (vs. ulimit of 5500)
modules C: tez-ui . U: .
Console output https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-215/1/console
versions git=2.25.1 maven=3.6.3
Powered by Apache Yetus 0.12.0 https://yetus.apache.org

This message was automatically generated.

tez-yetus avatar Jun 06 '22 14:06 tez-yetus

@abstractdog @rbalamohan Can you please help with the review?

guptanikhil007 avatar Jun 06 '22 14:06 guptanikhil007

:broken_heart: -1 overall

Vote Subsystem Runtime Comment
+0 :ok: reexec 1m 31s Docker mode activated.
_ Prechecks _
+1 :green_heart: dupname 0m 0s No case conflicting files found.
+1 :green_heart: @author 0m 0s The patch does not contain any @author tags.
-1 :x: test4tests 0m 0s The patch doesn't appear to include any new or modified tests. Please justify why no new tests are needed for this patch. Also please list what manual steps were performed to verify this patch.
_ master Compile Tests _
+0 :ok: mvndep 6m 29s Maven dependency ordering for branch
+1 :green_heart: mvninstall 10m 36s master passed
+1 :green_heart: compile 3m 38s master passed with JDK Private Build-11.0.15+10-Ubuntu-0ubuntu0.20.04.1
+1 :green_heart: compile 3m 26s master passed with JDK Private Build-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07
+1 :green_heart: javadoc 2m 56s master passed with JDK Private Build-11.0.15+10-Ubuntu-0ubuntu0.20.04.1
+1 :green_heart: javadoc 2m 19s master passed with JDK Private Build-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07
_ Patch Compile Tests _
+0 :ok: mvndep 0m 17s Maven dependency ordering for patch
+1 :green_heart: mvninstall 5m 41s the patch passed
+1 :green_heart: compile 3m 26s the patch passed with JDK Private Build-11.0.15+10-Ubuntu-0ubuntu0.20.04.1
+1 :green_heart: javac 3m 26s the patch passed
+1 :green_heart: compile 3m 13s the patch passed with JDK Private Build-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07
+1 :green_heart: javac 3m 13s the patch passed
+1 :green_heart: whitespace 0m 0s The patch has no whitespace issues.
+1 :green_heart: xml 0m 2s The patch has no ill-formed XML file.
+1 :green_heart: javadoc 2m 45s the patch passed with JDK Private Build-11.0.15+10-Ubuntu-0ubuntu0.20.04.1
+1 :green_heart: javadoc 2m 22s the patch passed with JDK Private Build-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07
_ Other Tests _
+1 :green_heart: unit 1m 57s tez-ui in the patch passed.
+1 :green_heart: unit 66m 0s root in the patch passed.
+1 :green_heart: asflicense 1m 26s The patch does not generate ASF License warnings.
119m 16s
Subsystem Report/Notes
Docker ClientAPI=1.41 ServerAPI=1.41 base: https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-215/2/artifact/out/Dockerfile
GITHUB PR https://github.com/apache/tez/pull/215
JIRA Issue TEZ-4419
Optional Tests dupname asflicense javac javadoc unit xml compile
uname Linux 87e1cf18bf86 4.15.0-175-generic #184-Ubuntu SMP Thu Mar 24 17:48:36 UTC 2022 x86_64 x86_64 x86_64 GNU/Linux
Build tool maven
Personality personality/tez.sh
git revision master / cf9e3ff30
Default Java Private Build-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07
Multi-JDK versions /usr/lib/jvm/java-11-openjdk-amd64:Private Build-11.0.15+10-Ubuntu-0ubuntu0.20.04.1 /usr/lib/jvm/java-8-openjdk-amd64:Private Build-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07
Test Results https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-215/2/testReport/
Max. process+thread count 1383 (vs. ulimit of 5500)
modules C: tez-ui . U: .
Console output https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-215/2/console
versions git=2.25.1 maven=3.6.3
Powered by Apache Yetus 0.12.0 https://yetus.apache.org

This message was automatically generated.

tez-yetus avatar Jun 06 '22 18:06 tez-yetus

thanks guys for taking care of security issues in Tez! I can see that TEZ-4419 is an umbrella with lots of subtasks if we're tracking fixes on separate jiras, we might want to fix them in separate PRs/commits too, if possible, can you please do this accordingly? I'm adding contributor rights to all of you in jira to tez project, feel free to assign tickets to yourselves

abstractdog avatar Jun 06 '22 20:06 abstractdog

TEZ-4419 is resolved, I think we can close this PR please reopen if I'm wrong

abstractdog avatar Nov 17 '22 09:11 abstractdog