Here are the change requests. If anyone has time, will you give them a review? They are all straightforward version bumps, so hopefully will not take a lot of time.
Update Guava to 30.1
https://git.eclipse.org/r/c/orbit/orbit-recipes/+/175412
Guava 27.1 is intentionally retained in order to provide transition window.
Update Apache HttpComponents HttpClient to 4.13.5
https://git.eclipse.org/r/c/orbit/orbit-recipes/+/175418
Update com.fasterxml.jackson to 2.12.1
https://git.eclipse.org/r/c/orbit/orbit-recipes/+/175420
This one is failing because it depends on 175412. After that one is merged, this one will pass.
Thanks!
Tony Homer
From: orbit-dev <orbit-dev-bounces@xxxxxxxxxxx> on behalf of Jonah Graham <jonah@xxxxxxxxxxxxxxxx>
Reply-To: Orbit Developer discussion <orbit-dev@xxxxxxxxxxx>
Date: Wednesday, January 27, 2021 at 11:48 AM
To: Orbit Developer discussion <orbit-dev@xxxxxxxxxxx>
Subject: Re: [orbit-dev] Late 2021-03 M2 Build / Consuming I-builds
On 1/27/21 , 9:51 AM, "orbit-dev on behalf of Homer, Tony" <orbit-dev-bounces@xxxxxxxxxxx on behalf of
tony.homer@xxxxxxxxx> wrote:
Thanks for this, Roland.
I intend to update 3 sets of dependencies for which the latest version available in Orbit is vulnerable to CVEs.
I plan to add Guava 30.1 (retaining 27.1 for now in order to give teams time to update), bump Jackson to 2.12.1 and bump apache http-client to 4.5.13.
I logged one issue in Bugzilla and will add the others today.
I hope to get the changes opened tomorrow morning (PST).
I hope to get some quick reviews so that I can merge these by Friday, then I will follow the steps you provided.
Tony Homer
On 1/27/21 , 9:44 AM, "orbit-dev on behalf of Roland Grunberg" <orbit-dev-bounces@xxxxxxxxxxx on behalf of
rgrunber@xxxxxxxxxx> wrote:
Hey all,
Unfortunately I don't think I'll have time to put together an M2 (S-
build) so platform has continued using M1. Every change is also
consumable through the latest I-builds so that is also possible. I'm
still around to keep our builds in good working order, particularly
leading up to the final release.
There also haven't been many changes in Orbit for M2 but if any
committer is interested, I have instructions at the following link on
how promote an S-build for M2 :
https://wiki.eclipse.org/Orbit/Adding_Bundles_To_Orbit_In_5_Minutes#Manual_Build_And_Promotion
If anyone is interested but needs some extra hints/information, feel
free to contact me.
Cheers,
--
Roland Grunberg
_______________________________________________
orbit-dev mailing list
orbit-dev@xxxxxxxxxxx
To unsubscribe from this list, visit
https://www.eclipse.org/mailman/listinfo/orbit-dev
_______________________________________________
orbit-dev mailing list
orbit-dev@xxxxxxxxxxx
To unsubscribe from this list, visit
https://www.eclipse.org/mailman/listinfo/orbit-dev
_______________________________________________
orbit-dev mailing list
orbit-dev@xxxxxxxxxxx
To unsubscribe from this list, visit
https://www.eclipse.org/mailman/listinfo/orbit-dev
|