Skip to content

TEZ-4463: Upgrade jquery-ui to 1.13.2 due to CVE issues - #259

Closed
maheshrajus wants to merge 1 commit into
apache:masterfrom
maheshrajus:TEZ-4463
Closed

TEZ-4463: Upgrade jquery-ui to 1.13.2 due to CVE issues#259
maheshrajus wants to merge 1 commit into
apache:masterfrom
maheshrajus:TEZ-4463

Conversation

@maheshrajus

@maheshrajusmaheshrajus commented Dec 13, 2022

Copy link
Copy Markdown
Contributor

Upgrade jquery-ui to 1.13.2 due to CVE issues
Bower not supporting jquery 1.13.2 version so moving required files into tez-ui.

@maheshrajusmaheshrajus changed the title [TEZ-4463] Upgrade jquery-ui to 1.13.0 due to CVEsTEZ-4463: Upgrade jquery-ui to 1.13.0 due to CVEsDec 13, 2022
@tez-yetus

This comment was marked as outdated.

@tez-yetus

This comment was marked as outdated.

@maheshrajusmaheshrajus changed the title TEZ-4463: Upgrade jquery-ui to 1.13.0 due to CVEsTEZ-4463: Upgrade jquery-ui to 1.13.0 due to CVE issuesFeb 7, 2023
@maheshrajusmaheshrajus reopened this Feb 7, 2023
@tez-yetus

This comment was marked as outdated.

@abstractdog

Copy link
Copy Markdown
Contributor

@maheshrajus: can you please check why the tez-ui module fails?

@abstractdog
abstractdog self-requested a review February 14, 2023 12:41
@maheshrajus

Copy link
Copy Markdown
ContributorAuthor

@abstractdog tez-ui module latest version 1.13.0 dependency failed to download with bower. Some how we need to pull this dependency with npm or other. I need to check this. any pointers/suggestions can help.

[INFO] bower jquery-ui#1.13.0 ENORESTARGET No version found that was able to satisfy 1.13.0

@abstractdog tez-ui module latest version 1.13.0 dependency failed to download with bower. Some how we need to pull this dependency with npm or other. I need to check this. any pointers/suggestions can help.

[INFO] bower jquery-ui#1.13.0 ENORESTARGET No version found that was able to satisfy 1.13.0

@maheshrajusmaheshrajus changed the title TEZ-4463: Upgrade jquery-ui to 1.13.0 due to CVE issuesTEZ-4463: Upgrade jquery-ui to 1.13.2 due to CVE issuesMar 14, 2023
@tez-yetus

Copy link
Copy Markdown

💔 -1 overall

VoteSubsystemRuntimeComment
+0 🆗reexec24m 49sDocker mode activated.
_ Prechecks _
+1 💚dupname0m 0sNo case conflicting files found.
+1 💚@author0m 0sThe patch does not contain any @author tags.
-1 ❌test4tests0m 0sThe patch doesn't appear to include any new or modified tests. Please justify why no new tests are needed for this patch. Also please list what manual steps were performed to verify this patch.
_ master Compile Tests _
+1 💚mvninstall15m 35smaster passed
+1 💚javadoc0m 38smaster passed with JDK Ubuntu-11.0.18+10-post-Ubuntu-0ubuntu122.04
+1 💚javadoc0m 17smaster passed with JDK Private Build-1.8.0_362-8u362-ga-0ubuntu1~22.04-b09
_ Patch Compile Tests _
-1 ❌mvninstall0m 32stez-ui in the patch failed.
+1 💚whitespace0m 0sThe patch has no whitespace issues.
+1 💚javadoc0m 15sthe patch passed with JDK Ubuntu-11.0.18+10-post-Ubuntu-0ubuntu122.04
+1 💚javadoc0m 15sthe patch passed with JDK Private Build-1.8.0_362-8u362-ga-0ubuntu1~22.04-b09
_ Other Tests _
-1 ❌unit0m 18stez-ui in the patch failed.
+1 💚asflicense0m 22sThe patch does not generate ASF License warnings.
43m 46s
SubsystemReport/Notes
DockerClientAPI=1.42 ServerAPI=1.42 base: https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-259/4/artifact/out/Dockerfile
GITHUB PR#259
JIRA IssueTEZ-4463
Optional Testsdupname asflicense javac javadoc unit
unameLinux 3508c09ba8db 4.15.0-206-generic #217-Ubuntu SMP Fri Feb 3 19:10:13 UTC 2023 x86_64 x86_64 x86_64 GNU/Linux
Build toolmaven
Personalitypersonality/tez.sh
git revisionmaster / 25a9536
Default JavaPrivate Build-1.8.0_362-8u362-ga-0ubuntu1~22.04-b09
Multi-JDK versions/usr/lib/jvm/java-11-openjdk-amd64:Ubuntu-11.0.18+10-post-Ubuntu-0ubuntu122.04 /usr/lib/jvm/java-8-openjdk-amd64:Private Build-1.8.0_362-8u362-ga-0ubuntu1~22.04-b09
mvninstallhttps://ci-hadoop.apache.org/job/tez-multibranch/job/PR-259/4/artifact/out/patch-mvninstall-tez-ui.txt
unithttps://ci-hadoop.apache.org/job/tez-multibranch/job/PR-259/4/artifact/out/patch-unit-tez-ui.txt
Test Resultshttps://ci-hadoop.apache.org/job/tez-multibranch/job/PR-259/4/testReport/
Max. process+thread count72 (vs. ulimit of 5500)
modulesC: tez-ui U: tez-ui
Console outputhttps://ci-hadoop.apache.org/job/tez-multibranch/job/PR-259/4/console
versionsgit=2.34.1 maven=3.6.3
Powered byApache Yetus 0.12.0 https://yetus.apache.org

This message was automatically generated.

@abstractdog

Copy link
Copy Markdown
Contributor

regarding bower failure: jquery/jquery-ui#2068

@maheshrajus

Copy link
Copy Markdown
ContributorAuthor

@abstractdog yeah laszlo, i am checking about same dependency how we can achieve with npm. Let me check and confirm.

@tez-yetus

This comment was marked as outdated.

@tez-yetus

Copy link
Copy Markdown

💔 -1 overall

VoteSubsystemRuntimeComment
+0 🆗reexec0m 33sDocker mode activated.
_ Prechecks _
+1 💚dupname0m 0sNo case conflicting files found.
+1 💚@author0m 0sThe patch does not contain any @author tags.
-1 ❌test4tests0m 0sThe patch doesn't appear to include any new or modified tests. Please justify why no new tests are needed for this patch. Also please list what manual steps were performed to verify this patch.
_ master Compile Tests _
+1 💚mvninstall15m 25smaster passed
+1 💚javadoc0m 37smaster passed with JDK Ubuntu-11.0.18+10-post-Ubuntu-0ubuntu122.04
+1 💚javadoc0m 16smaster passed with JDK Private Build-1.8.0_362-8u362-ga-0ubuntu1~22.04-b09
_ Patch Compile Tests _
+1 💚mvninstall1m 11sthe patch passed
+1 💚jshint57m 55sThere were no new jshint issues.
-1 ❌whitespace0m 0sThe patch has 1 line(s) that end in whitespace. Use git apply --whitespace=fix <<patch_file>>. Refer https://git-scm.com/docs/git-apply
-1 ❌whitespace0m 0sThe patch 15448 line(s) with tabs.
+1 💚javadoc0m 16sthe patch passed with JDK Ubuntu-11.0.18+10-post-Ubuntu-0ubuntu122.04
+1 💚javadoc0m 16sthe patch passed with JDK Private Build-1.8.0_362-8u362-ga-0ubuntu1~22.04-b09
_ Other Tests _
+1 💚unit1m 39stez-ui in the patch passed.
-1 ❌asflicense0m 24sThe patch generated 2 ASF License warnings.
79m 23s
SubsystemReport/Notes
DockerClientAPI=1.42 ServerAPI=1.42 base: https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-259/6/artifact/out/Dockerfile
GITHUB PR#259
JIRA IssueTEZ-4463
Optional Testsdupname asflicense javac javadoc unit jshint
unameLinux 150459927f38 4.15.0-206-generic #217-Ubuntu SMP Fri Feb 3 19:10:13 UTC 2023 x86_64 x86_64 x86_64 GNU/Linux
Build toolmaven
Personalitypersonality/tez.sh
git revisionmaster / c9ccf1c
Default JavaPrivate Build-1.8.0_362-8u362-ga-0ubuntu1~22.04-b09
Multi-JDK versions/usr/lib/jvm/java-11-openjdk-amd64:Ubuntu-11.0.18+10-post-Ubuntu-0ubuntu122.04 /usr/lib/jvm/java-8-openjdk-amd64:Private Build-1.8.0_362-8u362-ga-0ubuntu1~22.04-b09
whitespacehttps://ci-hadoop.apache.org/job/tez-multibranch/job/PR-259/6/artifact/out/whitespace-eol.txt
whitespacehttps://ci-hadoop.apache.org/job/tez-multibranch/job/PR-259/6/artifact/out/whitespace-tabs.txt
Test Resultshttps://ci-hadoop.apache.org/job/tez-multibranch/job/PR-259/6/testReport/
asflicensehttps://ci-hadoop.apache.org/job/tez-multibranch/job/PR-259/6/artifact/out/patch-asflicense-problems.txt
Max. process+thread count91 (vs. ulimit of 5500)
modulesC: tez-ui U: tez-ui
Console outputhttps://ci-hadoop.apache.org/job/tez-multibranch/job/PR-259/6/console
versionsgit=2.34.1 maven=3.6.3 jshint=2.12.0
Powered byApache Yetus 0.12.0 https://yetus.apache.org

This message was automatically generated.

@maheshrajus

Copy link
Copy Markdown
ContributorAuthor

for 1.13.0+jquery-ui version bower not supporting dependency. So changing bower to npm dependency way is complex and changes will be more.

@abstractdog

Copy link
Copy Markdown
Contributor

why is this PR closed? I believe we still need to address CVE-s, even if collecting dependencies from different sources might be challenging
I can see the latest patchset tries to address this question, didn't it work? can you take a look at that @sreenaths ?

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@maheshrajus@tez-yetus@abstractdog