-
Notifications
You must be signed in to change notification settings - Fork 2k
Pull requests: opensearch-project/OpenSearch
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[CVE] Upgrade dependencies for Azure related plugins to mitigate CVEs
CVE
Fixes a CVE
v2.0.0
Version 2.0.0
#688
by abbashus
was merged May 25, 2021
Loading…
2 of 5 tasks
Upgrade to log4j 2.15.0
backport 1.x
CVE
Fixes a CVE
pending backport
Identifies an issue or PR that still needs to be backported
Severity-Critical
v1.2.1
#1698
by andrross
was merged Dec 10, 2021
Loading…
Update FIPS API libraries of Bouncy Castle
backport 1.x
CVE
Fixes a CVE
>upgrade
Label used when upgrading library dependencies (e.g., Lucene)
v1.3.0
v2.0.0
Version 2.0.0
#1853
by tlfeng
was merged Jan 6, 2022
Loading…
2 of 5 tasks
[Backport 1.2] Upgrading Netty to 4.1.72-Final
backport
PRs or issues specific to backporting features or enhancments
backport 1.2
CVE
Fixes a CVE
>upgrade
Label used when upgrading library dependencies (e.g., Lucene)
v1.2.4
#1890
by saratvemulapalli
was merged Jan 12, 2022
Loading…
1 of 5 tasks
[Backport 1.2] Upgrading bouncycastle to 1.70 (#1832)
backport
PRs or issues specific to backporting features or enhancments
CVE
Fixes a CVE
>upgrade
Label used when upgrading library dependencies (e.g., Lucene)
v1.2.4
#1889
by saratvemulapalli
was merged Jan 12, 2022
Loading…
1 of 5 tasks
Update protobuf-java to 3.19.3
backport 1.x
CVE
Fixes a CVE
>upgrade
Label used when upgrading library dependencies (e.g., Lucene)
v1.3.0
v2.0.0
Version 2.0.0
#1945
by tlfeng
was merged Jan 20, 2022
Loading…
2 of 5 tasks
Upgrading Shadow plugin to 7.1.2
>breaking
Identifies a breaking change.
CVE
Fixes a CVE
>upgrade
Label used when upgrading library dependencies (e.g., Lucene)
v2.0.0
Version 2.0.0
#2033
by saratvemulapalli
was merged Feb 2, 2022
Loading…
1 of 5 tasks
Upgrading Jackson-Databind version
backport 1.x
CVE
Fixes a CVE
pending backport
Identifies an issue or PR that still needs to be backported
>upgrade
Label used when upgrading library dependencies (e.g., Lucene)
v1.3.0
v2.0.0
Version 2.0.0
#1982
by Rishikesh1159
was merged Jan 27, 2022
Loading…
5 tasks
[Backport 1.x] Upgrading Shadow plugin to 7.1.2
backport
PRs or issues specific to backporting features or enhancments
CVE
Fixes a CVE
>upgrade
Label used when upgrading library dependencies (e.g., Lucene)
v1.3.0
#2037
by github-actions
bot
was merged Feb 2, 2022
Loading…
[CVE] Update snakeyaml dependency
backport 1.x
backport 2.x
Backport to 2.x branch
CVE
Fixes a CVE
dependencies
Pull requests that update a dependency file
>upgrade
Label used when upgrading library dependencies (e.g., Lucene)
v3.0.0
Issues and PRs related to version 3.0.0
#4341
by adnapibar
was merged Aug 30, 2022
Loading…
2 of 6 tasks
[Backport 1.x] Bump commons-configuration2 from 2.7 to 2.8.0 in /plugins/repository-hdfs
backport
PRs or issues specific to backporting features or enhancments
CVE
Fixes a CVE
dependencies
Pull requests that update a dependency file
>upgrade
Label used when upgrading library dependencies (e.g., Lucene)
#4645
by opensearch-trigger-bot
bot
was merged Sep 30, 2022
Loading…
[Backport 1.3] Bump commons-configuration2 from 2.7 to 2.8.0 in /plugins/repository-hdfs
CVE
Fixes a CVE
dependencies
Pull requests that update a dependency file
>upgrade
Label used when upgrading library dependencies (e.g., Lucene)
v1.3.0
#4646
by opensearch-trigger-bot
bot
was merged Sep 30, 2022
Loading…
[2.x] Bump jettison version from 1.4.1 to 1.5.1
CVE
Fixes a CVE
dependencies
Pull requests that update a dependency file
>upgrade
Label used when upgrading library dependencies (e.g., Lucene)
#4717
by Rishikesh1159
was merged Oct 10, 2022
Loading…
6 tasks
Previous Next
ProTip!
Add no:assignee to see everything that’s not assigned.