[GitHub] [felix-dev] dependabot[bot] commented on pull request #141: Bump commons-io from 2.6 to 2.7 in /http/bridge-4.x

2022-10-06 Thread GitBox
dependabot[bot] commented on PR #141: URL: https://github.com/apache/felix-dev/pull/141#issuecomment-1271187557 Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting `@dependabot rebase`. -

[jira] [Resolved] (FELIX-6564) NPE while retrieving component descriptions from SCR

2022-10-06 Thread Jira
[ https://issues.apache.org/jira/browse/FELIX-6564?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jean-Baptiste Onofré resolved FELIX-6564. - Fix Version/s: scr-2.2.4 Resolution: Fixed > NPE while retrieving componen

Re: SCR Release

2022-10-06 Thread Amit Mondal
Hi Jean-Baptiste, Thanks a lot for preparing the release. Best Regards, Amit From: Jean-Baptiste Onofr? Sent: 06 October 2022 15:53 To: dev@felix.apache.org Subject: Re: SCR Release Hi Amit, I'm preparing the release (dryRun) and doing a Jira pass now. Regard

[jira] [Assigned] (FELIX-6564) NPE while retrieving component descriptions from SCR

2022-10-06 Thread Jira
[ https://issues.apache.org/jira/browse/FELIX-6564?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jean-Baptiste Onofré reassigned FELIX-6564: --- Assignee: Jean-Baptiste Onofré > NPE while retrieving component descriptions

[jira] [Assigned] (FELIX-6568) Add skip option to maven-bundle-plugin goals

2022-10-06 Thread Jira
[ https://issues.apache.org/jira/browse/FELIX-6568?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jean-Baptiste Onofré reassigned FELIX-6568: --- Assignee: Jean-Baptiste Onofré > Add skip option to maven-bundle-plugin goal

Re: [VOTE] Release Apache Felix Http Base 4.2.2, Bridge 4.2.2 and Jetty 4.2.2

2022-10-06 Thread Jean-Baptiste Onofré
+1 (binding) Regards JB On Thu, Oct 6, 2022 at 3:45 PM Carsten Ziegeler wrote: > > Hi, > > > We solved three issues for Http Jetty 4.2.2 > https://issues.apache.org/jira/browse/FELIX-6569?jql=project%20%3D%20FELIX%20AND%20fixVersion%20%3D%20http.jetty-4.2.2 > > We solved two issues for Http Base

Re: [VOTE] Release Apache Felix Http Base 4.2.2, Bridge 4.2.2 and Jetty 4.2.2

2022-10-06 Thread Raymond Augé
+1 On Thu, Oct 6, 2022 at 9:48 AM Carsten Ziegeler wrote: > +1 > > Carsten > > Am 06.10.2022 um 15:45 schrieb Carsten Ziegeler: > > Hi, > > > > > > We solved three issues for Http Jetty 4.2.2 > > > https://issues.apache.org/jira/browse/FELIX-6569?jql=project%20%3D%20FELIX%20AND%20fixVersion%20%3

Re: SCR Release

2022-10-06 Thread Jean-Baptiste Onofré
Hi Amit, I'm preparing the release (dryRun) and doing a Jira pass now. Regards JB On Wed, Oct 5, 2022 at 6:51 PM Amit Mondal wrote: > > Hi Jean-Baptiste, > > Thanks a lot for taking care of it. > > Best Regards, > Amit > > From: Jean-Baptiste Onofr? > Sent: 05

[GitHub] [felix-dev] dependabot[bot] commented on pull request #141: Bump commons-io from 2.6 to 2.7 in /http/bridge-4.x

2022-10-06 Thread GitBox
dependabot[bot] commented on PR #141: URL: https://github.com/apache/felix-dev/pull/141#issuecomment-1270088455 Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting `@dependabot rebase`. -

Re: [VOTE] Release Apache Felix Http Base 4.2.2, Bridge 4.2.2 and Jetty 4.2.2

2022-10-06 Thread Carsten Ziegeler
+1 Carsten Am 06.10.2022 um 15:45 schrieb Carsten Ziegeler: Hi, We solved three issues for Http Jetty 4.2.2 https://issues.apache.org/jira/browse/FELIX-6569?jql=project%20%3D%20FELIX%20AND%20fixVersion%20%3D%20http.jetty-4.2.2 We solved two issues for Http Base 4.2.2 https://issues.apache.or

Re: [VOTE] Release Apache Felix Http Base 4.2.2, Bridge 4.2.2 and Jetty 4.2.2

2022-10-06 Thread Thomas Watson
+1 Tom On Thu, Oct 6, 2022 at 8:45 AM Carsten Ziegeler wrote: > Hi, > > > We solved three issues for Http Jetty 4.2.2 > > https://issues.apache.org/jira/browse/FELIX-6569?jql=project%20%3D%20FELIX%20AND%20fixVersion%20%3D%20http.jetty-4.2.2 > > We solved two issues for Http Base 4.2.2 > > https

[VOTE] Release Apache Felix Http Base 4.2.2, Bridge 4.2.2 and Jetty 4.2.2

2022-10-06 Thread Carsten Ziegeler
Hi, We solved three issues for Http Jetty 4.2.2 https://issues.apache.org/jira/browse/FELIX-6569?jql=project%20%3D%20FELIX%20AND%20fixVersion%20%3D%20http.jetty-4.2.2 We solved two issues for Http Base 4.2.2 https://issues.apache.org/jira/browse/FELIX-6553?jql=project%20%3D%20FELIX%20AND%20fixV

[GitHub] [felix-dev] dependabot[bot] opened a new pull request, #176: Bump plexus-archiver from 3.5 to 3.6.0 in /tools/osgicheck-maven-plugin

2022-10-06 Thread GitBox
dependabot[bot] opened a new pull request, #176: URL: https://github.com/apache/felix-dev/pull/176 Bumps [plexus-archiver](https://github.com/codehaus-plexus/plexus-archiver) from 3.5 to 3.6.0. Release notes Sourced from https://github.com/codehaus-plexus/plexus-archiver/releases";

[jira] [Commented] (FELIX-6569) Felix embeds vulnerable version of Jetty (CVE-2022-2048)

2022-10-06 Thread Akanksha Jain (Jira)
[ https://issues.apache.org/jira/browse/FELIX-6569?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17613469#comment-17613469 ] Akanksha Jain commented on FELIX-6569: -- Thank you [~cziegeler]  > Felix embeds vuln

[jira] [Commented] (FELIX-6569) Felix embeds vulnerable version of Jetty (CVE-2022-2048)

2022-10-06 Thread Carsten Ziegeler (Jira)
[ https://issues.apache.org/jira/browse/FELIX-6569?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17613468#comment-17613468 ] Carsten Ziegeler commented on FELIX-6569: - I've updated to the latest available v

[GitHub] [felix-dev] dependabot[bot] closed pull request #164: Bump http2-server from 9.4.45.v20220203 to 9.4.48.v20220622 in /http/jetty-4.x

2022-10-06 Thread GitBox
dependabot[bot] closed pull request #164: Bump http2-server from 9.4.45.v20220203 to 9.4.48.v20220622 in /http/jetty-4.x URL: https://github.com/apache/felix-dev/pull/164 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use th

[GitHub] [felix-dev] dependabot[bot] commented on pull request #164: Bump http2-server from 9.4.45.v20220203 to 9.4.48.v20220622 in /http/jetty-4.x

2022-10-06 Thread GitBox
dependabot[bot] commented on PR #164: URL: https://github.com/apache/felix-dev/pull/164#issuecomment-1269897299 Looks like org.eclipse.jetty.http2:http2-server is up-to-date now, so this is no longer needed. -- This is an automated message from the Apache Git Service. To respond to the me

[GitHub] [felix-dev] dependabot[bot] closed pull request #167: Bump jetty-server from 9.4.45.v20220203 to 10.0.10 in /http/jetty-4.x

2022-10-06 Thread GitBox
dependabot[bot] closed pull request #167: Bump jetty-server from 9.4.45.v20220203 to 10.0.10 in /http/jetty-4.x URL: https://github.com/apache/felix-dev/pull/167 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL abo

