From ee15f60c9d2ede667a3501aa654f28eaffab2791 Mon Sep 17 00:00:00 2001 From: Michael Trimarchi Date: Sun, 10 Dec 2023 09:41:46 +0100 Subject: [PATCH 1/4] bump to 2.387.3 to addressing XSS script vulnerability Addressing CVE-2022-34185 Signed-off-by: Michael Trimarchi --- pom.xml | 9 ++------- 1 file changed, 2 insertions(+), 7 deletions(-) diff --git a/pom.xml b/pom.xml index a2d00c7..e7c379f 100644 --- a/pom.xml +++ b/pom.xml @@ -5,18 +5,13 @@ org.jenkins-ci.plugins plugin - 2.11 + 4.75 - 1.614 - + 2.387.3 me.leejay.jenkins From 21c11f2f62c8db3c69043b725cdeda8e325966fe Mon Sep 17 00:00:00 2001 From: Michael Trimarchi Date: Sun, 10 Dec 2023 09:43:14 +0100 Subject: [PATCH 2/4] index.jelly: Escape the title explicity Addressing CVE-2022-34185 Signed-off-by: Michael Trimarchi --- .../dateparameter/DateParameterDefinition/index.jelly | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/src/main/resources/me/leejay/jenkins/dateparameter/DateParameterDefinition/index.jelly b/src/main/resources/me/leejay/jenkins/dateparameter/DateParameterDefinition/index.jelly index 2921d56..26993df 100644 --- a/src/main/resources/me/leejay/jenkins/dateparameter/DateParameterDefinition/index.jelly +++ b/src/main/resources/me/leejay/jenkins/dateparameter/DateParameterDefinition/index.jelly @@ -2,11 +2,11 @@ - - + +
-
\ No newline at end of file + From 3f1ffa3a2f7db0bb6ffa9919818ced59fff26f66 Mon Sep 17 00:00:00 2001 From: Michael Trimarchi Date: Sun, 10 Dec 2023 10:04:28 +0100 Subject: [PATCH 3/4] [maven-release-plugin] prepare release v0.0.5 Signed-off-by: Michael Trimarchi --- pom.xml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pom.xml b/pom.xml index e7c379f..8584e8d 100644 --- a/pom.xml +++ b/pom.xml @@ -16,7 +16,7 @@ me.leejay.jenkins date-parameter - 0.0.5-SNAPSHOT + 0.0.5 hpi Date Parameter Plugin https://wiki.jenkins-ci.org/display/JENKINS/Date+Parameter+Plugin @@ -34,7 +34,7 @@ scm:git:git://github.com/jenkinsci/date-parameter-plugin.git scm:git:git@github.com:jenkinsci/date-parameter-plugin.git https://github.com/jenkinsci/date-parameter-plugin - HEAD + v0.0.5 From ffca73641cdfb64e493bd27bf0d860669078eda8 Mon Sep 17 00:00:00 2001 From: Michael Trimarchi Date: Sun, 10 Dec 2023 10:05:54 +0100 Subject: [PATCH 4/4] [maven-release-plugin] prepare for next development iteration Signed-off-by: Michael Trimarchi --- pom.xml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pom.xml b/pom.xml index 8584e8d..e89a587 100644 --- a/pom.xml +++ b/pom.xml @@ -16,7 +16,7 @@ me.leejay.jenkins date-parameter - 0.0.5 + 0.0.6-SNAPSHOT hpi Date Parameter Plugin https://wiki.jenkins-ci.org/display/JENKINS/Date+Parameter+Plugin @@ -34,7 +34,7 @@ scm:git:git://github.com/jenkinsci/date-parameter-plugin.git scm:git:git@github.com:jenkinsci/date-parameter-plugin.git https://github.com/jenkinsci/date-parameter-plugin - v0.0.5 + HEAD