Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump tar from 6.1.13 to 6.2.1 #6492

Merged
merged 6 commits into from
Jun 5, 2024
Merged

Conversation

LDrago27
Copy link
Contributor

@LDrago27 LDrago27 commented Apr 16, 2024

Description

Bumps the tar package from 6.1.13 to 6.2.1. It is a complete version of #6397 which is linked to CVE(#6488) mentioned here.

Changelog

Check List

  • All tests pass
    • yarn test:jest
    • yarn test:jest_integration
  • New functionality includes testing.
  • New functionality has been documented.
  • Update CHANGELOG.md
  • Commits are signed per the DCO using --signoff

ananzh
ananzh previously approved these changes Apr 16, 2024
Copy link
Contributor

❌ Invalid Changelog Heading

The '## Changelog' heading in your PR description is either missing or malformed. Please make sure that your PR description includes a '## Changelog' heading with proper spelling, capitalization, spacing, and Markdown syntax.

Copy link
Contributor

❌ Changelog Entry Missing Hyphen

Changelog entries must begin with a hyphen (-).

Copy link
Contributor

❌ Invalid Prefix For Manual Changeset Creation

Invalid description prefix. Found "Bump tar package from 6.1.13 to 6.2.1". Only "skip" entry option is permitted for manual commit of changeset files.

If you were trying to skip the changelog entry, please use the "skip" entry option in the ##Changelog section of your PR description.

Copy link
Contributor

❌ Invalid Prefix For Manual Changeset Creation

Invalid description prefix. Found "chore". Only "skip" entry option is permitted for manual commit of changeset files.

If you were trying to skip the changelog entry, please use the "skip" entry option in the ##Changelog section of your PR description.

opensearch-changeset-bot bot added a commit to LDrago27/OpenSearch-Dashboards that referenced this pull request Apr 16, 2024
@ananzh
Copy link
Member

ananzh commented Jun 4, 2024

Changelog should be security not chore.
Can use this one #6770 as a reference.
It will create a changelog file automatically in the changelogs/fragments. You could just remove your changelog.md changes.

Signed-off-by: Suchit Sahoo <suchsah@amazon.com>
Copy link
Contributor

github-actions bot commented Jun 5, 2024

❌ Entry Too Long

Entry is 104 characters long, which is 4 characters longer than the maximum allowed length of 100 characters. Please revise your entry to be within the maximum length.

@LDrago27
Copy link
Contributor Author

LDrago27 commented Jun 5, 2024

Changelog should be security not chore. Can use this one #6770 as a reference. It will create a changelog file automatically in the changelogs/fragments. You could just remove your changelog.md changes.

Updated the change log

@ananzh ananzh added the cve Security vulnerabilities detected by Dependabot or Mend label Jun 5, 2024
@AMoo-Miki AMoo-Miki merged commit 2b8600d into opensearch-project:main Jun 5, 2024
72 checks passed
opensearch-trigger-bot bot pushed a commit that referenced this pull request Jun 5, 2024
* [CVE-2024-28863] Bump tar from 6.1.11 to 6.2.1

Signed-off-by: Suchit Sahoo <suchsah@amazon.com>

* Changeset file for PR #6492 created/updated

* Changeset file for PR #6492 created/updated

* Changeset file for PR #6492 created/updated

* Changeset file for PR #6492 created/updated

* Changeset file for PR #6492 created/updated

---------

Signed-off-by: Suchit Sahoo <suchsah@amazon.com>
Co-authored-by: opensearch-changeset-bot[bot] <154024398+opensearch-changeset-bot[bot]@users.noreply.github.com>
(cherry picked from commit 2b8600d)
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
BionIT pushed a commit that referenced this pull request Jun 5, 2024
* [CVE-2024-28863] Bump tar from 6.1.11 to 6.2.1



* Changeset file for PR #6492 created/updated

* Changeset file for PR #6492 created/updated

* Changeset file for PR #6492 created/updated

* Changeset file for PR #6492 created/updated

* Changeset file for PR #6492 created/updated

---------



(cherry picked from commit 2b8600d)

Signed-off-by: Suchit Sahoo <suchsah@amazon.com>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: opensearch-changeset-bot[bot] <154024398+opensearch-changeset-bot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
backport 2.x cve Security vulnerabilities detected by Dependabot or Mend repeat-contributor v2.15.0
Projects
None yet
Development

Successfully merging this pull request may close these issues.

CVE-2024-28863 (Medium) detected in tar-6.1.11.tgz, tar-6.1.13.tgz
3 participants