You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@flink.apache.org by GitBox <gi...@apache.org> on 2022/01/07 12:35:13 UTC

[GitHub] [flink] Chromico opened a new pull request #18300: Update H2 to 2.0.206 to address CVE-2021-42392.

Chromico opened a new pull request #18300:
URL: https://github.com/apache/flink/pull/18300


   https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42392


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscribe@flink.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [flink] deadwind4 edited a comment on pull request #18300: Update H2 to 2.0.206 to address CVE-2021-42392.

Posted by GitBox <gi...@apache.org>.
deadwind4 edited a comment on pull request #18300:
URL: https://github.com/apache/flink/pull/18300#issuecomment-1007421253


   https://github.com/apache/flink/pull/18301 duplicated


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscribe@flink.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [flink] deadwind4 commented on pull request #18300: Update H2 to 2.0.206 to address CVE-2021-42392.

Posted by GitBox <gi...@apache.org>.
deadwind4 commented on pull request #18300:
URL: https://github.com/apache/flink/pull/18300#issuecomment-1007421253


   https://github.com/apache/flink/pull/18301


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscribe@flink.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [flink] Chromico commented on pull request #18300: Update H2 to 2.0.206 to address CVE-2021-42392.

Posted by GitBox <gi...@apache.org>.
Chromico commented on pull request #18300:
URL: https://github.com/apache/flink/pull/18300#issuecomment-1007489335


   Done :)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscribe@flink.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [flink] flinkbot commented on pull request #18300: Update H2 to 2.0.206 to address CVE-2021-42392.

Posted by GitBox <gi...@apache.org>.
flinkbot commented on pull request #18300:
URL: https://github.com/apache/flink/pull/18300#issuecomment-1007376984


   <!--
   Meta data
   {
     "version" : 1,
     "metaDataEntries" : [ {
       "hash" : "4dc5bd5f599164575c672f6726ba4af5847b6d0e",
       "status" : "UNKNOWN",
       "url" : "TBD",
       "triggerID" : "4dc5bd5f599164575c672f6726ba4af5847b6d0e",
       "triggerType" : "PUSH"
     } ]
   }-->
   ## CI report:
   
   * 4dc5bd5f599164575c672f6726ba4af5847b6d0e UNKNOWN
   
   <details>
   <summary>Bot commands</summary>
     The @flinkbot bot supports the following commands:
   
    - `@flinkbot run azure` re-run the last Azure build
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscribe@flink.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [flink] flinkbot commented on pull request #18300: Update H2 to 2.0.206 to address CVE-2021-42392.

Posted by GitBox <gi...@apache.org>.
flinkbot commented on pull request #18300:
URL: https://github.com/apache/flink/pull/18300#issuecomment-1007376585






-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscribe@flink.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [flink] deadwind4 commented on pull request #18300: Update H2 to 2.0.206 to address CVE-2021-42392.

Posted by GitBox <gi...@apache.org>.
deadwind4 commented on pull request #18300:
URL: https://github.com/apache/flink/pull/18300#issuecomment-1007421253


   https://github.com/apache/flink/pull/18301


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscribe@flink.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [flink] flinkbot commented on pull request #18300: Update H2 to 2.0.206 to address CVE-2021-42392.

Posted by GitBox <gi...@apache.org>.
flinkbot commented on pull request #18300:
URL: https://github.com/apache/flink/pull/18300#issuecomment-1007376585


   Thanks a lot for your contribution to the Apache Flink project. I'm the @flinkbot. I help the community
   to review your pull request. We will use this comment to track the progress of the review.
   
   
   ## Automated Checks
   Last check on commit 4dc5bd5f599164575c672f6726ba4af5847b6d0e (Fri Jan 07 12:39:38 UTC 2022)
   
   **Warnings:**
    * **1 pom.xml files were touched**: Check for build and licensing issues.
    * No documentation files were touched! Remember to keep the Flink docs up to date!
    * **Invalid pull request title: No valid Jira ID provided**
   
   
   <sub>Mention the bot in a comment to re-run the automated checks.</sub>
   ## Review Progress
   
   * ❓ 1. The [description] looks good.
   * ❓ 2. There is [consensus] that the contribution should go into to Flink.
   * ❓ 3. Needs [attention] from.
   * ❓ 4. The change fits into the overall [architecture].
   * ❓ 5. Overall code [quality] is good.
   
   Please see the [Pull Request Review Guide](https://flink.apache.org/contributing/reviewing-prs.html) for a full explanation of the review process.<details>
    The Bot is tracking the review progress through labels. Labels are applied according to the order of the review items. For consensus, approval by a Flink committer of PMC member is required <summary>Bot commands</summary>
     The @flinkbot bot supports the following commands:
   
    - `@flinkbot approve description` to approve one or more aspects (aspects: `description`, `consensus`, `architecture` and `quality`)
    - `@flinkbot approve all` to approve all aspects
    - `@flinkbot approve-until architecture` to approve everything until `architecture`
    - `@flinkbot attention @username1 [@username2 ..]` to require somebody's attention
    - `@flinkbot disapprove architecture` to remove an approval you gave earlier
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscribe@flink.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [flink] deadwind4 edited a comment on pull request #18300: Update H2 to 2.0.206 to address CVE-2021-42392.