[GitHub] [felix-dev] dependabot[bot] commented on pull request #167: Bump jetty-server from 9.4.45.v20220203 to 10.0.10 in /http/jetty-4.x

2022-10-06 Thread GitBox
dependabot[bot] commented on PR #167: URL: https://github.com/apache/felix-dev/pull/167#issuecomment-1269891620 Looks like org.eclipse.jetty:jetty-server is up-to-date now, so this is no longer needed. -- This is an automated message from the Apache Git Service. To respond to the message,

[jira] [Resolved] (FELIX-6569) Felix embeds vulnerable version of Jetty (CVE-2022-2048)

2022-10-06 Thread Carsten Ziegeler (Jira)
[ https://issues.apache.org/jira/browse/FELIX-6569?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Carsten Ziegeler resolved FELIX-6569. - Resolution: Fixed > Felix embeds vulnerable version of Jetty (CVE-2022-2048) > --

[jira] [Commented] (FELIX-6569) Felix embeds vulnerable version of Jetty (CVE-2022-2048)

2022-10-06 Thread Carsten Ziegeler (Jira)
[ https://issues.apache.org/jira/browse/FELIX-6569?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17613465#comment-17613465 ] Carsten Ziegeler commented on FELIX-6569: - Thanks [~akanksha88] - I've applied yo

[GitHub] [felix-dev] cziegeler merged pull request #175: FELIX-6569 - upgrade jetty version to fix CVE-2022-2048

2022-10-06 Thread GitBox
cziegeler merged PR #175: URL: https://github.com/apache/felix-dev/pull/175 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: dev-unsubscr...@felix.apache

[jira] [Assigned] (FELIX-6569) Felix embeds vulnerable version of Jetty (CVE-2022-2048)

2022-10-06 Thread Carsten Ziegeler (Jira)
[ https://issues.apache.org/jira/browse/FELIX-6569?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Carsten Ziegeler reassigned FELIX-6569: --- Assignee: Carsten Ziegeler > Felix embeds vulnerable version of Jetty (CVE-2022-2048

[jira] [Updated] (FELIX-6569) Felix embeds vulnerable version of Jetty (CVE-2022-2048)

2022-10-06 Thread Carsten Ziegeler (Jira)
[ https://issues.apache.org/jira/browse/FELIX-6569?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Carsten Ziegeler updated FELIX-6569: Fix Version/s: http.jetty-4.2.2 > Felix embeds vulnerable version of Jetty (CVE-2022-2048)

[jira] [Updated] (FELIX-6569) Felix embeds vulnerable version of Jetty (CVE-2022-2048)

2022-10-06 Thread Carsten Ziegeler (Jira)
[ https://issues.apache.org/jira/browse/FELIX-6569?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Carsten Ziegeler updated FELIX-6569: Affects Version/s: http.jetty-4.2.0 > Felix embeds vulnerable version of Jetty (CVE-2022-20

[jira] [Commented] (FELIX-6569) Felix embeds vulnerable version of Jetty (CVE-2022-2048)

2022-10-06 Thread Akanksha Jain (Jira)
[ https://issues.apache.org/jira/browse/FELIX-6569?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17613452#comment-17613452 ] Akanksha Jain commented on FELIX-6569: -- [~cziegeler]  I have updated the jetty vers

[jira] [Updated] (FELIX-6569) Felix embeds vulnerable version of Jetty (CVE-2022-2048)

2022-10-06 Thread Akanksha Jain (Jira)
[ https://issues.apache.org/jira/browse/FELIX-6569?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Akanksha Jain updated FELIX-6569: - Description: Vulnerability: [https://nvd.nist.gov/vuln/detail/CVE-2022-2048] Description: [https

[jira] [Created] (FELIX-6569) Felix embeds vulnerable version of Jetty (CVE-2022-2048)

2022-10-06 Thread Akanksha Jain (Jira)
Akanksha Jain created FELIX-6569: Summary: Felix embeds vulnerable version of Jetty (CVE-2022-2048) Key: FELIX-6569 URL: https://issues.apache.org/jira/browse/FELIX-6569 Project: Felix Issue