That is great David!

With another batch of merging, there are NO MORE SOLRBOT PR’S OPEN!!!

https://github.com/apache/solr/pulls/solrbot

Plus, I’ve finished documenting with VEX files the remaining 7 vulnerabilities 
from https://github.com/apache/solr/security/dependabot.

I’ll merge https://github.com/apache/solr-site/pull/232 probably tomorrow and 
republish the website.

Thanks Jan for helping me on the Github Actions (and a bunch of silly questions 
on how to do dependency upgrades).

Theoretically next week Tuesday morning Solrbot will wake up and open a new set 
of dependency upgrade PR’s, however:

1) No Java 17 or later upgrades being opened against branch_9x
2) Grouped upgrades so we don’t have a million separate PR's against branch_9x 
and main.

Then maybe we can stay on top of it better and focus more on adding value, not 
plugging security holes ;-).

Eric

> On Aug 25, 2026, at 9:29 AM, David Smiley <[email protected]> wrote:
> 
> I'm addressing org.apache.solr.cloud.RecoveryAfterSoftCommitTest.test and
> likely other flaky failures via
> https://issues.apache.org/jira/browse/SOLR-18401 
> <https://issues.apache.org/jira/browse/SOLR-18401>
> 
> On Sun, Aug 23, 2026 at 6:07 AM Eric Pugh <[email protected]>
> wrote:
> 
> > These two builds are working fine:
> >
> > https://ci-builds.apache.org/job/Solr/job/Solr-Test-9.x/ 
> > <https://ci-builds.apache.org/job/Solr/job/Solr-Test-9.x>
> > https://ci-builds.apache.org/job/Solr/job/Solr-Test-10.x/ 
> > <https://ci-builds.apache.org/job/Solr/job/Solr-Test-10.x>
> >
> > However, https://ci-builds.apache.org/job/Solr/job/Solr-Test-main/ 
> > <https://ci-builds.apache.org/job/Solr/job/Solr-Test-main> seems
> > to have a test that fails more often than not….
> >
> >
> >
> >
> > > On Aug 22, 2026, at 1:43 PM, Eric Pugh <[email protected]>
> > wrote:
> > >
> > > Hey all,
> > >
> > > I worked through the long list of “solrbot” authored PR’s (
> > https://github.com/apache/solr/pulls/solrbot 
> > <https://github.com/apache/solr/pulls/solrbot>) and applied a bunch, to
> > both main/branch_10x and some to branch_9x.
> > >
> > > There was definitely some fighting with lock files, so I’m hoping I’ve
> > handled them all appropriately, and haven’t interfered with some other
> > efforts to manage these better.
> > >
> > > In chatting with Jan, we talked about disabling the built in Github
> > “dependabot” that was opening PR’s for upgrades as security alerts are
> > found. This was leading to quite a few duplicate PRs with PR’s opened by
> > “solrbot”. https://github.com/apache/solr/pull/4798 
> > <https://github.com/apache/solr/pull/4798>
> > >
> > > This way we will just have a monthly batch of upgrades for branch_9x and
> > main. I’m hoping to finish next week getting the backlog of upgrade pre
> > generated by "dependably" and “solrbot" cleared up.
> > >
> > > Eric
> > >
> >
> > Disclaimer
> >
> > The information contained in this communication from the sender is
> > confidential. It is intended solely for use by the recipient and others
> > authorized to receive it. If you are not the recipient, you are hereby
> > notified that any disclosure, copying, distribution or taking action in
> > relation of the contents of this information is strictly prohibited and may
> > be unlawful.
> >
> > This email has been scanned for viruses and malware, and may have been
> > automatically archived by Mimecast, a leader in email security and cyber
> > resilience. Mimecast integrates email defenses with brand protection,
> > security awareness training, web security, compliance and other essential
> > capabilities. Mimecast helps protect large and small organizations from
> > malicious activity, human error and technology failure; and to lead the
> > movement toward building a more resilient world. To find out more, visit
> > our website.
> >

Disclaimer

The information contained in this communication from the sender is 
confidential. It is intended solely for use by the recipient and others 
authorized to receive it. If you are not the recipient, you are hereby notified 
that any disclosure, copying, distribution or taking action in relation of the 
contents of this information is strictly prohibited and may be unlawful.

This email has been scanned for viruses and malware, and may have been 
automatically archived by Mimecast, a leader in email security and cyber 
resilience. Mimecast integrates email defenses with brand protection, security 
awareness training, web security, compliance and other essential capabilities. 
Mimecast helps protect large and small organizations from malicious activity, 
human error and technology failure; and to lead the movement toward building a 
more resilient world. To find out more, visit our website.

Reply via email to