[JIRA] (JENKINS-49586) JDepend plugin classes not in JEP-200 whitelist
Title: Message Title Oleg Nenashev commented on JENKINS-49586 Re: JDepend plugin classes not in JEP-200 whitelist you are welcome Add Comment This message was sent by Atlassian JIRA (v7.3.0#73011-sha1:3c73d0e) -- You received this message because you are subscribed to the Google Groups "Jenkins Issues" group. To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-issues+unsubscr...@googlegroups.com. For more options, visit https://groups.google.com/d/optout.
[JIRA] (JENKINS-49586) JDepend plugin classes not in JEP-200 whitelist
Title: Message Title Chuck Burgess commented on JENKINS-49586 Re: JDepend plugin classes not in JEP-200 whitelist 1.3.0 seems to have fixed it for me... thanks Oleg Nenashev ! Add Comment This message was sent by Atlassian JIRA (v7.3.0#73011-sha1:3c73d0e) -- You received this message because you are subscribed to the Google Groups "Jenkins Issues" group. To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-issues+unsubscr...@googlegroups.com. For more options, visit https://groups.google.com/d/optout.
[JIRA] (JENKINS-49586) JDepend plugin classes not in JEP-200 whitelist
Title: Message Title Oleg Nenashev updated JENKINS-49586 The fix has been released in 1.3.0. Note that the release also includes this commit: https://github.com/jenkinsci/jdepend-plugin/commit/0c8fbfa25f1dac94b1df242578b12da2cd4ac7ec . If it causes any issues, raise the flag Jenkins / JENKINS-49586 JDepend plugin classes not in JEP-200 whitelist Change By: Oleg Nenashev Status: In Review Resolved Resolution: Fixed Add Comment This message was sent by Atlassian JIRA (v7.3.0#73011-sha1:3c73d0e) -- You received this message because you are subscribed to the Google Groups "Jenkins Issues" group. To
[JIRA] (JENKINS-49586) JDepend plugin classes not in JEP-200 whitelist
Title: Message Title SCM/JIRA link daemon commented on JENKINS-49586 Re: JDepend plugin classes not in JEP-200 whitelist Code changed in jenkins User: Oleg Nenashev Path: Jenkinsfile pom.xml src/main/java/hudson/plugins/jdepend/JDependBuildAction.java src/main/java/hudson/plugins/jdepend/JDependParser.java src/main/java/hudson/plugins/jdepend/JDependRecorder.java src/main/resources/hudson/plugins/jdepend/JDependBuildAction/index.jelly src/main/resources/hudson/plugins/jdepend/JDependProjectAction/index.jelly src/main/resources/hudson/plugins/jdepend/JDependRecorder/config.jelly src/main/resources/index.jelly http://jenkins-ci.org/commit/jdepend-plugin/afcf6bfd27770e813c279927c6020c1fc8f1e071 Log: Merge pull request #2 from oleg-nenashev/JENKINS-49586 JENKINS-49586 - Stop Serializing JDependParser to the disk (JEP-200 in 2.102+) Compare: https://github.com/jenkinsci/jdepend-plugin/compare/0c8fbfa25f1d...afcf6bfd2777 Add Comment This message was sent by Atlassian JIRA (v7.3.0#73011-sha1:3c73d0e) -- You received this message because you are subscribed to the Google Groups "Jenkins Issues" group. To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-issues+unsubscr...@googlegroups.com. For more options, visit https://groups.google.com/d/optout.
[JIRA] (JENKINS-49586) JDepend plugin classes not in JEP-200 whitelist
Title: Message Title SCM/JIRA link daemon commented on JENKINS-49586 Re: JDepend plugin classes not in JEP-200 whitelist Code changed in jenkins User: Oleg Nenashev Path: Jenkinsfile pom.xml http://jenkins-ci.org/commit/jdepend-plugin/a8c8e300b287d946e45c058f0f1b71116e4a200b Log: JENKINS-49586 - Add Jenkinsfile and resolve upper bounds for 2.104 Add Comment This message was sent by Atlassian JIRA (v7.3.0#73011-sha1:3c73d0e) -- You received this message because you are subscribed to the Google Groups "Jenkins Issues" group. To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-issues+unsubscr...@googlegroups.com. For more options, visit https://groups.google.com/d/optout.
[JIRA] (JENKINS-49586) JDepend plugin classes not in JEP-200 whitelist
Title: Message Title SCM/JIRA link daemon commented on JENKINS-49586 Re: JDepend plugin classes not in JEP-200 whitelist Code changed in jenkins User: Oleg Nenashev Path: src/main/java/hudson/plugins/jdepend/JDependBuildAction.java src/main/java/hudson/plugins/jdepend/JDependRecorder.java src/main/resources/hudson/plugins/jdepend/JDependBuildAction/index.jelly http://jenkins-ci.org/commit/jdepend-plugin/54a2c37429dc934055eb563c8e6e416459047835 Log: JENKINS-49586 - Stop serializing JDependParser to the disk Add Comment This message was sent by Atlassian JIRA (v7.3.0#73011-sha1:3c73d0e) -- You received this message because you are subscribed to the Google Groups "Jenkins Issues" group. To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-issues+unsubscr...@googlegroups.com. For more options, visit https://groups.google.com/d/optout.
[JIRA] (JENKINS-49586) JDepend plugin classes not in JEP-200 whitelist
Title: Message Title SCM/JIRA link daemon commented on JENKINS-49586 Re: JDepend plugin classes not in JEP-200 whitelist Code changed in jenkins User: Oleg Nenashev Path: pom.xml src/main/java/hudson/plugins/jdepend/JDependBuildAction.java src/main/java/hudson/plugins/jdepend/JDependParser.java src/main/resources/hudson/plugins/jdepend/JDependBuildAction/index.jelly src/main/resources/hudson/plugins/jdepend/JDependProjectAction/index.jelly src/main/resources/hudson/plugins/jdepend/JDependRecorder/config.jelly src/main/resources/index.jelly http://jenkins-ci.org/commit/jdepend-plugin/baad82043487526f1925e16bf416355d33213c10 Log: JENKINS-49586 - Update Parent POM and resolve reported issues Add Comment This message was sent by Atlassian JIRA (v7.3.0#73011-sha1:3c73d0e) -- You received this message because you are subscribed to the Google Groups "Jenkins Issues" group. To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-issues+unsubscr...@googlegroups.com. For more options, visit https://groups.google.com/d/optout.
[JIRA] (JENKINS-49586) JDepend plugin classes not in JEP-200 whitelist
Title: Message Title Oleg Nenashev commented on JENKINS-49586 Re: JDepend plugin classes not in JEP-200 whitelist 1) Download https://ci.jenkins.io/job/Plugins/job/jdepend-plugin/job/PR-2/1/artifact/target/jdepend.hpi 2) Go to Plugin Manager / Advanced tab 3) Find the "Upload a plugin" control, specify the downloaded file 4) After the plugin is installed, restart the instance Add Comment This message was sent by Atlassian JIRA (v7.3.0#73011-sha1:3c73d0e) -- You received this message because you are subscribed to the Google Groups "Jenkins Issues" group. To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-issues+unsubscr...@googlegroups.com. For more options, visit https://groups.google.com/d/optout.
[JIRA] (JENKINS-49586) JDepend plugin classes not in JEP-200 whitelist
Title: Message Title Chuck Burgess commented on JENKINS-49586 Re: JDepend plugin classes not in JEP-200 whitelist Not sure that I could test the snapshot... are there instructions somewhere about pulling a plugin snapshot into a Jenkins instance that would normally only see releases available? Add Comment This message was sent by Atlassian JIRA (v7.3.0#73011-sha1:3c73d0e) -- You received this message because you are subscribed to the Google Groups "Jenkins Issues" group. To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-issues+unsubscr...@googlegroups.com. For more options, visit https://groups.google.com/d/optout.
[JIRA] (JENKINS-49586) JDepend plugin classes not in JEP-200 whitelist
Title: Message Title Oleg Nenashev commented on JENKINS-49586 Re: JDepend plugin classes not in JEP-200 whitelist Created https://github.com/jenkinsci/jdepend-plugin/pull/2. Would it be possible to test the snapshot? Add Comment This message was sent by Atlassian JIRA (v7.3.0#73011-sha1:3c73d0e) -- You received this message because you are subscribed to the Google Groups "Jenkins Issues" group. To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-issues+unsubscr...@googlegroups.com. For more options, visit https://groups.google.com/d/optout.
[JIRA] (JENKINS-49586) JDepend plugin classes not in JEP-200 whitelist
Title: Message Title Oleg Nenashev updated JENKINS-49586 Jenkins / JENKINS-49586 JDepend plugin classes not in JEP-200 whitelist Change By: Oleg Nenashev Status: In Progress Review Add Comment This message was sent by Atlassian JIRA (v7.3.0#73011-sha1:3c73d0e) -- You received this message because you are subscribed to the Google Groups "Jenkins Issues" group. To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-issues+unsubscr...@googlegroups.com. For more options, visit https://groups.google.com/d/optout.
[JIRA] (JENKINS-49586) JDepend plugin classes not in JEP-200 whitelist
Title: Message Title Oleg Nenashev assigned an issue to Oleg Nenashev Jenkins / JENKINS-49586 JDepend plugin classes not in JEP-200 whitelist Change By: Oleg Nenashev Assignee: Oleg Nenashev Add Comment This message was sent by Atlassian JIRA (v7.3.0#73011-sha1:3c73d0e) -- You received this message because you are subscribed to the Google Groups "Jenkins Issues" group. To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-issues+unsubscr...@googlegroups.com. For more options, visit https://groups.google.com/d/optout.
[JIRA] (JENKINS-49586) JDepend plugin classes not in JEP-200 whitelist
Title: Message Title Oleg Nenashev started work on JENKINS-49586 Change By: Oleg Nenashev Status: Open In Progress Add Comment This message was sent by Atlassian JIRA (v7.3.0#73011-sha1:3c73d0e) -- You received this message because you are subscribed to the Google Groups "Jenkins Issues" group. To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-issues+unsubscr...@googlegroups.com. For more options, visit https://groups.google.com/d/optout.
[JIRA] (JENKINS-49586) JDepend plugin classes not in JEP-200 whitelist
Title: Message Title Oleg Nenashev commented on JENKINS-49586 Re: JDepend plugin classes not in JEP-200 whitelist It comes from this dependency: org.codehaus.mojo jdepend-maven-plugin 2.0-beta-2 The code is not on GitHub AFAICT. CC Arnaud Héritier Stephen Connolly. Likely does not matter, because the plugin should not persist the parser on the disk: https://github.com/jenkinsci/jdepend-plugin/blob/master/src/main/java/hudson/plugins/jdepend/JDependBuildAction.java#L23-L36 From what I see in the code, the logic can be safely replaced by a transient field Add Comment This message was sent by Atlassian JIRA (v7.3.0#73011-sha1:3c73d0e) -- You received this message because you are subscribed to the Google Groups "Jenkins Issues" group. To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-issues+unsubscr...@googlegroups.com. For more options, visit https://groups.google.com/d/optout.
[JIRA] (JENKINS-49586) JDepend plugin classes not in JEP-200 whitelist
Title: Message Title Chuck Burgess commented on JENKINS-49586 Re: JDepend plugin classes not in JEP-200 whitelist JDepend plugin affected by JEP-200 Add Comment This message was sent by Atlassian JIRA (v7.3.0#73011-sha1:3c73d0e) -- You received this message because you are subscribed to the Google Groups "Jenkins Issues" group. To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-issues+unsubscr...@googlegroups.com. For more options, visit https://groups.google.com/d/optout.
[JIRA] (JENKINS-49586) JDepend plugin classes not in JEP-200 whitelist
Title: Message Title Chuck Burgess updated an issue Jenkins / JENKINS-49586 JDepend plugin classes not in JEP-200 whitelist Change By: Chuck Burgess Labels: JEP-200 Add Comment This message was sent by Atlassian JIRA (v7.3.0#73011-sha1:3c73d0e) -- You received this message because you are subscribed to the Google Groups "Jenkins Issues" group. To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-issues+unsubscr...@googlegroups.com. For more options, visit https://groups.google.com/d/optout.
[JIRA] (JENKINS-49586) JDepend plugin classes not in JEP-200 whitelist
Title: Message Title Chuck Burgess created an issue Jenkins / JENKINS-49586 JDepend plugin classes not in JEP-200 whitelist Issue Type: Bug Assignee: Unassigned Components: jdepend-plugin Created: 2018-02-15 17:39 Priority: Minor Reporter: Chuck Burgess From what I'm reading about JEP-200, it seems that the (old) JDepend plugin's classes might not have been included in the whitelisting. WARNING: org.codehaus.mojo.jdepend.objects.JDPackage in file:/var/lib/jenkins/plugins/jdepend/WEB-INF/lib/jdepend-maven-plugin-2.0-beta-2.jar might be dangerous, so rejecting; see https://jenkins.io/redirect/class-filter/ ... org.codehaus.mojo.jdepend.objects.JDPackage in file:/var/lib/jenkins/plugins/jdepend/WEB-INF/lib/jdepend-maven-plugin-2.0-beta-2.jar might be dangerous, so rejecting; see https://jenkins.io/redirect/class-filter/ Feb 15, 2018 11:20:35 AM SEVERE hudson.model.Run execute Failed to save build record java.lang.UnsupportedOperationException: Refusing to marshal org.codehaus.mojo.jdepend.objects.JDPackage for security reasons; see https://jenkins.io/redirect/class-filter/ at hudson.util.XStream2$BlacklistedTypesConverter.marshal(XStream2.java:543) at com.thoughtworks.xstream.core.AbstractReferenceMarshaller.convert(AbstractReferenceMarshaller.java:69) at com.thoughtworks.xstream.core.TreeMarshaller.convertAnother(TreeMarshaller.java:58) at com.thoughtworks.xstream.core.TreeMarshaller.convertAnother(TreeMarshaller.java:43) at com.thoughtworks.xstream.core.AbstractReferenceMarshaller$1.convertAnother(AbstractReferenceMarshaller.java:88) at com.thoughtworks.xstream.converters.collections.AbstractCollectionConverter.writeItem(AbstractCollectionConverter.java:64) at com.thoughtworks.xstream.converters.collections.CollectionConverter.marshal(CollectionConverter.java:74) at com.thoughtworks.xstream.core.AbstractReferenceMarshaller.convert(AbstractReferenceMarshaller.java:69) at com.thoughtworks.xstream.core.TreeMarshaller.convertAnother(TreeMarshaller.java:58) at