- 
                Notifications
    You must be signed in to change notification settings 
- Fork 3.4k
HBASE-29651 Bump jruby to 9.4.14.0 to fix multiple CVEs #7405
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
| 🎊 +1 overall 
 
 This message was automatically generated. | 
| 💔 -1 overall 
 
 This message was automatically generated. | 
| Built code locally with this change, untar'ed, started hbase, and ran basic shell commands and verified no errors! Test cases :- Execution report :- | 
| UT Failures are not related. Validation looks fine. | 
| Hi @xavifeds8 I assume this is your first PR in Apache HBase. Welcome to the project with your first contribution. I would suggest you to (also) add your personal email for the commits currently it references your organisation email id. Please update and push a commit to fix this. Also, please ensure to keep PR title in sync with the JIRA title. We usually follow a simple format  Ref https://hbase.apache.org/book.html#_commit_message_format | 
4377a71    to
    1745bdc      
    Compare
  
    1745bdc    to
    b0e21f3      
    Compare
  
    | Hi @NihalJain , Thanks for the warm welcome! I have applied both fixes: Thanks! | 
| Pushed to master. Please raise backports for all relevant branches. I think this would go until branch-2 | 
      
        
              This comment was marked as outdated.
        
        
      
    
  This comment was marked as outdated.
    
      
        1 similar comment
      
    
  
    | 💔 -1 overall 
 
 This message was automatically generated. | 
This change fixes the following list of CVEs: - **CVE-2025-43857**: Fixed in JRuby 9.4.13.0 - **CVE-2025-27219**: Fixed in JRuby 9.4.14.0 - **CVE-2025-27220**: Fixed in JRuby 9.4.14.0 Signed-off-by: Nihal Jain <[email protected]> Signed-off-by: Pankaj Kumar <[email protected]> (cherry picked from commit 305951e)
This change fixes the following list of CVEs: - **CVE-2025-43857**: Fixed in JRuby 9.4.13.0 - **CVE-2025-27219**: Fixed in JRuby 9.4.14.0 - **CVE-2025-27220**: Fixed in JRuby 9.4.14.0 Signed-off-by: Nihal Jain <[email protected]> Signed-off-by: Pankaj Kumar <[email protected]> (cherry picked from commit 305951e)
This change fixes the following list of CVEs: - **CVE-2025-43857**: Fixed in JRuby 9.4.13.0 - **CVE-2025-27219**: Fixed in JRuby 9.4.14.0 - **CVE-2025-27220**: Fixed in JRuby 9.4.14.0 Signed-off-by: Nihal Jain <[email protected]> Signed-off-by: Pankaj Kumar <[email protected]> (cherry picked from commit 305951e)
This change fixes the following list of CVEs: