Skip to content

[2.19] Bump org.apache.hadoop:hadoop-minicluster from 3.4.1 to 3.4.2 in /test/fixtures/hdfs-fixture (#19203)#19605

Merged
cwperks merged 2 commits intoopensearch-project:2.19from
dbwiddis:backport/backport-19203-to-2.19
Oct 13, 2025
Merged

[2.19] Bump org.apache.hadoop:hadoop-minicluster from 3.4.1 to 3.4.2 in /test/fixtures/hdfs-fixture (#19203)#19605
cwperks merged 2 commits intoopensearch-project:2.19from
dbwiddis:backport/backport-19203-to-2.19

Conversation

@dbwiddis
Copy link
Copy Markdown
Member

Backports 26a4014 from #19203

Fixes CVE-2025-3588

…t/fixtures/hdfs-fixture (opensearch-project#19203)

* Bump org.apache.hadoop:hadoop-minicluster in /test/fixtures/hdfs-fixture

Bumps org.apache.hadoop:hadoop-minicluster from 3.4.1 to 3.4.2.

---
updated-dependencies:
- dependency-name: org.apache.hadoop:hadoop-minicluster
  dependency-version: 3.4.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

* Update changelog

Signed-off-by: dependabot[bot] <support@github.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Craig Perkins <cwperx@amazon.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Craig Perkins <cwperx@amazon.com>
(cherry picked from commit 26a4014)
@dbwiddis dbwiddis requested a review from a team as a code owner October 11, 2025 22:25
@dbwiddis dbwiddis added the CVE Fixes a CVE label Oct 11, 2025
@github-actions
Copy link
Copy Markdown
Contributor

✅ Gradle check result for a323f8f: SUCCESS

@codecov
Copy link
Copy Markdown

codecov bot commented Oct 11, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 71.91%. Comparing base (9057d4c) to head (d3f3076).
⚠️ Report is 1 commits behind head on 2.19.

Additional details and impacted files
@@             Coverage Diff              @@
##               2.19   #19605      +/-   ##
============================================
- Coverage     71.93%   71.91%   -0.03%     
+ Complexity    65945    65936       -9     
============================================
  Files          5341     5341              
  Lines        307273   307273              
  Branches      44845    44845              
============================================
- Hits         221050   220968      -82     
- Misses        67735    67887     +152     
+ Partials      18488    18418      -70     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@dbwiddis dbwiddis added the v2.19.4 Issues targeting release v2.19.4 label Oct 12, 2025
Signed-off-by: Craig Perkins <cwperx@amazon.com>
@github-actions
Copy link
Copy Markdown
Contributor

✅ Gradle check result for d3f3076: SUCCESS

@cwperks cwperks merged commit 887b961 into opensearch-project:2.19 Oct 13, 2025
43 of 45 checks passed
sokdak pushed a commit to sokdak/OpenSearch that referenced this pull request Oct 15, 2025
…t/fixtures/hdfs-fixture (opensearch-project#19203) (opensearch-project#19605)

* Bump org.apache.hadoop:hadoop-minicluster in /test/fixtures/hdfs-fixture

Bumps org.apache.hadoop:hadoop-minicluster from 3.4.1 to 3.4.2.

---
updated-dependencies:
- dependency-name: org.apache.hadoop:hadoop-minicluster
  dependency-version: 3.4.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...



* Update changelog



---------





(cherry picked from commit 26a4014)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Craig Perkins <cwperx@amazon.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Craig Perkins <cwperx@amazon.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CVE Fixes a CVE v2.19.4 Issues targeting release v2.19.4

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants