Skip to content

Commit 472a583

Browse files
authored
Merge pull request #140 from ibm-datapower/amiya-cve-fix
updated plugin to fix multiple CVEs
2 parents 0ac1318 + 18ed629 commit 472a583

File tree

8 files changed

+22
-8
lines changed

8 files changed

+22
-8
lines changed

.github/workflows/main.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ jobs:
3131
- name: Create GitHub Release
3232
uses: softprops/action-gh-release@v2
3333
with:
34-
tag_name: Datapower26
34+
tag_name: Datapower27
3535
files: |
3636
dist/*.zip
3737
dist/*.jar

.gitignore

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,3 +7,7 @@
77

88
/target/
99
/schemas/
10+
.DS_Store
11+
.idea/
12+
src/datapower-configuration-manager.iml
13+
src/main/main.iml

README.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ Deploy (UCD).
77
## Prerequisites
88

99
* JDK 1.6 or later is required to build. An equivalent JRE is supported if using a prebuilt plugin.
10-
* Apache Ant (1.8.1 or later, 1.9.9 will be packaged with UCD plugin)
10+
* Apache Ant (1.8.1 or later, 1.9.15 will be packaged with UCD plugin)
1111

1212
## Building
1313

build.xml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -41,16 +41,16 @@
4141

4242
<!-- Java-related defaults -->
4343
<property name="java.debug" value="true"/>
44-
<property name="needed.java.version" value="1.7"/>
44+
<property name="needed.java.version" value="1.8"/>
4545

4646
<!-- Which Xalan version to include -->
47-
<property name="needed.xalan.version" value="2.7.2"/>
47+
<property name="needed.xalan.version" value="2.7.3"/>
4848

4949
<!-- Which Ant version to include -->
50-
<property name="needed.ant.version" value="1.9.9"/>
50+
<property name="needed.ant.version" value="1.9.15"/>
5151

5252
<!-- Plugin version during build time -->
53-
<property name="plugin.version" value="26"/>
53+
<property name="plugin.version" value="27"/>
5454

5555
<target name="distro" description="Produce a new distribution" depends="clean,plugin">
5656

src/main/zip/RunDeployDotAnt.groovy

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -54,7 +54,7 @@ try
5454

5555
def ch = new CommandHelper(new File('.'))
5656
def dcmDir = ch.getProcessBuilder().environment().get('PLUGIN_HOME') + '/dcm'
57-
def anthome = dcmDir + '/apache-ant-1.9.9/'
57+
def anthome = dcmDir + '/apache-ant-1.9.15/'
5858
ch.addEnvironmentVariable('ANT_HOME', anthome)
5959

6060
// Get ANT_OPTS environment variable

src/main/zip/info.xml

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -200,5 +200,13 @@
200200
<release-note plugin-version="26">
201201
Added "upload directory" step a a duplicate step to "upload files" to avoid confusion for a users.
202202
</release-note>
203+
<release-note plugin-version="27">
204+
DataPower plugin is now bundled with Ant v1.9.15due to CVEs.
205+
Removed vulnerability: CVE-2022-34169
206+
Removed vulnerability: sonatype-2018-0330
207+
Removed vulnerability: CVE-2020-1945
208+
Removed vulnerability: CVE-2021-36373
209+
Removed vulnerability: CVE-2022-34169
210+
</release-note>
203211
</release-notes>
204212
</pluginInfo>

src/main/zip/plugin.xml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
<plugin xmlns="http://www.urbancode.com/PluginXMLSchema_v1" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
2020

2121
<header>
22-
<identifier version="26" id="com.ibm.datapower" name="DataPower"/>
22+
<identifier version="27" id="com.ibm.datapower" name="DataPower"/>
2323
<description>The IBM WebSphere DataPower plugin deploys DataPower services.</description>
2424
<tag>Infrastructure/WebSphere DataPower</tag>
2525
</header>

src/main/zip/upgrade.xml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -597,5 +597,7 @@
597597
</migrate>
598598
<migrate to-version="26">
599599
</migrate>
600+
<migrate to-version="27">
601+
</migrate>
600602

601603
</plugin-upgrade>

0 commit comments

Comments
 (0)