[CVE-2026-24400] Upgrade assertj-core to 3.27.7 - #5100

Merged
qianheng-aws merged 2 commits into
opensearch-project:mainfrom
RyanL1997:cve-350-assertj-core
Feb 3, 2026
Merged

[CVE-2026-24400] Upgrade assertj-core to 3.27.7#5100
qianheng-aws merged 2 commits into
opensearch-project:mainfrom
RyanL1997:cve-350-assertj-core

Conversation

@RyanL1997

Copy link
Copy Markdown
Collaborator

Description

[CVE] Upgrade assertj-core to 3.27.7

Related Issues

Check List

  • New functionality includes testing.
  • New functionality has been documented.
  • New functionality has javadoc added.
  • New functionality has a user manual doc added.
  • New PPL command checklist all confirmed.
  • API changes companion pull request created.
  • Commits are signed per the DCO using --signoff or -s.
  • Public documentation issue/PR created.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

Signed-off-by: Jialiang Liang <jiallian@amazon.com>
@coderabbitai

coderabbitaiBot commented Feb 2, 2026

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Updates AssertJ test dependency from 3.9.1 to 3.27.7 and adds a corresponding maintenance note in the 3.5.0.0 release notes. No functional code or public API changes.

Changes

Cohort / File(s)Summary
Dependency Version Update
common/build.gradle
Bumps org.assertj:assertj-core test dependency from 3.9.1 to 3.27.7.
Release Notes
release-notes/opensearch-sql.release-notes-3.5.0.0.md
Adds a Maintenance entry documenting the AssertJ upgrade ([#5100]).

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Possibly related PRs

  • opensearch-project/sql#5092 — also updates the 3.5 release notes with the AssertJ 3.27.7 maintenance entry.

Suggested labels

maintenance

Suggested reviewers

  • ps48
  • kavithacm
  • derek-ho
  • penghuo
  • qianheng-aws
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description check✅ PassedThe description is directly related to the changeset, explaining the CVE upgrade, referencing the related security advisory, and providing a properly formatted checklist.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check✅ PassedThe title directly and specifically addresses the main change: upgrading assertj-core to 3.27.7 to resolve CVE-2026-24400, which is confirmed by both the file summaries and PR objectives.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment

Comment @coderabbitai help to get the list of available commands and usage tips.

Signed-off-by: Jialiang Liang <jiallian@amazon.com>
@RyanL1997RyanL1997 added the maintenance Improves code quality, but not the product label Feb 2, 2026
dai-chen
dai-chen previously approved these changes Feb 2, 2026
@RyanL1997

Copy link
Copy Markdown
CollaboratorAuthor

Some of the CI tasks has been cancelled by github, will ltrigger the re-run.

@RyanL1997

Copy link
Copy Markdown
CollaboratorAuthor

All this CI tasks has been stucked at:

Job is waiting for a hosted runner to come online.
Evaluating security-it-linux.if
Evaluating: success()
Result: true
Job is about to start running on the hosted runner: GitHub Actions 1001943859
Requested labels: ubuntu-latest
Job defined at: opensearch-project/sql/.github/workflows/integ-tests-with-security.yml@refs/pull/5100/merge
Waiting for a runner to pick up this job...

@RyanL1997

RyanL1997 commented Feb 2, 2026

Copy link
Copy Markdown
CollaboratorAuthor

I have also confirmed with @rishabh6788 that we dont need to include this into the 3.5 release + this is a test related dependency. So im reverting the release note change and no backport needed as for now.

Also had a conversation with @peterzhuamazon, and it is actually better if we can fix this cve at current 3.5 release.

@RyanL1997

Copy link
Copy Markdown
CollaboratorAuthor

The above CI error is due to the ongoing GHA outage : https://www.githubstatus.com/
Screenshot 2026-02-02 at 1 07 26 PM

@RyanL1997RyanL1997 changed the title [CVE] Upgrade assertj-core to 3.27.7[CVE-2026-24400] Upgrade assertj-core to 3.27.7Feb 2, 2026
@qianheng-aws
qianheng-aws merged commit a1bb9ba into opensearch-project:mainFeb 3, 2026
114 of 155 checks passed
@opensearch-trigger-bot

Copy link
Copy Markdown
Contributor

The backport to 2.19-dev failed:

The process '/usr/bin/git' failed with exit code 128

To backport manually, run these commands in your terminal:

# Navigate to the root of your repositorycd$(git rev-parse --show-toplevel)# Fetch latest updates from GitHub
git fetch
# Create a new working tree
git worktree add ../.worktrees/sql/backport-2.19-dev 2.19-dev
# Navigate to the new working treepushd ../.worktrees/sql/backport-2.19-dev
# Create a new branch
git switch --create backport/backport-5100-to-2.19-dev
# Cherry-pick the merged commit of this pull request and resolve the conflicts
git cherry-pick -x --mainline 1 a1bb9ba652b1d70c9315eb61170b6c29efd9fd5d
# Push it to GitHub
git push --set-upstream origin backport/backport-5100-to-2.19-dev
# Go back to the original working treepopd# Delete the working tree
git worktree remove ../.worktrees/sql/backport-2.19-dev

Then, create a pull request where the base branch is 2.19-dev and the compare/head branch is backport/backport-5100-to-2.19-dev.

asifabashar pushed a commit to asifabashar/sql that referenced this pull request Feb 3, 2026
)
* [CVE] Upgrade assertj-core to 3.27.7
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
* update release not of 3.5
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
---------
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport 2.19-devbackport-failedmaintenanceImproves code quality, but not the product

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@RyanL1997@LantaoJin@dai-chen@qianheng-aws
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

