[JBoss JIRA] (JBIDE-21232) parent pom should never allow skipTests to prevent download of required libraries
by Nick Boldt (JIRA)
[ https://issues.jboss.org/browse/JBIDE-21232?page=com.atlassian.jira.plugi... ]
Nick Boldt reassigned JBIDE-21232:
----------------------------------
Assignee: Denis Golovin
> parent pom should never allow skipTests to prevent download of required libraries
> ---------------------------------------------------------------------------------
>
> Key: JBIDE-21232
> URL: https://issues.jboss.org/browse/JBIDE-21232
> Project: Tools (JBoss Tools)
> Issue Type: Bug
> Components: build, forge, hibernate, openshift
> Affects Versions: 4.3.1.Beta1, 4.4.0.Alpha1
> Reporter: Nick Boldt
> Assignee: Denis Golovin
>
> {quote}
> {quote}I think at this time obviously we have to change
> maven-dependency-plugin declaration
> in *parent/pom.xml#build/pluginManagement* to never skip downloading
> dependencies, because it is most common use case. After it is done we can
> remove unnecessary *<skip>false</skip>* throughout the projects.{quote}
> Yes - your conclusion matches mine on the jira and what mistria suggestion for fixes
> and with my updates handles.
> Can you make it happen ? :)
> {quote}
> If there are libs for (2) and (3) downloaded from external URL using
> download-maven-plugin/maven-download-plugin we should probably move them to
> locus.{quote}
> Main problem I know is forge, hibernate and openshift afaik.
> forge and openshift would not be able to move very fast if we moved their libs for Locus.
> Hibernate - we don't actually want/intend to expose the internal apis of hibernate so not
> sure if pushing all variations of hibernate into Locus is such a good idea....but it could
> be considered.
> One thing that might be worth looking for are those bundling mockito or other testing libs
> that we might already have put into locus or use from orbit so these are not even relevant anymore.{quote}
--
This message was sent by Atlassian JIRA
(v6.4.11#64026)
10 years, 4 months
[JBoss JIRA] (JBIDE-21232) parent pom should never allow skipTests to prevent download of required libraries
by Nick Boldt (JIRA)
[ https://issues.jboss.org/browse/JBIDE-21232?page=com.atlassian.jira.plugi... ]
Nick Boldt updated JBIDE-21232:
-------------------------------
Component/s: forge
hibernate
openshift
> parent pom should never allow skipTests to prevent download of required libraries
> ---------------------------------------------------------------------------------
>
> Key: JBIDE-21232
> URL: https://issues.jboss.org/browse/JBIDE-21232
> Project: Tools (JBoss Tools)
> Issue Type: Bug
> Components: build, forge, hibernate, openshift
> Affects Versions: 4.3.1.Beta1, 4.4.0.Alpha1
> Reporter: Nick Boldt
>
> {quote}
> {quote}I think at this time obviously we have to change
> maven-dependency-plugin declaration
> in *parent/pom.xml#build/pluginManagement* to never skip downloading
> dependencies, because it is most common use case. After it is done we can
> remove unnecessary *<skip>false</skip>* throughout the projects.{quote}
> Yes - your conclusion matches mine on the jira and what mistria suggestion for fixes
> and with my updates handles.
> Can you make it happen ? :)
> {quote}
> If there are libs for (2) and (3) downloaded from external URL using
> download-maven-plugin/maven-download-plugin we should probably move them to
> locus.{quote}
> Main problem I know is forge, hibernate and openshift afaik.
> forge and openshift would not be able to move very fast if we moved their libs for Locus.
> Hibernate - we don't actually want/intend to expose the internal apis of hibernate so not
> sure if pushing all variations of hibernate into Locus is such a good idea....but it could
> be considered.
> One thing that might be worth looking for are those bundling mockito or other testing libs
> that we might already have put into locus or use from orbit so these are not even relevant anymore.{quote}
--
This message was sent by Atlassian JIRA
(v6.4.11#64026)
10 years, 4 months
[JBoss JIRA] (JBIDE-21232) parent pom should never allow skipTests to prevent download of required libraries
by Nick Boldt (JIRA)
Nick Boldt created JBIDE-21232:
----------------------------------
Summary: parent pom should never allow skipTests to prevent download of required libraries
Key: JBIDE-21232
URL: https://issues.jboss.org/browse/JBIDE-21232
Project: Tools (JBoss Tools)
Issue Type: Bug
Components: build
Affects Versions: 4.3.1.Beta1, 4.4.0.Alpha1
Reporter: Nick Boldt
{quote}
{quote}I think at this time obviously we have to change
maven-dependency-plugin declaration
in *parent/pom.xml#build/pluginManagement* to never skip downloading
dependencies, because it is most common use case. After it is done we can
remove unnecessary *<skip>false</skip>* throughout the projects.{quote}
Yes - your conclusion matches mine on the jira and what mistria suggestion for fixes
and with my updates handles.
Can you make it happen ? :)
{quote}
If there are libs for (2) and (3) downloaded from external URL using
download-maven-plugin/maven-download-plugin we should probably move them to
locus.{quote}
Main problem I know is forge, hibernate and openshift afaik.
forge and openshift would not be able to move very fast if we moved their libs for Locus.
Hibernate - we don't actually want/intend to expose the internal apis of hibernate so not
sure if pushing all variations of hibernate into Locus is such a good idea....but it could
be considered.
One thing that might be worth looking for are those bundling mockito or other testing libs
that we might already have put into locus or use from orbit so these are not even relevant anymore.{quote}
--
This message was sent by Atlassian JIRA
(v6.4.11#64026)
10 years, 4 months
[JBoss JIRA] (JBDS-3560) Arbitrary remote code execution with InvokerTransformer (COLLECTIONS-580)
by Alexey Kazakov (JIRA)
[ https://issues.jboss.org/browse/JBDS-3560?page=com.atlassian.jira.plugin.... ]
Alexey Kazakov updated JBDS-3560:
---------------------------------
Fix Version/s: 9.0.0.Beta1
(was: 9.0.0.Beta2)
> Arbitrary remote code execution with InvokerTransformer (COLLECTIONS-580)
> -------------------------------------------------------------------------
>
> Key: JBDS-3560
> URL: https://issues.jboss.org/browse/JBDS-3560
> Project: Developer Studio (JBoss Developer Studio)
> Issue Type: Bug
> Components: upstream
> Affects Versions: 8.1.0.GA, 9.0.0.GA, 10.0.0.Alpha1
> Reporter: Nick Boldt
> Assignee: Fred Bricon
> Fix For: 9.0.0.Beta1, 10.0.0.Alpha1
>
> Attachments: apache-commons-collections-in-JBDS7,8,9,10.png, apache-commons-collections-in-JBDS7,8,9,10_refs1.png, apache-commons-collections-in-JBDS7,8,9,10_refs10.png, apache-commons-collections-in-JBDS7,8,9,10_refs7.png, apache-commons-collections-in-JBDS7,8,9,10_refs8-IS-fuse.png, apache-commons-collections-in-JBDS7,8,9,10_refs8.png, apache-commons-collections-in-JBDS7,8,9,10_refs9.png, orbit.R20150519210750_vs_I20151117200049.log.txt, orbit.R20150519210750_vs_I20151117200049.log_onlyLatest.txt
>
>
> This is a container issue to wrap & track https://issues.apache.org/jira/browse/COLLECTIONS-580
> Problem is that JBDS 9 (and probably 8 and 10 too) include org.apache.commons.collections 3.2.0.v2013030210310, which is affected by COLLECTIONS-580 - Arbitrary remote code execution with InvokerTransformer
--
This message was sent by Atlassian JIRA
(v6.4.11#64026)
10 years, 4 months
[JBoss JIRA] (JBDS-3560) Arbitrary remote code execution with InvokerTransformer (COLLECTIONS-580)
by Alexey Kazakov (JIRA)
[ https://issues.jboss.org/browse/JBDS-3560?page=com.atlassian.jira.plugin.... ]
Alexey Kazakov updated JBDS-3560:
---------------------------------
Fix Version/s: 9.0.0.Beta2
(was: 9.1.0.Beta1)
> Arbitrary remote code execution with InvokerTransformer (COLLECTIONS-580)
> -------------------------------------------------------------------------
>
> Key: JBDS-3560
> URL: https://issues.jboss.org/browse/JBDS-3560
> Project: Developer Studio (JBoss Developer Studio)
> Issue Type: Bug
> Components: upstream
> Affects Versions: 8.1.0.GA, 9.0.0.GA, 10.0.0.Alpha1
> Reporter: Nick Boldt
> Assignee: Fred Bricon
> Fix For: 9.0.0.Beta2, 10.0.0.Alpha1
>
> Attachments: apache-commons-collections-in-JBDS7,8,9,10.png, apache-commons-collections-in-JBDS7,8,9,10_refs1.png, apache-commons-collections-in-JBDS7,8,9,10_refs10.png, apache-commons-collections-in-JBDS7,8,9,10_refs7.png, apache-commons-collections-in-JBDS7,8,9,10_refs8-IS-fuse.png, apache-commons-collections-in-JBDS7,8,9,10_refs8.png, apache-commons-collections-in-JBDS7,8,9,10_refs9.png, orbit.R20150519210750_vs_I20151117200049.log.txt, orbit.R20150519210750_vs_I20151117200049.log_onlyLatest.txt
>
>
> This is a container issue to wrap & track https://issues.apache.org/jira/browse/COLLECTIONS-580
> Problem is that JBDS 9 (and probably 8 and 10 too) include org.apache.commons.collections 3.2.0.v2013030210310, which is affected by COLLECTIONS-580 - Arbitrary remote code execution with InvokerTransformer
--
This message was sent by Atlassian JIRA
(v6.4.11#64026)
10 years, 4 months
[JBoss JIRA] (JBIDE-21119) Update 4.5y.x TP to m2e 1.6.x (with fix for apache commons collections 3.2.2 / COLLECTIONS-580 / JBDS-3560)
by Alexey Kazakov (JIRA)
[ https://issues.jboss.org/browse/JBIDE-21119?page=com.atlassian.jira.plugi... ]
Alexey Kazakov updated JBIDE-21119:
-----------------------------------
Fix Version/s: 4.3.1.Beta2
(was: 4.3.1.Beta1)
> Update 4.5y.x TP to m2e 1.6.x (with fix for apache commons collections 3.2.2 / COLLECTIONS-580 / JBDS-3560)
> -----------------------------------------------------------------------------------------------------------
>
> Key: JBIDE-21119
> URL: https://issues.jboss.org/browse/JBIDE-21119
> Project: Tools (JBoss Tools)
> Issue Type: Bug
> Components: maven, target-platform, upstream
> Affects Versions: 4.3.0.Final
> Reporter: Nick Boldt
> Assignee: Fred Bricon
> Fix For: 4.3.1.Beta2
>
>
> Fred said: {quote}So the m2e archetype feature also embeds a version of vulnerable commons-collections, that we need to fix upstream (even though it's not really vulnerable, just makes people cringy) -- JBDS-3560
> {quote}
> So, we need a new version of m2e 1.6.x (with fix for apache commons collections 3.2.2 / COLLECTIONS-580 / JBDS-3560) and we can then mirror it and update the 4.50.x and 4.51.x TPs (for JBDS 9.1, not 9.0.1).
--
This message was sent by Atlassian JIRA
(v6.4.11#64026)
10 years, 4 months
[JBoss JIRA] (JBIDE-21215) IUs missing from snapshot update site while site is being published / outdated metadata needs to be refreshed within Eclipse
by Nick Boldt (JIRA)
[ https://issues.jboss.org/browse/JBIDE-21215?page=com.atlassian.jira.plugi... ]
Nick Boldt commented on JBIDE-21215:
------------------------------------
Max, as someone who loves statistics and analytics, please document every time this happens so we can establish a pattern to the failures. "see these failures repeatedly" is not a specific enough data set to be able to analyse. I've asked Denis the same thing. Write down when it happens, what you were doing, etc. THEN, and only THEN, can we start to fix it.
Then next time it happens, please add some row of data to a Google Spreadsheet, share it with me, and then try this:
{quote}
Window > Preferences > Install/Update > Available Software Sites > (select the site one at a time) > Reload.
Repeat for all sites you think might have stale metadata. Close that dialog and return to Eclipse.
Help > Check for Updates...
{quote}
> IUs missing from snapshot update site while site is being published / outdated metadata needs to be refreshed within Eclipse
> ----------------------------------------------------------------------------------------------------------------------------
>
> Key: JBIDE-21215
> URL: https://issues.jboss.org/browse/JBIDE-21215
> Project: Tools (JBoss Tools)
> Issue Type: Bug
> Components: build
> Affects Versions: 4.3.1.Beta1
> Reporter: Max Rydahl Andersen
> Assignee: Nick Boldt
> Fix For: 4.3.1.Beta1
>
>
> running updates from: http://download.jboss.org/jbosstools/mars/snapshots/updates/
> I get this error:
> {quote}
> An error occurred while collecting items to be installed
> session context was:(profile=_Users_max_products_eclipse_jee-mars3_Eclipse.app_Contents_Eclipse, phase=org.eclipse.equinox.internal.p2.engine.phases.Collect, operand=, action=).
> No repository found containing: osgi.bundle,org.jboss.tools.common,3.7.1.Beta1-v20151204-0542-B55
> No repository found containing: osgi.bundle,org.jboss.tools.common.core,3.7.1.Beta1-v20151204-0542-B55
> No repository found containing: osgi.bundle,org.jboss.tools.common.el.core,3.7.1.Beta1-v20151204-0542-B55
> No repository found containing: osgi.bundle,org.jboss.tools.common.jdt.debug,3.7.1.Beta1-v20151204-0542-B55
> No repository found containing: osgi.bundle,org.jboss.tools.common.jdt.debug.ui,3.7.1.Beta1-v20151204-0542-B55
> No repository found containing: osgi.bundle,org.jboss.tools.common.resref.core,3.7.1.Beta1-v20151204-0542-B55
> No repository found containing: osgi.bundle,org.jboss.tools.common.text.xml,3.7.1.Beta1-v20151204-0542-B55
> No repository found containing: osgi.bundle,org.jboss.tools.common.ui,3.7.1.Beta1-v20151204-0542-B55
> No repository found containing: osgi.bundle,org.jboss.tools.common.validation,3.7.1.Beta1-v20151204-0542-B55
> No repository found containing: osgi.bundle,org.jboss.tools.foundation.checkup,1.2.1.Beta1-v20151204-0542-B55
> No repository found containing: osgi.bundle,org.jboss.tools.foundation.core,1.2.1.Beta1-v20151204-0542-B55
> No repository found containing: osgi.bundle,org.jboss.tools.foundation.ui,1.2.1.Beta1-v20151204-0542-B55
> No repository found containing: osgi.bundle,org.jboss.tools.openshift.cdk.server,3.1.0.Beta1-v20151205-0342-B106
> No repository found containing: osgi.bundle,org.jboss.tools.openshift.client,3.1.0.Beta1-v20151205-0342-B106
> No repository found containing: osgi.bundle,org.jboss.tools.openshift.common.core,3.1.0.Beta1-v20151205-0342-B106
> No repository found containing: osgi.bundle,org.jboss.tools.openshift.common.ui,3.1.0.Beta1-v20151205-0342-B106
> No repository found containing: osgi.bundle,org.jboss.tools.openshift.core,3.1.0.Beta1-v20151205-0342-B106
> No repository found containing: osgi.bundle,org.jboss.tools.openshift.egit.core,3.1.0.Beta1-v20151205-0342-B106
> No repository found containing: osgi.bundle,org.jboss.tools.openshift.egit.ui,3.1.0.Beta1-v20151205-0342-B106
> No repository found containing: osgi.bundle,org.jboss.tools.openshift.express.client,3.1.0.Beta1-v20151205-0342-B106
> No repository found containing: osgi.bundle,org.jboss.tools.openshift.express.core,3.1.0.Beta1-v20151205-0342-B106
> No repository found containing: osgi.bundle,org.jboss.tools.openshift.express.ui,3.1.0.Beta1-v20151205-0342-B106
> No repository found containing: osgi.bundle,org.jboss.tools.openshift.ui,3.1.0.Beta1-v20151205-0342-B106
> No repository found containing: osgi.bundle,org.jboss.tools.runtime.core,3.1.1.Beta1-v20151204-0542-B55
> No repository found containing: osgi.bundle,org.jboss.tools.runtime.ui,3.1.1.Beta1-v20151204-0542-B55
> No repository found containing: osgi.bundle,org.jboss.tools.stacks.core,1.2.1.Beta1-v20151204-0542-B55
> No repository found containing: osgi.bundle,org.jboss.tools.usage,2.1.1.Beta1-v20151204-0542-B55
> No repository found containing: org.eclipse.update.feature,org.jboss.tools.openshift.cdk.feature,3.1.0.Beta1-v20151205-0342-B106
> No repository found containing: org.eclipse.update.feature,org.jboss.tools.openshift.express.feature,3.1.0.Beta1-v20151205-0342-B106
> No repository found containing: org.eclipse.update.feature,org.jboss.tools.openshift.feature,3.1.0.Beta1-v20151205-0342-B106
> {quote}
--
This message was sent by Atlassian JIRA
(v6.4.11#64026)
10 years, 4 months