Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Mark release blocker Issues with a Label #6870

Closed
plaird opened this issue Sep 28, 2021 · 9 comments
Closed

Mark release blocker Issues with a Label #6870

plaird opened this issue Sep 28, 2021 · 9 comments
Labels
enhancement Feature not a bug

Comments

@plaird
Copy link

plaird commented Sep 28, 2021

The 5.0.0-alpha.2 version was released 8 months ago on 2021-01-30. I have reviewed the commit history since then, and the open issues, but it isn't clear to me what is preventing the 5.0.0 release. I am doing this to assess whether the alpha.2 version is suitable for our use now, or whether we need to wait until the official 5.0.0 release.

It would be great if you could create a new Label (e.g. 5.0.0 Blocker, Release Blocker, etc) and assign that to the open Issues that are blocking the release. Thanks!

@plaird plaird added the enhancement Feature not a bug label Sep 28, 2021
@JakeWharton
Copy link
Member

A stable Okio release is a major blocker.

@simontoens
Copy link

Hi @JakeWharton we are also waiting for the 5.x release because security scanners are flagging okhttp because of this CVE. We are getting pressure from our security team to upgrade but we are reluctant to use an alpha release in production. Since Okio is also owned by Square, could you (or anybody else) provide a rough estimate of when we can expect an official 5.x release of okhttp?

@yschimke
Copy link
Collaborator

Yep - I think that would be included in a 4.9.2 #6741

But the good news is that the analysis of that CVE was that it wasn't called in that form by OkHttp. You'd have to create an OkHttp client, extract the hostname verifier (a public API) then use it outside of the scope of OkHttp to be hit by that bug.

@simontoens
Copy link

Thanks @yschimke. We will upgrade to that version. Unfortunately our scanner doesn't think that version has a fix - our scanner only points us to the 5.x alpha version.

@simontoens
Copy link

Hi @yschimke, looking in Maven Central and tags here, I only see 4.9.1 but not 4.9.2 ...?

@yschimke
Copy link
Collaborator

Sorry for the confusing message. I included "would" as in if we release 4.9.2.

@simontoens
Copy link

Thanks @yschimke - so my next question then is: do you know when 4.9.2 may get released?

@yschimke
Copy link
Collaborator

yschimke commented Oct 1, 2021

4.9.2 was just released by @swankjesse

@yschimke yschimke closed this as completed Oct 1, 2021
@simontoens
Copy link

Thank you @yschimke @swankjesse

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement Feature not a bug
Projects
None yet
Development

No branches or pull requests

4 participants