Posted by GitBox <gi...@apache.org>.
deadwind4 edited a comment on pull request #18300:
URL: https://github.com/apache/flink/pull/18300#issuecomment-1007421253


   https://github.com/apache/flink/pull/18301 duplicated


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscribe@flink.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [flink] Chromico closed pull request #18300: Update H2 to 2.0.206 to address CVE-2021-42392.

Posted by GitBox <gi...@apache.org>.
Chromico closed pull request #18300:
URL: https://github.com/apache/flink/pull/18300


   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscribe@flink.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [flink] flinkbot edited a comment on pull request #18300: Update H2 to 2.0.206 to address CVE-2021-42392.

Posted by GitBox <gi...@apache.org>.
flinkbot edited a comment on pull request #18300:
URL: https://github.com/apache/flink/pull/18300#issuecomment-1007376984


   <!--
   Meta data
   {
     "version" : 1,
     "metaDataEntries" : [ {
       "hash" : "4dc5bd5f599164575c672f6726ba4af5847b6d0e",
       "status" : "PENDING",
       "url" : "https://dev.azure.com/apache-flink/98463496-1af2-4620-8eab-a2ecc1a2e6fe/_build/results?buildId=29104",
       "triggerID" : "4dc5bd5f599164575c672f6726ba4af5847b6d0e",
       "triggerType" : "PUSH"
     } ]
   }-->
   ## CI report:
   
   * 4dc5bd5f599164575c672f6726ba4af5847b6d0e Azure: [PENDING](https://dev.azure.com/apache-flink/98463496-1af2-4620-8eab-a2ecc1a2e6fe/_build/results?buildId=29104) 
   
   <details>
   <summary>Bot commands</summary>
     The @flinkbot bot supports the following commands:
   
    - `@flinkbot run azure` re-run the last Azure build
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscribe@flink.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [flink] Chromico commented on pull request #18300: Update H2 to 2.0.206 to address CVE-2021-42392.

Posted by GitBox <gi...@apache.org>.
Chromico commented on pull request #18300:
URL: https://github.com/apache/flink/pull/18300#issuecomment-1007489335


   Done :)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscribe@flink.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [flink] MartijnVisser commented on pull request #18300: Update H2 to 2.0.206 to address CVE-2021-42392.

Posted by GitBox <gi...@apache.org>.
MartijnVisser commented on pull request #18300:
URL: https://github.com/apache/flink/pull/18300#issuecomment-1007471404


   @Chromico Please close this PR as it's indeed a duplicate. Also, the vulnerability for Flink is not applicable since Flink only uses this dependency for testing purposes


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscribe@flink.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [flink] flinkbot edited a comment on pull request #18300: Update H2 to 2.0.206 to address CVE-2021-42392.

Posted by GitBox <gi...@apache.org>.
flinkbot edited a comment on pull request #18300:
URL: https://github.com/apache/flink/pull/18300#issuecomment-1007376984


   <!--
   Meta data
   {
     "version" : 1,
     "metaDataEntries" : [ {
       "hash" : "4dc5bd5f599164575c672f6726ba4af5847b6d0e",
       "status" : "FAILURE",
       "url" : "https://dev.azure.com/apache-flink/98463496-1af2-4620-8eab-a2ecc1a2e6fe/_build/results?buildId=29104",
       "triggerID" : "4dc5bd5f599164575c672f6726ba4af5847b6d0e",
       "triggerType" : "PUSH"
     } ]
   }-->
   ## CI report:
   
   * 4dc5bd5f599164575c672f6726ba4af5847b6d0e Azure: [FAILURE](https://dev.azure.com/apache-flink/98463496-1af2-4620-8eab-a2ecc1a2e6fe/_build/results?buildId=29104) 
   
   <details>
   <summary>Bot commands</summary>
     The @flinkbot bot supports the following commands:
   
    - `@flinkbot run azure` re-run the last Azure build
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscribe@flink.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [flink] MartijnVisser commented on pull request #18300: Update H2 to 2.0.206 to address CVE-2021-42392.

Posted by GitBox <gi...@apache.org>.
MartijnVisser commented on pull request #18300:
URL: https://github.com/apache/flink/pull/18300#issuecomment-1007471404


   @Chromico Please close this PR as it's indeed a duplicate. Also, the vulnerability for Flink is not applicable since Flink only uses this dependency for testing purposes


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscribe@flink.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [flink] Chromico closed pull request #18300: Update H2 to 2.0.206 to address CVE-2021-42392.

Posted by GitBox <gi...@apache.org>.
Chromico closed pull request #18300:
URL: https://github.com/apache/flink/pull/18300


   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscribe@flink.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [flink] flinkbot edited a comment on pull request #18300: Update H2 to 2.0.206 to address CVE-2021-42392.

Posted by GitBox <gi...@apache.org>.
flinkbot edited a comment on pull request #18300:
URL: https://github.com/apache/flink/pull/18300#issuecomment-1007376984






-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscribe@flink.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org