Skip to content

Bump tar from 6.1.13 to 6.2.1#6492

Merged
AMoo-Miki merged 6 commits intoopensearch-project:mainfrom
LDrago27:remoteMain
Jun 5, 2024
Merged

Bump tar from 6.1.13 to 6.2.1#6492
AMoo-Miki merged 6 commits intoopensearch-project:mainfrom
LDrago27:remoteMain

Conversation

@LDrago27
Copy link
Copy Markdown
Collaborator

@LDrago27 LDrago27 commented Apr 16, 2024

Description

Bumps the tar package from 6.1.13 to 6.2.1. It is a complete version of #6397 which is linked to CVE(#6488) mentioned here.

Changelog

Check List

  • All tests pass
    • yarn test:jest
    • yarn test:jest_integration
  • New functionality includes testing.
  • New functionality has been documented.
  • Update CHANGELOG.md
  • Commits are signed per the DCO using --signoff

ananzh
ananzh previously approved these changes Apr 16, 2024
@github-actions
Copy link
Copy Markdown
Contributor

❌ Invalid Changelog Heading

The '## Changelog' heading in your PR description is either missing or malformed. Please make sure that your PR description includes a '## Changelog' heading with proper spelling, capitalization, spacing, and Markdown syntax.

@github-actions
Copy link
Copy Markdown
Contributor

❌ Changelog Entry Missing Hyphen

Changelog entries must begin with a hyphen (-).

@github-actions
Copy link
Copy Markdown
Contributor

❌ Invalid Prefix For Manual Changeset Creation

Invalid description prefix. Found "Bump tar package from 6.1.13 to 6.2.1". Only "skip" entry option is permitted for manual commit of changeset files.

If you were trying to skip the changelog entry, please use the "skip" entry option in the ##Changelog section of your PR description.

@github-actions
Copy link
Copy Markdown
Contributor

❌ Invalid Prefix For Manual Changeset Creation

Invalid description prefix. Found "chore". Only "skip" entry option is permitted for manual commit of changeset files.

If you were trying to skip the changelog entry, please use the "skip" entry option in the ##Changelog section of your PR description.

opensearch-changeset-bot bot added a commit to LDrago27/OpenSearch-Dashboards that referenced this pull request Apr 16, 2024
@ananzh
Copy link
Copy Markdown
Member

ananzh commented Jun 4, 2024

Changelog should be security not chore.
Can use this one #6770 as a reference.
It will create a changelog file automatically in the changelogs/fragments. You could just remove your changelog.md changes.

Signed-off-by: Suchit Sahoo <suchsah@amazon.com>
@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Jun 5, 2024

❌ Entry Too Long

Entry is 104 characters long, which is 4 characters longer than the maximum allowed length of 100 characters. Please revise your entry to be within the maximum length.

@LDrago27
Copy link
Copy Markdown
Collaborator Author

LDrago27 commented Jun 5, 2024

Changelog should be security not chore. Can use this one #6770 as a reference. It will create a changelog file automatically in the changelogs/fragments. You could just remove your changelog.md changes.

Updated the change log

@ananzh ananzh added the cve Security vulnerabilities detected by Dependabot or Mend label Jun 5, 2024
@AMoo-Miki AMoo-Miki merged commit 2b8600d into opensearch-project:main Jun 5, 2024
opensearch-trigger-bot bot pushed a commit that referenced this pull request Jun 5, 2024
* [CVE-2024-28863] Bump tar from 6.1.11 to 6.2.1

Signed-off-by: Suchit Sahoo <suchsah@amazon.com>

* Changeset file for PR #6492 created/updated

* Changeset file for PR #6492 created/updated

* Changeset file for PR #6492 created/updated

* Changeset file for PR #6492 created/updated

* Changeset file for PR #6492 created/updated

---------

Signed-off-by: Suchit Sahoo <suchsah@amazon.com>
Co-authored-by: opensearch-changeset-bot[bot] <154024398+opensearch-changeset-bot[bot]@users.noreply.github.com>
(cherry picked from commit 2b8600d)
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
BionIT pushed a commit that referenced this pull request Jun 5, 2024
* [CVE-2024-28863] Bump tar from 6.1.11 to 6.2.1



* Changeset file for PR #6492 created/updated

* Changeset file for PR #6492 created/updated

* Changeset file for PR #6492 created/updated

* Changeset file for PR #6492 created/updated

* Changeset file for PR #6492 created/updated

---------



(cherry picked from commit 2b8600d)

Signed-off-by: Suchit Sahoo <suchsah@amazon.com>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: opensearch-changeset-bot[bot] <154024398+opensearch-changeset-bot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport 2.x cve Security vulnerabilities detected by Dependabot or Mend repeat-contributor v2.15.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CVE-2024-28863 (Medium) detected in tar-6.1.11.tgz, tar-6.1.13.tgz

3 participants