See <https://ci-builds.apache.org/job/Struts/job/Struts-master-dependency-check/213/display/redirect?page=changes>
Changes: [github] Bump org.apache.maven.plugins:maven-failsafe-plugin from 3.2.5 to 3.3.0 [stefansielaff] "Swap order of sysStrSubstitutor and envStrSubstitutor in substitute method" [github] Bump actions/upload-artifact from 4.3.3 to 4.3.4 [git] WW-5428 Allowlist capability should resolve Hibernate proxies when disableProxyObjects is not set [git] WW-5428 Clean up SecurityMemberAccessProxyTest [git] WW-5428 Add unit test coverage for Hibernate proxy resolution [git] WW-5428 Add log warning for Hibernate entities [git] WW-5428 Add log warning for allowlist disabled [git] WW-5428 Amend log warning for missing allowlist entry [git] WW-5439 Move Dev Mode security configuration [git] WW-5428 Stop excessive logging in DevMode [Lukasz Lenart] [maven-release-plugin] prepare release STRUTS_6_5_0 [Lukasz Lenart] [maven-release-plugin] prepare for next development iteration [git] WW-5441 Bump net.sf.jasperreports:jasperreports to 6.21.3 [git] WW-5440 Deprecate AnnotationParameterFilterInterceptor [git] WW-5440 Fix MultipleFileUploadUsingArrayAction [git] WW-5440 Add missing annotations [git] WW-5440 Fix Showcase App allowlist configuration [git] WW-5428 Stop further excessive logging in DevMode [git] WW-5440 Fix OGNL allowlist compat with Convention plugin [git] WW-5440 Fix inconsistent indenting [git] WW-5442 Enforce allowlist for OgnlReflectionProvider [git] WW-5443 Bump Spring dependencies to 5.3.37 [github] Bump jackson.version from 2.17.1 to 2.17.2 [github] Bump maven-surefire-plugin.version from 3.2.5 to 3.3.1 [Lukasz Lenart] [maven-release-plugin] prepare release STRUTS_6_6_0 [Lukasz Lenart] [maven-release-plugin] prepare for next development iteration ------------------------------------------ Started by timer Running as SYSTEM [EnvInject] - Loading node environment variables. Building remotely on builds24 (ubuntu) in workspace <https://ci-builds.apache.org/job/Struts/job/Struts-master-dependency-check/ws/> The recommended git tool is: NONE No credentials specified > git rev-parse --resolve-git-dir > <https://ci-builds.apache.org/job/Struts/job/Struts-master-dependency-check/ws/.git> > # timeout=10 Fetching changes from the remote Git repository > git config remote.origin.url https://gitbox.apache.org/repos/asf/struts.git > # timeout=10 Fetching upstream changes from https://gitbox.apache.org/repos/asf/struts.git > git --version # timeout=10 > git --version # 'git version 2.34.1' > git fetch --tags --force --progress -- > https://gitbox.apache.org/repos/asf/struts.git > +refs/heads/*:refs/remotes/origin/* # timeout=10 > git rev-parse refs/remotes/origin/master^{commit} # timeout=10 Checking out Revision f977f0c0e5c69f8d95b897fcf012cb8ba204d938 (refs/remotes/origin/master) > git config core.sparsecheckout # timeout=10 > git checkout -f f977f0c0e5c69f8d95b897fcf012cb8ba204d938 # timeout=10 Commit message: "[maven-release-plugin] prepare for next development iteration" > git rev-list --no-walk 8b22f7170ff41e1f2e948e229a78f74a2f455408 # timeout=10 ERROR: No tool found matching MAVEN_3_LATEST__HOME Setting MAVEN_3_LATEST_HOME=/home/jenkins/tools/maven/latest3 [Struts-master-dependency-check] $ /bin/sh -xe /tmp/jenkins8547016605550237668.sh + export MAVEN_OPTS=-Xms2g -Xmx2g + /home/jenkins/tools/maven/latest3/bin/mvn verify -Pdependency-check [INFO] Scanning for projects... [INFO] ------------------------------------------------------------------------ [INFO] Reactor Build Order: [INFO] [INFO] Struts 2 [pom] [INFO] Struts 2 Bill of Materials [pom] [INFO] Struts 2 Core [jar] [INFO] Struts 2 Plugins [pom] [INFO] Struts 2 Async Plugin [jar] [INFO] Struts 2 Bean Validation Plugin [jar] [INFO] Struts 2 CDI Plugin [jar] [INFO] Struts 2 Spring Plugin [jar] [INFO] Struts 2 JUnit