[jira] [Resolved] (JDO-821) Fix sonarcloud issues of type Bugs and Security Hotspots

2022-12-29 Thread Michael Bouschen (Jira)


 [ 
https://issues.apache.org/jira/browse/JDO-821?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Michael Bouschen resolved JDO-821.
--
Resolution: Fixed

The issues in the categories Reliability (= Bugs) and Security Review (= 
Security Hotspots) are fixed now.

> Fix sonarcloud issues of type Bugs and Security Hotspots
> 
>
> Key: JDO-821
> URL: https://issues.apache.org/jira/browse/JDO-821
> Project: JDO
>  Issue Type: Task
>  Components: api
>Affects Versions: JDO 3.2.1
>Reporter: Michael Bouschen
>Assignee: Michael Bouschen
>Priority: Major
> Fix For: JDO 3.3
>
>
> The latest sonarcloud run lists 20 bugs in the category Reliability.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)


Minutes: JDO TCK Conference Call Thursday December 29 1100 PST 2000 CET

2022-12-29 Thread Craig Russell
Attendees: Michael Bouschen, Tobias Bouschen, Craig Russell

Next meeting: Thursday January 5 1100 PST 2000 CET

Agenda:

1. Derby vulnerability
See https://issues.apache.org/jira/browse/DERBY-7147

This is a vulnerably without a known exploit. The only use of Derby in JDO is 
in the TCK tests. The Derby fix is not yet available, and will only be 
available for Java 17. So no action for JDO.

2. JIRA JDO-821: "Fix sonarcloud issues of type Bugs" 
https://issues.apache.org/jira/browse/JDO-821
JIRA JDO-819 "Code quality analysis" 
https://issues.apache.org/jira/browse/JDO-819

Just two issues left:
When catching an interrupt, the exception is "swallowed" by a RuntimeException. 
AI Michael: merge fix to main.
When printing stack traces, we synchronize on the output stream. Will not fix.

Other issues are SonarCloud "Code Smell" which should be looked at more 
closely.'
Whenever a collection of issues is going to be fixed, we should create a new 
JIRA and link it to "parent" JDO-819. Once we have reached "will not fix" for 
all remaining issues we can close JDO-819.

3. JIRA JDO-709 "Standardize field/property converters" 
https://issues.apache.org/jira/browse/JDO-709

No update. Waiting for DataNucleus and/or reporter.

4. JIRA JDO-822: "Verify compatibility with JDK 20" 
https://issues.apache.org/jira/browse/JDO-822

A volunteer can see if the TCK runs on JDK 20 but not high priority since JDO 
20 is not expected to be Long Term Support.

5. JIRA JDO-812 "Move to JDK 11 as the lowest supported version" 
https://issues.apache.org/jira/browse/JDO-812

6. Other issues

Action Items from weeks past:

[Nov 23 2022] AI Tilmann see what else is needed to have the analysis 
integrated into GitHub repo.
[Nov 23 2022] AI Tilmann follow up with Andy/DataNucleus for his advice on 
JDO-709.
[Oct 20 2022] AI Craig update the JIRA JDO-709 to request a test case using 
annotations and results of the test.
[Dec 09 2021] AI Craig: Try to contact all current/former participants in JDO 
development and see if and how they want to be recognized on the JDO and DB web 
sites.https://db.apache.org/whoweare.html
[Oct 07 2021] AI Craig send a private message to all JSR-243 Expert Group 
members asking if they wish to continue.
[Mar 25 2021] AI Craig: investigate "merging" papajdo and apache.clr accounts
[Oct 17 2014] AI Matthew any updates for "Modify specification to address NoSQL 
datastores" https://issues.apache.org/jira/browse/JDO-651

Regards Michael


Craig L Russell
c...@apache.org



[jira] [Updated] (JDO-821) Fix sonarcloud issues of type Bugs and Security Hotspots

2022-12-29 Thread Michael Bouschen (Jira)


 [ 
https://issues.apache.org/jira/browse/JDO-821?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Michael Bouschen updated JDO-821:
-
Summary: Fix sonarcloud issues of type Bugs and Security Hotspots  (was: 
Fix sonarcloud issues of type Bugs)

> Fix sonarcloud issues of type Bugs and Security Hotspots
> 
>
> Key: JDO-821
> URL: https://issues.apache.org/jira/browse/JDO-821
> Project: JDO
>  Issue Type: Task
>  Components: api
>Affects Versions: JDO 3.2.1
>Reporter: Michael Bouschen
>Assignee: Michael Bouschen
>Priority: Major
> Fix For: JDO 3.3
>
>
> The latest sonarcloud run lists 20 bugs in the category Reliability.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)