[CVE-2026-24400] Upgrade assertj-core to 3.27.7 - #5100

Merged
qianheng-aws merged 2 commits into
opensearch-project:mainfrom
RyanL1997:cve-350-assertj-core
Feb 3, 2026
Merged

[CVE-2026-24400] Upgrade assertj-core to 3.27.7#5100
qianheng-aws merged 2 commits into
opensearch-project:mainfrom
RyanL1997:cve-350-assertj-core

Conversation

@RyanL1997

Copy link
Copy Markdown
Collaborator

Description

[CVE] Upgrade assertj-core to 3.27.7

Related Issues

Check List

  • New functionality includes testing.
  • New functionality has been documented.
  • New functionality has javadoc added.
  • New functionality has a user manual doc added.
  • New PPL command checklist all confirmed.
  • API changes companion pull request created.
  • Commits are signed per the DCO using --signoff or -s.
  • Public documentation issue/PR created.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

Signed-off-by: Jialiang Liang <jiallian@amazon.com>
@coderabbitai

coderabbitaiBot commented Feb 2, 2026

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Updates AssertJ test dependency from 3.9.1 to 3.27.7 and adds a corresponding maintenance note in the 3.5.0.0 release notes. No functional code or public API changes.

Changes

Cohort / File(s)Summary
Dependency Version Update
common/build.gradle
Bumps org.assertj:assertj-core test dependency from 3.9.1 to 3.27.7.
Release Notes
release-notes/opensearch-sql.release-notes-3.5.0.0.md
Adds a Maintenance entry documenting the AssertJ upgrade ([#5100]).

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Possibly related PRs

  • opensearch-project/sql#5092 — also updates the 3.5 release notes with the AssertJ 3.27.7 maintenance entry.

Suggested labels

maintenance

Suggested reviewers

  • ps48
  • kavithacm
  • derek-ho
  • penghuo
  • qianheng-aws
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description check✅ PassedThe description is directly related to the changeset, explaining the CVE upgrade, referencing the related security advisory, and providing a properly formatted checklist.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check✅ PassedThe title directly and specifically addresses the main change: upgrading assertj-core to 3.27.7 to resolve CVE-2026-24400, which is confirmed by both the file summaries and PR objectives.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment

Comment @coderabbitai help to get the list of available commands and usage tips.

Signed-off-by: Jialiang Liang <jiallian@amazon.com>
@RyanL1997RyanL1997 added the maintenance Improves code quality, but not the product label Feb 2, 2026
dai-chen
dai-chen previously approved these changes Feb 2, 2026
@RyanL1997

Copy link
Copy Markdown
CollaboratorAuthor

Some of the CI tasks has been cancelled by github, will ltrigger the re-run.

@RyanL1997

Copy link
Copy Markdown
CollaboratorAuthor

All this CI tasks has been stucked at:

Job is waiting for a hosted runner to come online.
Evaluating security-it-linux.if
Evaluating: success()
Result: true
Job is about to start running on the hosted runner: GitHub Actions 1001943859
Requested labels: ubuntu-latest
Job defined at: opensearch-project/sql/.github/workflows/integ-tests-with-security.yml@refs/pull/5100/merge
Waiting for a runner to pick up this job...

@RyanL1997

RyanL1997 commented Feb 2, 2026

Copy link
Copy Markdown
CollaboratorAuthor

I have also confirmed with @rishabh6788 that we dont need to include this into the 3.5 release + this is a test related dependency. So im reverting the release note change and no backport needed as for now.

Also had a conversation with @peterzhuamazon, and it is actually better if we can fix this cve at current 3.5 release.

@RyanL1997

Copy link
Copy Markdown
CollaboratorAuthor

The above CI error is due to the ongoing GHA outage : https://www.githubstatus.com/
Screenshot 2026-02-02 at 1 07 26 PM

@RyanL1997RyanL1997 changed the title [CVE] Upgrade assertj-core to 3.27.7[CVE-2026-24400] Upgrade assertj-core to 3.27.7Feb 2, 2026
@qianheng-aws
qianheng-aws merged commit a1bb9ba into opensearch-project:mainFeb 3, 2026
114 of 155 checks passed
@opensearch-trigger-bot

Copy link
Copy Markdown
Contributor

The backport to 2.19-dev failed:

The process '/usr/bin/git' failed with exit code 128

To backport manually, run these commands in your terminal:

# Navigate to the root of your repositorycd$(git rev-parse --show-toplevel)# Fetch latest updates from GitHub
git fetch
# Create a new working tree
git worktree add ../.worktrees/sql/backport-2.19-dev 2.19-dev
# Navigate to the new working treepushd ../.worktrees/sql/backport-2.19-dev
# Create a new branch
git switch --create backport/backport-5100-to-2.19-dev
# Cherry-pick the merged commit of this pull request and resolve the conflicts
git cherry-pick -x --mainline 1 a1bb9ba652b1d70c9315eb61170b6c29efd9fd5d
# Push it to GitHub
git push --set-upstream origin backport/backport-5100-to-2.19-dev
# Go back to the original working treepopd# Delete the working tree
git worktree remove ../.worktrees/sql/backport-2.19-dev

Then, create a pull request where the base branch is 2.19-dev and the compare/head branch is backport/backport-5100-to-2.19-dev.

asifabashar pushed a commit to asifabashar/sql that referenced this pull request Feb 3, 2026
)
* [CVE] Upgrade assertj-core to 3.27.7
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
* update release not of 3.5
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
---------
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport 2.19-devbackport-failedmaintenanceImproves code quality, but not the product

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@RyanL1997@LantaoJin@dai-chen@qianheng-aws
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[CVE-2026-24400] Upgrade assertj-core to 3.27.7 - #5100

Merged
qianheng-aws merged 2 commits into
opensearch-project:mainfrom
RyanL1997:cve-350-assertj-core
Feb 3, 2026
Merged

[CVE-2026-24400] Upgrade assertj-core to 3.27.7#5100
qianheng-aws merged 2 commits into
opensearch-project:mainfrom
RyanL1997:cve-350-assertj-core

Conversation

@RyanL1997

Copy link
Copy Markdown
Collaborator

Description

[CVE] Upgrade assertj-core to 3.27.7

Related Issues

Check List

  • New functionality includes testing.
  • New functionality has been documented.
  • New functionality has javadoc added.
  • New functionality has a user manual doc added.
  • New PPL command checklist all confirmed.
  • API changes companion pull request created.
  • Commits are signed per the DCO using --signoff or -s.
  • Public documentation issue/PR created.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

Signed-off-by: Jialiang Liang <jiallian@amazon.com>
@coderabbitai

coderabbitaiBot commented Feb 2, 2026

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Updates AssertJ test dependency from 3.9.1 to 3.27.7 and adds a corresponding maintenance note in the 3.5.0.0 release notes. No functional code or public API changes.

Changes

Cohort / File(s)Summary
Dependency Version Update
common/build.gradle
Bumps org.assertj:assertj-core test dependency from 3.9.1 to 3.27.7.
Release Notes
release-notes/opensearch-sql.release-notes-3.5.0.0.md
Adds a Maintenance entry documenting the AssertJ upgrade ([#5100]).

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Possibly related PRs

  • opensearch-project/sql#5092 — also updates the 3.5 release notes with the AssertJ 3.27.7 maintenance entry.

Suggested labels

maintenance

Suggested reviewers

  • ps48
  • kavithacm
  • derek-ho
  • penghuo
  • qianheng-aws
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description check✅ PassedThe description is directly related to the changeset, explaining the CVE upgrade, referencing the related security advisory, and providing a properly formatted checklist.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check✅ PassedThe title directly and specifically addresses the main change: upgrading assertj-core to 3.27.7 to resolve CVE-2026-24400, which is confirmed by both the file summaries and PR objectives.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment

Comment @coderabbitai help to get the list of available commands and usage tips.

Signed-off-by: Jialiang Liang <jiallian@amazon.com>
@RyanL1997RyanL1997 added the maintenance Improves code quality, but not the product label Feb 2, 2026
dai-chen
dai-chen previously approved these changes Feb 2, 2026
@RyanL1997

Copy link
Copy Markdown
CollaboratorAuthor

Some of the CI tasks has been cancelled by github, will ltrigger the re-run.

@RyanL1997

Copy link
Copy Markdown
CollaboratorAuthor

All this CI tasks has been stucked at:

Job is waiting for a hosted runner to come online.
Evaluating security-it-linux.if
Evaluating: success()
Result: true
Job is about to start running on the hosted runner: GitHub Actions 1001943859
Requested labels: ubuntu-latest
Job defined at: opensearch-project/sql/.github/workflows/integ-tests-with-security.yml@refs/pull/5100/merge
Waiting for a runner to pick up this job...

@RyanL1997

RyanL1997 commented Feb 2, 2026

Copy link
Copy Markdown
CollaboratorAuthor

I have also confirmed with @rishabh6788 that we dont need to include this into the 3.5 release + this is a test related dependency. So im reverting the release note change and no backport needed as for now.

Also had a conversation with @peterzhuamazon, and it is actually better if we can fix this cve at current 3.5 release.

@RyanL1997

Copy link
Copy Markdown
CollaboratorAuthor

The above CI error is due to the ongoing GHA outage : https://www.githubstatus.com/
Screenshot 2026-02-02 at 1 07 26 PM

@RyanL1997RyanL1997 changed the title [CVE] Upgrade assertj-core to 3.27.7[CVE-2026-24400] Upgrade assertj-core to 3.27.7Feb 2, 2026
@qianheng-aws
qianheng-aws merged commit a1bb9ba into opensearch-project:mainFeb 3, 2026
114 of 155 checks passed
@opensearch-trigger-bot

Copy link
Copy Markdown
Contributor

The backport to 2.19-dev failed:

The process '/usr/bin/git' failed with exit code 128

To backport manually, run these commands in your terminal:

# Navigate to the root of your repositorycd$(git rev-parse --show-toplevel)# Fetch latest updates from GitHub
git fetch
# Create a new working tree
git worktree add ../.worktrees/sql/backport-2.19-dev 2.19-dev
# Navigate to the new working treepushd ../.worktrees/sql/backport-2.19-dev
# Create a new branch
git switch --create backport/backport-5100-to-2.19-dev
# Cherry-pick the merged commit of this pull request and resolve the conflicts
git cherry-pick -x --mainline 1 a1bb9ba652b1d70c9315eb61170b6c29efd9fd5d
# Push it to GitHub
git push --set-upstream origin backport/backport-5100-to-2.19-dev
# Go back to the original working treepopd# Delete the working tree
git worktree remove ../.worktrees/sql/backport-2.19-dev

Then, create a pull request where the base branch is 2.19-dev and the compare/head branch is backport/backport-5100-to-2.19-dev.

asifabashar pushed a commit to asifabashar/sql that referenced this pull request Feb 3, 2026
)
* [CVE] Upgrade assertj-core to 3.27.7
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
* update release not of 3.5
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
---------
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport 2.19-devbackport-failedmaintenanceImproves code quality, but not the product

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@RyanL1997@LantaoJin@dai-chen@qianheng-aws
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[CVE-2026-24400] Upgrade assertj-core to 3.27.7 - #5100

Merged
qianheng-aws merged 2 commits into
opensearch-project:mainfrom
RyanL1997:cve-350-assertj-core
Feb 3, 2026
Merged

[CVE-2026-24400] Upgrade assertj-core to 3.27.7#5100
qianheng-aws merged 2 commits into
opensearch-project:mainfrom
RyanL1997:cve-350-assertj-core

Conversation

@RyanL1997

Copy link
Copy Markdown
Collaborator

Description

[CVE] Upgrade assertj-core to 3.27.7

Related Issues

Check List

  • New functionality includes testing.
  • New functionality has been documented.
  • New functionality has javadoc added.
  • New functionality has a user manual doc added.
  • New PPL command checklist all confirmed.
  • API changes companion pull request created.
  • Commits are signed per the DCO using --signoff or -s.
  • Public documentation issue/PR created.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

Signed-off-by: Jialiang Liang <jiallian@amazon.com>
@coderabbitai

coderabbitaiBot commented Feb 2, 2026

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Updates AssertJ test dependency from 3.9.1 to 3.27.7 and adds a corresponding maintenance note in the 3.5.0.0 release notes. No functional code or public API changes.

Changes

Cohort / File(s)Summary
Dependency Version Update
common/build.gradle
Bumps org.assertj:assertj-core test dependency from 3.9.1 to 3.27.7.
Release Notes
release-notes/opensearch-sql.release-notes-3.5.0.0.md
Adds a Maintenance entry documenting the AssertJ upgrade ([#5100]).

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Possibly related PRs

  • opensearch-project/sql#5092 — also updates the 3.5 release notes with the AssertJ 3.27.7 maintenance entry.

Suggested labels

maintenance

Suggested reviewers

  • ps48
  • kavithacm
  • derek-ho
  • penghuo
  • qianheng-aws
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description check✅ PassedThe description is directly related to the changeset, explaining the CVE upgrade, referencing the related security advisory, and providing a properly formatted checklist.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check✅ PassedThe title directly and specifically addresses the main change: upgrading assertj-core to 3.27.7 to resolve CVE-2026-24400, which is confirmed by both the file summaries and PR objectives.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment

Comment @coderabbitai help to get the list of available commands and usage tips.

Signed-off-by: Jialiang Liang <jiallian@amazon.com>
@RyanL1997RyanL1997 added the maintenance Improves code quality, but not the product label Feb 2, 2026
dai-chen
dai-chen previously approved these changes Feb 2, 2026
@RyanL1997

Copy link
Copy Markdown
CollaboratorAuthor

Some of the CI tasks has been cancelled by github, will ltrigger the re-run.

@RyanL1997

Copy link
Copy Markdown
CollaboratorAuthor

All this CI tasks has been stucked at:

Job is waiting for a hosted runner to come online.
Evaluating security-it-linux.if
Evaluating: success()
Result: true
Job is about to start running on the hosted runner: GitHub Actions 1001943859
Requested labels: ubuntu-latest
Job defined at: opensearch-project/sql/.github/workflows/integ-tests-with-security.yml@refs/pull/5100/merge
Waiting for a runner to pick up this job...

@RyanL1997

RyanL1997 commented Feb 2, 2026

Copy link
Copy Markdown
CollaboratorAuthor

I have also confirmed with @rishabh6788 that we dont need to include this into the 3.5 release + this is a test related dependency. So im reverting the release note change and no backport needed as for now.

Also had a conversation with @peterzhuamazon, and it is actually better if we can fix this cve at current 3.5 release.

@RyanL1997

Copy link
Copy Markdown
CollaboratorAuthor

The above CI error is due to the ongoing GHA outage : https://www.githubstatus.com/
Screenshot 2026-02-02 at 1 07 26 PM

@RyanL1997RyanL1997 changed the title [CVE] Upgrade assertj-core to 3.27.7[CVE-2026-24400] Upgrade assertj-core to 3.27.7Feb 2, 2026
@qianheng-aws
qianheng-aws merged commit a1bb9ba into opensearch-project:mainFeb 3, 2026
114 of 155 checks passed
@opensearch-trigger-bot

Copy link
Copy Markdown
Contributor

The backport to 2.19-dev failed:

The process '/usr/bin/git' failed with exit code 128

To backport manually, run these commands in your terminal:

# Navigate to the root of your repositorycd$(git rev-parse --show-toplevel)# Fetch latest updates from GitHub
git fetch
# Create a new working tree
git worktree add ../.worktrees/sql/backport-2.19-dev 2.19-dev
# Navigate to the new working treepushd ../.worktrees/sql/backport-2.19-dev
# Create a new branch
git switch --create backport/backport-5100-to-2.19-dev
# Cherry-pick the merged commit of this pull request and resolve the conflicts
git cherry-pick -x --mainline 1 a1bb9ba652b1d70c9315eb61170b6c29efd9fd5d
# Push it to GitHub
git push --set-upstream origin backport/backport-5100-to-2.19-dev
# Go back to the original working treepopd# Delete the working tree
git worktree remove ../.worktrees/sql/backport-2.19-dev

Then, create a pull request where the base branch is 2.19-dev and the compare/head branch is backport/backport-5100-to-2.19-dev.

asifabashar pushed a commit to asifabashar/sql that referenced this pull request Feb 3, 2026
)
* [CVE] Upgrade assertj-core to 3.27.7
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
* update release not of 3.5
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
---------
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport 2.19-devbackport-failedmaintenanceImproves code quality, but not the product

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@RyanL1997@LantaoJin@dai-chen@qianheng-aws
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

[CVE-2026-24400] Upgrade assertj-core to 3.27.7 - #5100

Merged
qianheng-aws merged 2 commits into
opensearch-project:mainfrom
RyanL1997:cve-350-assertj-core
Feb 3, 2026
Merged

[CVE-2026-24400] Upgrade assertj-core to 3.27.7#5100
qianheng-aws merged 2 commits into
opensearch-project:mainfrom
RyanL1997:cve-350-assertj-core

Conversation

@RyanL1997

Copy link
Copy Markdown
Collaborator

Description

[CVE] Upgrade assertj-core to 3.27.7

Related Issues

Check List

  • New functionality includes testing.
  • New functionality has been documented.
  • New functionality has javadoc added.
  • New functionality has a user manual doc added.
  • New PPL command checklist all confirmed.
  • API changes companion pull request created.
  • Commits are signed per the DCO using --signoff or -s.
  • Public documentation issue/PR created.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

Signed-off-by: Jialiang Liang <jiallian@amazon.com>
@coderabbitai

coderabbitaiBot commented Feb 2, 2026

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Updates AssertJ test dependency from 3.9.1 to 3.27.7 and adds a corresponding maintenance note in the 3.5.0.0 release notes. No functional code or public API changes.

Changes

Cohort / File(s)Summary
Dependency Version Update
common/build.gradle
Bumps org.assertj:assertj-core test dependency from 3.9.1 to 3.27.7.
Release Notes
release-notes/opensearch-sql.release-notes-3.5.0.0.md
Adds a Maintenance entry documenting the AssertJ upgrade ([#5100]).

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Possibly related PRs

  • opensearch-project/sql#5092 — also updates the 3.5 release notes with the AssertJ 3.27.7 maintenance entry.

Suggested labels

maintenance

Suggested reviewers

  • ps48
  • kavithacm
  • derek-ho
  • penghuo
  • qianheng-aws
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description check✅ PassedThe description is directly related to the changeset, explaining the CVE upgrade, referencing the related security advisory, and providing a properly formatted checklist.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check✅ PassedThe title directly and specifically addresses the main change: upgrading assertj-core to 3.27.7 to resolve CVE-2026-24400, which is confirmed by both the file summaries and PR objectives.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment

Comment @coderabbitai help to get the list of available commands and usage tips.

Signed-off-by: Jialiang Liang <jiallian@amazon.com>
@RyanL1997RyanL1997 added the maintenance Improves code quality, but not the product label Feb 2, 2026
dai-chen
dai-chen previously approved these changes Feb 2, 2026
@RyanL1997

Copy link
Copy Markdown
CollaboratorAuthor

Some of the CI tasks has been cancelled by github, will ltrigger the re-run.

@RyanL1997

Copy link
Copy Markdown
CollaboratorAuthor

All this CI tasks has been stucked at:

Job is waiting for a hosted runner to come online.
Evaluating security-it-linux.if
Evaluating: success()
Result: true
Job is about to start running on the hosted runner: GitHub Actions 1001943859
Requested labels: ubuntu-latest
Job defined at: opensearch-project/sql/.github/workflows/integ-tests-with-security.yml@refs/pull/5100/merge
Waiting for a runner to pick up this job...

@RyanL1997

RyanL1997 commented Feb 2, 2026

Copy link
Copy Markdown
CollaboratorAuthor

I have also confirmed with @rishabh6788 that we dont need to include this into the 3.5 release + this is a test related dependency. So im reverting the release note change and no backport needed as for now.

Also had a conversation with @peterzhuamazon, and it is actually better if we can fix this cve at current 3.5 release.

@RyanL1997

Copy link
Copy Markdown
CollaboratorAuthor

The above CI error is due to the ongoing GHA outage : https://www.githubstatus.com/
Screenshot 2026-02-02 at 1 07 26 PM

@RyanL1997RyanL1997 changed the title [CVE] Upgrade assertj-core to 3.27.7[CVE-2026-24400] Upgrade assertj-core to 3.27.7Feb 2, 2026
@qianheng-aws
qianheng-aws merged commit a1bb9ba into opensearch-project:mainFeb 3, 2026
114 of 155 checks passed
@opensearch-trigger-bot

Copy link
Copy Markdown
Contributor

The backport to 2.19-dev failed:

The process '/usr/bin/git' failed with exit code 128

To backport manually, run these commands in your terminal:

# Navigate to the root of your repositorycd$(git rev-parse --show-toplevel)# Fetch latest updates from GitHub
git fetch
# Create a new working tree
git worktree add ../.worktrees/sql/backport-2.19-dev 2.19-dev
# Navigate to the new working treepushd ../.worktrees/sql/backport-2.19-dev
# Create a new branch
git switch --create backport/backport-5100-to-2.19-dev
# Cherry-pick the merged commit of this pull request and resolve the conflicts
git cherry-pick -x --mainline 1 a1bb9ba652b1d70c9315eb61170b6c29efd9fd5d
# Push it to GitHub
git push --set-upstream origin backport/backport-5100-to-2.19-dev
# Go back to the original working treepopd# Delete the working tree
git worktree remove ../.worktrees/sql/backport-2.19-dev

Then, create a pull request where the base branch is 2.19-dev and the compare/head branch is backport/backport-5100-to-2.19-dev.

asifabashar pushed a commit to asifabashar/sql that referenced this pull request Feb 3, 2026
)
* [CVE] Upgrade assertj-core to 3.27.7
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
* update release not of 3.5
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
---------
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport 2.19-devbackport-failedmaintenanceImproves code quality, but not the product

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@RyanL1997@LantaoJin@dai-chen@qianheng-aws
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[CVE-2026-24400] Upgrade assertj-core to 3.27.7 - #5100

Merged
qianheng-aws merged 2 commits into
opensearch-project:mainfrom
RyanL1997:cve-350-assertj-core
Feb 3, 2026
Merged

[CVE-2026-24400] Upgrade assertj-core to 3.27.7#5100
qianheng-aws merged 2 commits into
opensearch-project:mainfrom
RyanL1997:cve-350-assertj-core

Conversation

@RyanL1997

Copy link
Copy Markdown
Collaborator

Description

[CVE] Upgrade assertj-core to 3.27.7

Related Issues

Check List

  • New functionality includes testing.
  • New functionality has been documented.
  • New functionality has javadoc added.
  • New functionality has a user manual doc added.
  • New PPL command checklist all confirmed.
  • API changes companion pull request created.
  • Commits are signed per the DCO using --signoff or -s.
  • Public documentation issue/PR created.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

Signed-off-by: Jialiang Liang <jiallian@amazon.com>
@coderabbitai

coderabbitaiBot commented Feb 2, 2026

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Updates AssertJ test dependency from 3.9.1 to 3.27.7 and adds a corresponding maintenance note in the 3.5.0.0 release notes. No functional code or public API changes.

Changes

Cohort / File(s)Summary
Dependency Version Update
common/build.gradle
Bumps org.assertj:assertj-core test dependency from 3.9.1 to 3.27.7.
Release Notes
release-notes/opensearch-sql.release-notes-3.5.0.0.md
Adds a Maintenance entry documenting the AssertJ upgrade ([#5100]).

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Possibly related PRs

  • opensearch-project/sql#5092 — also updates the 3.5 release notes with the AssertJ 3.27.7 maintenance entry.

Suggested labels

maintenance

Suggested reviewers

  • ps48
  • kavithacm
  • derek-ho
  • penghuo
  • qianheng-aws
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description check✅ PassedThe description is directly related to the changeset, explaining the CVE upgrade, referencing the related security advisory, and providing a properly formatted checklist.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check✅ PassedThe title directly and specifically addresses the main change: upgrading assertj-core to 3.27.7 to resolve CVE-2026-24400, which is confirmed by both the file summaries and PR objectives.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment

Comment @coderabbitai help to get the list of available commands and usage tips.

Signed-off-by: Jialiang Liang <jiallian@amazon.com>
@RyanL1997RyanL1997 added the maintenance Improves code quality, but not the product label Feb 2, 2026
dai-chen
dai-chen previously approved these changes Feb 2, 2026
@RyanL1997

Copy link
Copy Markdown
CollaboratorAuthor

Some of the CI tasks has been cancelled by github, will ltrigger the re-run.

@RyanL1997

Copy link
Copy Markdown
CollaboratorAuthor

All this CI tasks has been stucked at:

Job is waiting for a hosted runner to come online.
Evaluating security-it-linux.if
Evaluating: success()
Result: true
Job is about to start running on the hosted runner: GitHub Actions 1001943859
Requested labels: ubuntu-latest
Job defined at: opensearch-project/sql/.github/workflows/integ-tests-with-security.yml@refs/pull/5100/merge
Waiting for a runner to pick up this job...

@RyanL1997

RyanL1997 commented Feb 2, 2026

Copy link
Copy Markdown
CollaboratorAuthor

I have also confirmed with @rishabh6788 that we dont need to include this into the 3.5 release + this is a test related dependency. So im reverting the release note change and no backport needed as for now.

Also had a conversation with @peterzhuamazon, and it is actually better if we can fix this cve at current 3.5 release.

@RyanL1997

Copy link
Copy Markdown
CollaboratorAuthor

The above CI error is due to the ongoing GHA outage : https://www.githubstatus.com/
Screenshot 2026-02-02 at 1 07 26 PM

@RyanL1997RyanL1997 changed the title [CVE] Upgrade assertj-core to 3.27.7[CVE-2026-24400] Upgrade assertj-core to 3.27.7Feb 2, 2026
@qianheng-aws
qianheng-aws merged commit a1bb9ba into opensearch-project:mainFeb 3, 2026
114 of 155 checks passed
@opensearch-trigger-bot

Copy link
Copy Markdown
Contributor

The backport to 2.19-dev failed:

The process '/usr/bin/git' failed with exit code 128

To backport manually, run these commands in your terminal:

# Navigate to the root of your repositorycd$(git rev-parse --show-toplevel)# Fetch latest updates from GitHub
git fetch
# Create a new working tree
git worktree add ../.worktrees/sql/backport-2.19-dev 2.19-dev
# Navigate to the new working treepushd ../.worktrees/sql/backport-2.19-dev
# Create a new branch
git switch --create backport/backport-5100-to-2.19-dev
# Cherry-pick the merged commit of this pull request and resolve the conflicts
git cherry-pick -x --mainline 1 a1bb9ba652b1d70c9315eb61170b6c29efd9fd5d
# Push it to GitHub
git push --set-upstream origin backport/backport-5100-to-2.19-dev
# Go back to the original working treepopd# Delete the working tree
git worktree remove ../.worktrees/sql/backport-2.19-dev

Then, create a pull request where the base branch is 2.19-dev and the compare/head branch is backport/backport-5100-to-2.19-dev.

asifabashar pushed a commit to asifabashar/sql that referenced this pull request Feb 3, 2026
)
* [CVE] Upgrade assertj-core to 3.27.7
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
* update release not of 3.5
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
---------
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport 2.19-devbackport-failedmaintenanceImproves code quality, but not the product

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@RyanL1997@LantaoJin@dai-chen@qianheng-aws
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[CVE-2026-24400] Upgrade assertj-core to 3.27.7 - #5100

Merged
qianheng-aws merged 2 commits into
opensearch-project:mainfrom
RyanL1997:cve-350-assertj-core
Feb 3, 2026
Merged

[CVE-2026-24400] Upgrade assertj-core to 3.27.7#5100
qianheng-aws merged 2 commits into
opensearch-project:mainfrom
RyanL1997:cve-350-assertj-core

Conversation

@RyanL1997

Copy link
Copy Markdown
Collaborator

Description

[CVE] Upgrade assertj-core to 3.27.7

Related Issues

Check List

  • New functionality includes testing.
  • New functionality has been documented.
  • New functionality has javadoc added.
  • New functionality has a user manual doc added.
  • New PPL command checklist all confirmed.
  • API changes companion pull request created.
  • Commits are signed per the DCO using --signoff or -s.
  • Public documentation issue/PR created.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

Signed-off-by: Jialiang Liang <jiallian@amazon.com>
@coderabbitai

coderabbitaiBot commented Feb 2, 2026

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Updates AssertJ test dependency from 3.9.1 to 3.27.7 and adds a corresponding maintenance note in the 3.5.0.0 release notes. No functional code or public API changes.

Changes

Cohort / File(s)Summary
Dependency Version Update
common/build.gradle
Bumps org.assertj:assertj-core test dependency from 3.9.1 to 3.27.7.
Release Notes
release-notes/opensearch-sql.release-notes-3.5.0.0.md
Adds a Maintenance entry documenting the AssertJ upgrade ([#5100]).

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Possibly related PRs

  • opensearch-project/sql#5092 — also updates the 3.5 release notes with the AssertJ 3.27.7 maintenance entry.

Suggested labels

maintenance

Suggested reviewers

  • ps48
  • kavithacm
  • derek-ho
  • penghuo
  • qianheng-aws
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description check✅ PassedThe description is directly related to the changeset, explaining the CVE upgrade, referencing the related security advisory, and providing a properly formatted checklist.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check✅ PassedThe title directly and specifically addresses the main change: upgrading assertj-core to 3.27.7 to resolve CVE-2026-24400, which is confirmed by both the file summaries and PR objectives.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment

Comment @coderabbitai help to get the list of available commands and usage tips.

Signed-off-by: Jialiang Liang <jiallian@amazon.com>
@RyanL1997RyanL1997 added the maintenance Improves code quality, but not the product label Feb 2, 2026
dai-chen
dai-chen previously approved these changes Feb 2, 2026
@RyanL1997

Copy link
Copy Markdown
CollaboratorAuthor

Some of the CI tasks has been cancelled by github, will ltrigger the re-run.

@RyanL1997

Copy link
Copy Markdown
CollaboratorAuthor

All this CI tasks has been stucked at:

Job is waiting for a hosted runner to come online.
Evaluating security-it-linux.if
Evaluating: success()
Result: true
Job is about to start running on the hosted runner: GitHub Actions 1001943859
Requested labels: ubuntu-latest
Job defined at: opensearch-project/sql/.github/workflows/integ-tests-with-security.yml@refs/pull/5100/merge
Waiting for a runner to pick up this job...

@RyanL1997

RyanL1997 commented Feb 2, 2026

Copy link
Copy Markdown
CollaboratorAuthor

I have also confirmed with @rishabh6788 that we dont need to include this into the 3.5 release + this is a test related dependency. So im reverting the release note change and no backport needed as for now.

Also had a conversation with @peterzhuamazon, and it is actually better if we can fix this cve at current 3.5 release.

@RyanL1997

Copy link
Copy Markdown
CollaboratorAuthor

The above CI error is due to the ongoing GHA outage : https://www.githubstatus.com/
Screenshot 2026-02-02 at 1 07 26 PM

@RyanL1997RyanL1997 changed the title [CVE] Upgrade assertj-core to 3.27.7[CVE-2026-24400] Upgrade assertj-core to 3.27.7Feb 2, 2026
@qianheng-aws
qianheng-aws merged commit a1bb9ba into opensearch-project:mainFeb 3, 2026
114 of 155 checks passed
@opensearch-trigger-bot

Copy link
Copy Markdown
Contributor

The backport to 2.19-dev failed:

The process '/usr/bin/git' failed with exit code 128

To backport manually, run these commands in your terminal:

# Navigate to the root of your repositorycd$(git rev-parse --show-toplevel)# Fetch latest updates from GitHub
git fetch
# Create a new working tree
git worktree add ../.worktrees/sql/backport-2.19-dev 2.19-dev
# Navigate to the new working treepushd ../.worktrees/sql/backport-2.19-dev
# Create a new branch
git switch --create backport/backport-5100-to-2.19-dev
# Cherry-pick the merged commit of this pull request and resolve the conflicts
git cherry-pick -x --mainline 1 a1bb9ba652b1d70c9315eb61170b6c29efd9fd5d
# Push it to GitHub
git push --set-upstream origin backport/backport-5100-to-2.19-dev
# Go back to the original working treepopd# Delete the working tree
git worktree remove ../.worktrees/sql/backport-2.19-dev

Then, create a pull request where the base branch is 2.19-dev and the compare/head branch is backport/backport-5100-to-2.19-dev.

asifabashar pushed a commit to asifabashar/sql that referenced this pull request Feb 3, 2026
)
* [CVE] Upgrade assertj-core to 3.27.7
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
* update release not of 3.5
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
---------
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport 2.19-devbackport-failedmaintenanceImproves code quality, but not the product

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@RyanL1997@LantaoJin@dai-chen@qianheng-aws
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

[CVE-2026-24400] Upgrade assertj-core to 3.27.7 - #5100

Merged
qianheng-aws merged 2 commits into
opensearch-project:mainfrom
RyanL1997:cve-350-assertj-core
Feb 3, 2026
Merged

[CVE-2026-24400] Upgrade assertj-core to 3.27.7#5100
qianheng-aws merged 2 commits into
opensearch-project:mainfrom
RyanL1997:cve-350-assertj-core

Conversation

@RyanL1997

Copy link
Copy Markdown
Collaborator

Description

[CVE] Upgrade assertj-core to 3.27.7

Related Issues

Check List

  • New functionality includes testing.
  • New functionality has been documented.
  • New functionality has javadoc added.
  • New functionality has a user manual doc added.
  • New PPL command checklist all confirmed.
  • API changes companion pull request created.
  • Commits are signed per the DCO using --signoff or -s.
  • Public documentation issue/PR created.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

Signed-off-by: Jialiang Liang <jiallian@amazon.com>
@coderabbitai

coderabbitaiBot commented Feb 2, 2026

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Updates AssertJ test dependency from 3.9.1 to 3.27.7 and adds a corresponding maintenance note in the 3.5.0.0 release notes. No functional code or public API changes.

Changes

Cohort / File(s)Summary
Dependency Version Update
common/build.gradle
Bumps org.assertj:assertj-core test dependency from 3.9.1 to 3.27.7.
Release Notes
release-notes/opensearch-sql.release-notes-3.5.0.0.md
Adds a Maintenance entry documenting the AssertJ upgrade ([#5100]).

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Possibly related PRs

  • opensearch-project/sql#5092 — also updates the 3.5 release notes with the AssertJ 3.27.7 maintenance entry.

Suggested labels

maintenance

Suggested reviewers

  • ps48
  • kavithacm
  • derek-ho
  • penghuo
  • qianheng-aws
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description check✅ PassedThe description is directly related to the changeset, explaining the CVE upgrade, referencing the related security advisory, and providing a properly formatted checklist.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check✅ PassedThe title directly and specifically addresses the main change: upgrading assertj-core to 3.27.7 to resolve CVE-2026-24400, which is confirmed by both the file summaries and PR objectives.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment

Comment @coderabbitai help to get the list of available commands and usage tips.

Signed-off-by: Jialiang Liang <jiallian@amazon.com>
@RyanL1997RyanL1997 added the maintenance Improves code quality, but not the product label Feb 2, 2026
dai-chen
dai-chen previously approved these changes Feb 2, 2026
@RyanL1997

Copy link
Copy Markdown
CollaboratorAuthor

Some of the CI tasks has been cancelled by github, will ltrigger the re-run.

@RyanL1997

Copy link
Copy Markdown
CollaboratorAuthor

All this CI tasks has been stucked at:

Job is waiting for a hosted runner to come online.
Evaluating security-it-linux.if
Evaluating: success()
Result: true
Job is about to start running on the hosted runner: GitHub Actions 1001943859
Requested labels: ubuntu-latest
Job defined at: opensearch-project/sql/.github/workflows/integ-tests-with-security.yml@refs/pull/5100/merge
Waiting for a runner to pick up this job...

@RyanL1997

RyanL1997 commented Feb 2, 2026

Copy link
Copy Markdown
CollaboratorAuthor

I have also confirmed with @rishabh6788 that we dont need to include this into the 3.5 release + this is a test related dependency. So im reverting the release note change and no backport needed as for now.

Also had a conversation with @peterzhuamazon, and it is actually better if we can fix this cve at current 3.5 release.

@RyanL1997

Copy link
Copy Markdown
CollaboratorAuthor

The above CI error is due to the ongoing GHA outage : https://www.githubstatus.com/
Screenshot 2026-02-02 at 1 07 26 PM

@RyanL1997RyanL1997 changed the title [CVE] Upgrade assertj-core to 3.27.7[CVE-2026-24400] Upgrade assertj-core to 3.27.7Feb 2, 2026
@qianheng-aws
qianheng-aws merged commit a1bb9ba into opensearch-project:mainFeb 3, 2026
114 of 155 checks passed
@opensearch-trigger-bot

Copy link
Copy Markdown
Contributor

The backport to 2.19-dev failed:

The process '/usr/bin/git' failed with exit code 128

To backport manually, run these commands in your terminal:

# Navigate to the root of your repositorycd$(git rev-parse --show-toplevel)# Fetch latest updates from GitHub
git fetch
# Create a new working tree
git worktree add ../.worktrees/sql/backport-2.19-dev 2.19-dev
# Navigate to the new working treepushd ../.worktrees/sql/backport-2.19-dev
# Create a new branch
git switch --create backport/backport-5100-to-2.19-dev
# Cherry-pick the merged commit of this pull request and resolve the conflicts
git cherry-pick -x --mainline 1 a1bb9ba652b1d70c9315eb61170b6c29efd9fd5d
# Push it to GitHub
git push --set-upstream origin backport/backport-5100-to-2.19-dev
# Go back to the original working treepopd# Delete the working tree
git worktree remove ../.worktrees/sql/backport-2.19-dev

Then, create a pull request where the base branch is 2.19-dev and the compare/head branch is backport/backport-5100-to-2.19-dev.

asifabashar pushed a commit to asifabashar/sql that referenced this pull request Feb 3, 2026
)
* [CVE] Upgrade assertj-core to 3.27.7
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
* update release not of 3.5
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
---------
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport 2.19-devbackport-failedmaintenanceImproves code quality, but not the product

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@RyanL1997@LantaoJin@dai-chen@qianheng-aws