Plugin [jar] [INFO] Struts 2 Velocity Plugin [jar] [INFO] Struts 2 Configuration Browser Plugin [jar] [INFO] Struts 2 Convention Plugin [jar] [INFO] Struts 2 DWR Plugin [jar] [INFO] DEPRECATED: Struts 2 Embedded JSP Plugin, since 6.0.0 [jar] [INFO] DEPRECATED: Struts 2 GXP Plugin - since 6.0.0 [jar] [INFO] Struts 2 Jasper Reports Plugin [jar] [INFO] Struts 2 Java Templates Plugin [jar] [INFO] Struts 2 JFreeChart Plugin [jar] [INFO] Struts 2 JSON Plugin [jar] [INFO] DEPRECATED: Struts 2 OSGi Plugin - since 6.0.0 [jar] [INFO] DEPRECATED: Struts 2 OVal Plugin, since 6.0.0 [jar] [INFO] DEPRECATED: Struts 2 Pell Multipart Plugin - since 6.2.0 [jar] [INFO] DEPRECATED: Struts 2 Plexus Plugin - since 6.0.0 [jar] [INFO] DEPRECATED: Struts 2 Portlet Mocks Plugin - since 6.0.0 [jar] [INFO] DEPRECATED: Struts 2 Portlet Plugin - since 6.0.0 [jar] [INFO] DEPRECATED: Struts 2 Portlet JUnit Plugin - since 6.3.0 [jar] [INFO] Struts 2 Tiles Plugin [jar] [INFO] DEPRECATED: Struts 2 Portlet Tiles Plugin - since 6.0.0 [jar] [INFO] Struts 2 REST Plugin [jar] [INFO] Struts 2 Sitemesh Plugin [jar] [INFO] Struts 2 TestNG Plugin [jar] [INFO] Struts 2 XSLT Plugin [jar] [INFO] DEPRECATED: Struts 2 OSGi Bundles - since 6.0.0 [pom] [INFO] DEPRECATED: Struts 2 OSGi Admin Bundle - since 6.0.0 [bundle] [INFO] DEPRECATED: Struts 2 OSGi Demo Bundle - since 6.0.0 [bundle] [INFO] Struts 2 Webapps [pom] [INFO] Struts 2 Showcase Webapp [war] [INFO] Struts 2 Rest Showcase Webapp [war] [INFO] Struts 2 Assembly [pom] [INFO] [INFO] ------------------< org.apache.struts:struts2-parent >------------------ [INFO] Building Struts 2 6.7.0-SNAPSHOT [1/39] [INFO] from pom.xml [INFO] --------------------------------[ pom ]--------------------------------- [INFO] [INFO] --- enforcer:3.5.0:enforce (enforce) @ struts2-parent --- [INFO] Rule 0: org.apache.maven.enforcer.rules.dependency.DependencyConvergence passed [INFO] [INFO] --- enforcer:3.5.0:enforce (enforce-maven-version) @ struts2-parent --- [INFO] Rule 0: org.apache.maven.enforcer.rules.version.RequireMavenVersion passed [INFO] [INFO] --- enforcer:3.5.0:enforce (enforce-java-version) @ struts2-parent --- [INFO] Rule 0: org.apache.maven.enforcer.rules.version.RequireJavaVersion passed [INFO] [INFO] --- remote-resources:3.1.0:process (process-resource-bundles) @ struts2-parent --- [INFO] Preparing remote bundle org.apache.apache.resources:apache-jar-resource-bundle:1.5 [INFO] Copying 3 resources from 1 bundle. [INFO] [INFO] --- bundle:5.1.9:manifest (bundle-manifest) @ struts2-parent --- [WARNING] Ignoring project type pom - supportedProjectTypes = [jar, bundle] [INFO] [INFO] --- apache-rat:0.15:check (default) @ struts2-parent --- [INFO] Added 1 additional default licenses. [INFO] Added 1 custom approved licenses. [INFO] Will parse SCM ignores for exclusions... [INFO] Parsing exclusions from <https://ci-builds.apache.org/job/Struts/job/Struts-master-dependency-check/ws/.gitignore> [INFO] Finished adding exclusions from SCM ignore files. [INFO] 89 implicit excludes. [INFO] 17 explicit excludes. [INFO] 3 resources included [INFO] Rat check: Summary over all files. Unapproved: 0, unknown: 0, generated: 0, approved: 3 licenses. [INFO] [INFO] --- site:3.12.1:attach-descriptor (attach-descriptor) @ struts2-parent --- [INFO] Attaching 'src/site/site.xml' site descriptor with classifier 'site'. [INFO] [INFO] --- dependency-check:9.2.0:check (default) @ struts2-parent --- [INFO] Checking for updates [WARNING] An NVD API Key was not provided - it is highly recommended to use an NVD API key as the update can take a VERY long time without an API Key [WARNING] NVD API request failures are occurring; retrying request for the 5 time [WARNING] NVD API request failures are occurring; retrying request for the 6 time [ERROR] Error updating the NVD Data; the NVD returned a 403 or 404 error Consider