Re: Random String Parameter Plugin has several vulnerabilities

2022-09-07 Thread 'Daniel Beck' via Jenkins Developers
On Wed, Sep 7, 2022 at 2:11 PM Khachatur Ashotyan < khachatur.ashot...@gmail.com> wrote: > I'm not sure, that I want to adopt this plugin, …. I'm ready to maintain > this plugin. > Could you clarify what you mean, because these don't seem to go together? We call it "adoption" when someone starts

Re: Random String Parameter Plugin has several vulnerabilities

2022-09-07 Thread Mark Waite
On Wednesday, September 7, 2022 at 6:11:36 AM UTC-6 you wrote: > Hello! > > I'm not sure, that I want to adopt this plugin, but it is abandoned and > vulnerable as described here, so some administrator may merge this PR's. > I'm ready to maintain this plugin. > >

Re: Add a GitHub App to allow marking pull request dependant on another

2022-09-07 Thread 'Jesse Glick' via Jenkins Developers
On Wed, Sep 7, 2022 at 6:42 AM 'Herve Le Meur' via Jenkins Developers < jenkinsci-dev@googlegroups.com> wrote: > I think it could be useful on the jenkinsci and jenkins-infra GitHub > organizations, WDYT? > Sure, assuming it passes some sort of security review. As someone who frequently creates

Random String Parameter Plugin has several vulnerabilities

2022-09-07 Thread Khachatur Ashotyan
Hello! I'm not sure, that I want to adopt this plugin, but it is abandoned and vulnerable as described here, so some administrator may merge this PR's. I'm ready to maintain this plugin. https://www.jenkins.io/security/advisory/2022-05-17/#SECURITY-2717 - URL:

Add a GitHub App to allow marking pull request dependant on another

2022-09-07 Thread 'Herve Le Meur' via Jenkins Developers
Hello! I've stumbled upon this GitHub App: https://github.com/marketplace/dpulls > Dpulls allows you to specify dependencies between pull requests [by adding a comment] and creates a status check to make sure the PRs are merged in the right order See it in action in this gif:

Re: Jenkins 2.361.1 LTS RC testing started

2022-09-07 Thread Vincent Latombe
I'm sorry to bring bad news, but I found a critical issue affecting websockets agents -- https://issues.jenkins.io/browse/JENKINS-69543 Vincent Le dim. 4 sept. 2022 à 05:59, Kris Stern a écrit : > Hi all, > > A second backporting PR has been opened and merged at >