Re: Question regarding transitive plugin dependencies and security advisories

2022-01-26 Thread James Nord
Hi Adam You don't have to do anything. Mostly as a security release of a plugin should not break API compatability. If someone installs your plugin then Jenkins will if the mailer plugin is not installed install the latest from the update center that it knows about You can choose to update

Question regarding transitive plugin dependencies and security advisories

2022-01-26 Thread Adam Kaplan
Hi all, January's security advisory had several vulnerabilities disclosed in plugins [1]. Some of these plugins are widely used and may be used as dependencies in other plugins. For example, my team maintains the openshift-login-plugin and we depend on Mailer, which was recently updated with a

Re: Question regarding transitive plugin dependencies and security advisories

2022-01-26 Thread Adam Kaplan
Thanks, James. For the login plugin we have a pinned dependency in our pom.xml, so we plan on updating that so folks get a fixed version of Mailer if that isn't present on their Jenkins instance. We also have a downstream distribution which pulls in 3rd party plugins, like blueocean. We noticed

Re: Dropping support for IE 11

2022-01-26 Thread Mark Waite
Was discussed in governance meeting today and agreed that we should proceed. On Wednesday, January 26, 2022 at 1:17:51 PM UTC-7 timja...@gmail.com wrote: > PR raised, > see https://github.com/jenkins-infra/jenkins.io/pull/4827 > > and preview: > >

Re: Jenkins 2.319.3 LTS RC testing started

2022-01-26 Thread 'Jesse Glick' via Jenkins Developers
On Wed, Jan 26, 2022 at 4:06 AM 'Ildefonso Montero' via Jenkins Developers < jenkinsci-dev@googlegroups.com> wrote: > Download the release from > https://repo.jenkins-ci.org/artifactory/snapshots/org/jenkins-ci/main/jenkins-war/2.319.3-SNAPSHOT/jenkins-war-2.319.3-20220126.084922-1.war > Maybe

Re: Jenkins 2.319.3 LTS RC testing started

2022-01-26 Thread Tim Jacomb
Looks like an issue with form element path not working on LTS line. It could be fixed, but: 1. there was only one (trivial) fix backported: https://github.com/jenkinsci/jenkins/pull/6187 2. Those tests are passing against latest weekly, there's just one plugin currently failing on which:

Governance meeting Jan 26, 2022

2022-01-26 Thread Mark Waite
Today's governance meeting will start at 9:00 PM UTC. Agenda items include: - News - LTS baseline selected - Jenkins plugin development environment setup webinar - Recording at https://youtu.be/u3eCEw6l8t0 - Jenkins UI improvements from UX SIG - Recording

Re: Dropping support for IE 11

2022-01-26 Thread timja...@gmail.com
PR raised, see https://github.com/jenkins-infra/jenkins.io/pull/4827 and preview: https://deploy-preview-4827--jenkins-io-site-pr.netlify.app/doc/administration/requirements/web-browsers/ On Friday, 21 January 2022 at 09:15:02 UTC jn...@cloudbees.com wrote: > The only issue I would have in

Jenkins 2.319.3 LTS RC testing started

2022-01-26 Thread 'Ildefonso Montero' via Jenkins Developers
Hello everyone, Latest LTS RC was made public and it is ready to be tested. The final release is scheduled for 2022-02-09. Please, report your findings in this thread. Download the release from

Re: 2.319.3 release lead

2022-01-26 Thread 'Ildefonso Montero' via Jenkins Developers
Hi all, just to inform you I'm back :-) Reviewing current status on https://github.com/jenkins-infra/release/issues/209 and planning to perform the RC creation today Best, Ildefonso On Wed, Jan 19, 2022 at 10:17 AM Ildefonso Montero wrote: > Hi, I got positive in COVID today, just to inform