using an NVD API Key; see https://github.com/jeremylong/DependencyCheck?tab=readme-ov-file#nvd-api-key-highly-recommended org.owasp.dependencycheck.data.update.exception.UpdateException: Error updating the NVD Data; the NVD returned a 403 or 404 error Consider using an NVD API Key; see https://github.com/jeremylong/DependencyCheck?tab=readme-ov-file#nvd-api-key-highly-recommended at org.owasp.dependencycheck.data.update.NvdApiDataSource.processApi (NvdApiDataSource.java:387) at org.owasp.dependencycheck.data.update.NvdApiDataSource.update (NvdApiDataSource.java:116) at org.owasp.dependencycheck.Engine.doUpdates (Engine.java:906) at org.owasp.dependencycheck.Engine.initializeAndUpdateDatabase (Engine.java:711) at org.owasp.dependencycheck.Engine.analyzeDependencies (Engine.java:637) at org.owasp.dependencycheck.maven.BaseDependencyCheckMojo.runCheck (BaseDependencyCheckMojo.java:1960) at org.owasp.dependencycheck.maven.BaseDependencyCheckMojo.execute (BaseDependencyCheckMojo.java:1143) at org.apache.maven.plugin.DefaultBuildPluginManager.executeMojo (DefaultBuildPluginManager.java:126) at org.apache.maven.lifecycle.internal.MojoExecutor.doExecute2 (MojoExecutor.java:328) at org.apache.maven.lifecycle.internal.MojoExecutor.doExecute (MojoExecutor.java:316) at org.apache.maven.lifecycle.internal.MojoExecutor.execute (MojoExecutor.java:212) at org.apache.maven.lifecycle.internal.MojoExecutor.execute (MojoExecutor.java:174) at org.apache.maven.lifecycle.internal.MojoExecutor.access$000 (MojoExecutor.java:75) at org.apache.maven.lifecycle.internal.MojoExecutor$1.run (MojoExecutor.java:162) at org.apache.maven.plugin.DefaultMojosExecutionStrategy.execute (DefaultMojosExecutionStrategy.java:39) at org.apache.maven.lifecycle.internal.MojoExecutor.execute (MojoExecutor.java:159) at org.apache.maven.lifecycle.internal.LifecycleModuleBuilder.buildProject (LifecycleModuleBuilder.java:105) at org.apache.maven.lifecycle.internal.LifecycleModuleBuilder.buildProject (LifecycleModuleBuilder.java:73) at org.apache.maven.lifecycle.internal.builder.singlethreaded.SingleThreadedBuilder.build (SingleThreadedBuilder.java:53) at org.apache.maven.lifecycle.internal.LifecycleStarter.execute (LifecycleStarter.java:118) at org.apache.maven.DefaultMaven.doExecute (DefaultMaven.java:261) at org.apache.maven.DefaultMaven.doExecute (DefaultMaven.java:173) at org.apache.maven.DefaultMaven.execute (DefaultMaven.java:101) at org.apache.maven.cli.MavenCli.execute (MavenCli.java:906) at org.apache.maven.cli.MavenCli.doMain (MavenCli.java:283) at org.apache.maven.cli.MavenCli.main (MavenCli.java:206) at sun.reflect.NativeMethodAccessorImpl.invoke0 (Native Method) at sun.reflect.NativeMethodAccessorImpl.invoke (NativeMethodAccessorImpl.java:62) at sun.reflect.DelegatingMethodAccessorImpl.invoke (DelegatingMethodAccessorImpl.java:43) at java.lang.reflect.Method.invoke (Method.java:498) at org.codehaus.plexus.classworlds.launcher.Launcher.launchEnhanced (Launcher.java:283) at org.codehaus.plexus.classworlds.launcher.Launcher.launch (Launcher.java:226) at org.codehaus.plexus.classworlds.launcher.Launcher.mainWithExitCode (Launcher.java:407) at org.codehaus.plexus.classworlds.launcher.Launcher.main (Launcher.java:348) [INFO] Skipping Known Exploited Vulnerabilities update check since last check was within 24 hours. [WARNING] Unable to update 1 or more Cached Web DataSource, using local data instead. Results may not include recent vulnerabilities. [ERROR] Unable to continue dependency-check analysis. [INFO] ------------------------------------------------------------------------ [INFO] Reactor Summary for Struts 2 6.7.0-SNAPSHOT: [INFO] [INFO] Struts 2 ........................................... FAILURE [ 10.343 s] [INFO] Struts 2 Bill of Materials ......................... SKIPPED [INFO] Struts 2 Core ...................................... SKIPPED [INFO] Struts 2 Plugins ................................... SKIPPED [INFO] Struts 2 Async Plugin .............................. SKIPPED [INFO] Struts 2 Bean Validation Plugin .................... SKIPPED [INFO] Struts 2 CDI Plugin ................................ SKIPPED [INFO] Struts 2 Spring Plugin ............................. SKIPPED [INFO] Struts 2 JUnit Plugin .............................. SKIPPED [INFO] Struts 2 Velocity Plugin ........................... SKIPPED [INFO] Struts 2 Configuration Browser Plugin .............. SKIPPED [INFO] Struts 2 Convention Plugin ......................... SKIPPED [INFO] Struts 2 DWR Plugin ................................ SKIPPED [INFO] DEPRECATED: Struts 2 Embedded JSP Plugin, since 6.0.0 SKIPPED [INFO] DEPRECATED: Struts 2 GXP Plugin - since 6.0.0 ...... SKIPPED [INFO] Struts 2 Jasper Reports Plugin ..................... SKIPPED [INFO] Struts 2 Java Templates Plugin ..................... SKIPPED [INFO] Struts 2 JFreeChart Plugin ......................... SKIPPED [INFO] Struts 2 JSON Plugin ............................... SKIPPED [INFO] DEPRECATED: Struts 2 OSGi Plugin - since 6.0.0 ..... SKIPPED [INFO] DEPRECATED: Struts 2 OVal Plugin, since 6.0.0 ...... SKIPPED [INFO] DEPRECATED: Struts 2 Pell Multipart Plugin - since 6.2.0 SKIPPED [INFO] DEPRECATED: Struts 2 Plexus Plugin - since 6.0.0 ... SKIPPED [INFO] DEPRECATED: Struts 2 Portlet Mocks Plugin - since 6.0.0 SKIPPED [INFO] DEPRECATED: Struts 2 Portlet Plugin - since 6.0.0 .. SKIPPED [INFO] DEPRECATED: Struts 2 Portlet JUnit Plugin - since 6.3.0 SKIPPED [INFO] Struts 2 Tiles Plugin .............................. SKIPPED [INFO] DEPRECATED: Struts 2 Portlet Tiles Plugin - since 6.0.0 SKIPPED [INFO] Struts 2 REST Plugin ............................... SKIPPED [INFO] Struts 2 Sitemesh Plugin ........................... SKIPPED [INFO] Struts 2 TestNG Plugin ............................. SKIPPED [INFO] Struts 2 XSLT Plugin ............................... SKIPPED [INFO] DEPRECATED: Struts 2 OSGi Bundles - since 6.0.0 .... SKIPPED [INFO] DEPRECATED: Struts 2 OSGi Admin Bundle - since 6.0.0 SKIPPED [INFO] DEPRECATED: Struts 2 OSGi Demo Bundle - since 6.0.0 SKIPPED [INFO] Struts 2 Webapps ................................... SKIPPED [INFO] Struts 2 Showcase Webapp ........................... SKIPPED [INFO] Struts 2 Rest Showcase Webapp ...................... SKIPPED [INFO] Struts 2 Assembly .................................. SKIPPED [INFO] ------------------------------------------------------------------------ [INFO] BUILD FAILURE [INFO] ------------------------------------------------------------------------ [INFO] Total time: 12.174 s [INFO] Finished at: 2024-07-22T06:39:25Z [INFO] ------------------------------------------------------------------------ [ERROR] Failed to execute goal org.owasp:dependency-check-maven:9.2.0:check (default) on project struts2-parent: Fatal exception(s) analyzing Struts 2: One or more exceptions occurred during analysis: [ERROR] UpdateException: Error updating the NVD Data; the NVD returned a 403 or 404 error [ERROR] [ERROR] Consider using an NVD API Key; see https://github.com/jeremylong/DependencyCheck?tab=readme-ov-file#nvd-api-key-highly-recommended [ERROR] NoDataException: No documents exist [ERROR] -> [Help 1] [ERROR] [ERROR] To see the full stack trace of the errors, re-run Maven with the -e switch. [ERROR] Re-run Maven using the -X switch to enable full debug logging. [ERROR] [ERROR] For more information about the errors and possible solutions, please read the following articles: [ERROR] [Help 1] http://cwiki.apache.org/confluence/display/MAVEN/MojoExecutionException Build step 'Execute shell' marked build as failure ERROR: No tool found matching MAVEN_3_LATEST__HOME Setting MAVEN_3_LATEST_HOME=/home/jenkins/tools/maven/latest3
