Skip to content

Conversation

dbwiddis
Copy link
Member

Backports f2cc655 from #18104
Backports b53de2b from #18336

Fixes CVE-2025-53864

dependabot bot and others added 2 commits October 11, 2025 14:59
…ository-azure (opensearch-project#18104)

* Bump com.nimbusds:nimbus-jose-jwt in /plugins/repository-azure

Bumps [com.nimbusds:nimbus-jose-jwt](https://bitbucket.org/connect2id/nimbus-jose-jwt) from 10.0.2 to 10.2.
- [Changelog](https://bitbucket.org/connect2id/nimbus-jose-jwt/src/master/CHANGELOG.txt)
- [Commits](https://bitbucket.org/connect2id/nimbus-jose-jwt/branches/compare/10.2..10.0.2)

---
updated-dependencies:
- dependency-name: com.nimbusds:nimbus-jose-jwt
  dependency-version: '10.2'
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>

* Updating SHAs

Signed-off-by: dependabot[bot] <[email protected]>

* Update changelog

Signed-off-by: dependabot[bot] <[email protected]>

* Fix thirdPartyAudit

Signed-off-by: Craig Perkins <[email protected]>

---------

Signed-off-by: dependabot[bot] <[email protected]>
Signed-off-by: Craig Perkins <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Craig Perkins <[email protected]>
(cherry picked from commit f2cc655)
…es/hdfs-fixture (opensearch-project#18336)

* Bump com.nimbusds:nimbus-jose-jwt in /test/fixtures/hdfs-fixture

Bumps [com.nimbusds:nimbus-jose-jwt](https://bitbucket.org/connect2id/nimbus-jose-jwt) from 10.0.2 to 10.3.
- [Changelog](https://bitbucket.org/connect2id/nimbus-jose-jwt/src/master/CHANGELOG.txt)
- [Commits](https://bitbucket.org/connect2id/nimbus-jose-jwt/branches/compare/10.3..10.0.2)

---
updated-dependencies:
- dependency-name: com.nimbusds:nimbus-jose-jwt
  dependency-version: '10.3'
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>

* Update changelog

Signed-off-by: dependabot[bot] <[email protected]>

---------

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
(cherry picked from commit b53de2b)
@dbwiddis dbwiddis requested a review from a team as a code owner October 11, 2025 22:10
@dbwiddis dbwiddis added the CVE Fixes a CVE label Oct 11, 2025
Copy link
Contributor

❌ Gradle check result for 4900c6c: null

Please examine the workflow log, locate, and copy-paste the failure(s) below, then iterate to green. Is the failure a flaky test unrelated to your change?

Copy link
Contributor

❌ Gradle check result for 4900c6c: FAILURE

Please examine the workflow log, locate, and copy-paste the failure(s) below, then iterate to green. Is the failure a flaky test unrelated to your change?

Copy link
Contributor

❌ Gradle check result for 4900c6c: null

Please examine the workflow log, locate, and copy-paste the failure(s) below, then iterate to green. Is the failure a flaky test unrelated to your change?

Copy link
Contributor

❌ Gradle check result for 4900c6c:

Please examine the workflow log, locate, and copy-paste the failure(s) below, then iterate to green. Is the failure a flaky test unrelated to your change?

Copy link
Contributor

✅ Gradle check result for 4900c6c: SUCCESS

Copy link

codecov bot commented Oct 12, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 72.04%. Comparing base (7caafaf) to head (4900c6c).
⚠️ Report is 5 commits behind head on 2.19.

Additional details and impacted files
@@             Coverage Diff              @@
##               2.19   #19604      +/-   ##
============================================
+ Coverage     72.02%   72.04%   +0.02%     
- Complexity    66027    66049      +22     
============================================
  Files          5341     5341              
  Lines        307273   307273              
  Branches      44845    44845              
============================================
+ Hits         221320   221386      +66     
+ Misses        67537    67427     -110     
- Partials      18416    18460      +44     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@dbwiddis dbwiddis added the v2.19.4 Issues targeting release v2.19.4 label Oct 12, 2025
@cwperks cwperks merged commit d9d178d into opensearch-project:2.19 Oct 13, 2025
55 of 63 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CVE Fixes a CVE v2.19.4 Issues targeting release v2.19.4

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants