Skip to content

Update logback dependencies to version 1.5.19#1996

Merged
riysaxen-amzn merged 1 commit intoopensearch-project:mainfrom
dbwiddis:patch-1
Dec 9, 2025
Merged

Update logback dependencies to version 1.5.19#1996
riysaxen-amzn merged 1 commit intoopensearch-project:mainfrom
dbwiddis:patch-1

Conversation

@dbwiddis
Copy link
Member

@dbwiddis dbwiddis commented Dec 3, 2025

Description

Resolves CVE-2025-11226.

Related Issues

See https://logback.qos.ch/news.html#1.5.19

Check List

  • Commits are signed per the DCO using --signoff.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

Signed-off-by: Daniel Widdis <widdis@gmail.com>
@riysaxen-amzn
Copy link
Collaborator

why some of the CI's are failing?

@riysaxen-amzn riysaxen-amzn added the v3.4.0 Issues targeting release v3.4.0 label Dec 9, 2025
@dbwiddis
Copy link
Member Author

dbwiddis commented Dec 9, 2025

why some of the CI's are failing?

The tests pass, looks like something wrong with artifact uploading with duplicate name, not unique per matrix. Once jdk25 upload completes the jdk21 and jdk24 uploads fail.

Upload is only unique per OS, needs to also have a different name per JDK version.

name: alerting-plugin-${{ matrix.os }}

Fixed in:

@dbwiddis
Copy link
Member Author

dbwiddis commented Dec 9, 2025

@riysaxen-amzn can you please add a "backport 3.4" label and tag this PR with it?

@riysaxen-amzn
Copy link
Collaborator

@riysaxen-amzn can you please add a "backport 3.4" label and tag this PR with it?

backport failed

@dbwiddis
Copy link
Member Author

dbwiddis commented Dec 9, 2025

backport failed

Won't actually backport until this one is merged.

@riysaxen-amzn riysaxen-amzn merged commit 72f9fcf into opensearch-project:main Dec 9, 2025
14 of 20 checks passed
opensearch-trigger-bot bot pushed a commit that referenced this pull request Dec 9, 2025
Signed-off-by: Daniel Widdis <widdis@gmail.com>
(cherry picked from commit 72f9fcf)
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
@dbwiddis dbwiddis deleted the patch-1 branch December 9, 2025 23:35
riysaxen-amzn pushed a commit that referenced this pull request Dec 10, 2025
(cherry picked from commit 72f9fcf)

Signed-off-by: Daniel Widdis <widdis@gmail.com>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
AWSHurneyt pushed a commit to AWSHurneyt/OpenSearch-Alerting that referenced this pull request Feb 12, 2026
… (opensearch-project#2002)

(cherry picked from commit 72f9fcf)

Signed-off-by: Daniel Widdis <widdis@gmail.com>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Signed-off-by: Thomas Hurney <hurneyt@amazon.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport 3.4 v3.4.0 Issues targeting release v3.4.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants