Skip to content

Commit 5d65c4b

Browse files
[AUTO-CHERRYPICK] Revert "Upgrade maven to 3.8.1 to fix CVE-2021-26291 in javapackages-bootstrap [Critical]" - branch main (#13799)
Co-authored-by: Kanishk Bansal <[email protected]>
1 parent 6e2e149 commit 5d65c4b

File tree

3 files changed

+7
-231
lines changed

3 files changed

+7
-231
lines changed

SPECS/javapackages-bootstrap/CVE-2021-26291.patch

Lines changed: 0 additions & 217 deletions
This file was deleted.

SPECS/javapackages-bootstrap/javapackages-bootstrap.signatures.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -64,7 +64,7 @@
6464
"maven-plugin-testing.tar.xz": "0bc167583eef4321b69d7990d3cb0f2c9e03f7c92137aae0c938c1b6f01798a1",
6565
"maven-plugin-tools.tar.xz": "27a3b5835a34712862b00b3f540fda541c6a54d841988b0a3dec7f02e9a3db11",
6666
"maven-remote-resources-plugin.tar.xz": "e0b8cd3eb4ec00652b44da236b2c4eb796a8f99f89b9f02dbdb290e712854a08",
67-
"maven-resolver-1.7.0.tar.xz": "d25fed747363399d91ab1dd19de01bf9c5eb288db17dc9262d844643dd2a2127",
67+
"maven-resolver.tar.xz": "f9722a31915945fa533995a642f7cee00f5e78ba8c4dfae6ad5f3e84fcbb1f87",
6868
"maven-resources-plugin.tar.xz": "a61514bcf9216c4543c8710dc0c1a7fdf7c4ecdebb1c1de118a2db536142fd9d",
6969
"maven-resources.tar.xz": "cee8b36b3869a40c8fee6e7f01105c835ab192361e9abb5bdd23a706b979b3c1",
7070
"maven-shared-incremental.tar.xz": "951c4c7cf5d4a5a40d47c213c711e76e369cfca4bfd2e55075996706f175af92",
@@ -74,7 +74,7 @@
7474
"maven-surefire.tar.xz": "2f6b7af5b523949ba194ed61774a336cf88b64cdb81753eb73d0b6a94375ff52",
7575
"maven-verifier.tar.xz": "bfd78b31d226bead42b88ae787c310b42aa57b3f64e68652a4e88b0d0f3b49c9",
7676
"maven-wagon.tar.xz": "a34b0a40dd7bc566a284858613c875c5534f80a7c2afd2c3e503e2385728d131",
77-
"maven-3.8.1.tar.xz": "65ea8259df08175343593daf6663e2c8a739d75a8d4ef76f0f7d23e15b06e40a",
77+
"maven.tar.xz": "9041ac7dda108625e159504f14e4d42375a1b2f0cf257a3b3c2ec4f0bd910d9e",
7878
"mockito.tar.xz": "7b35153653525935f7e6a039dbe608a1058b139e9e6b5f3b6d0362ff114fe77f",
7979
"modello.tar.xz": "be90712a48c4305d9e2ea4d35729d2a2b505ea25512fc3014234d9ac1ec6e46c",
8080
"mojo-parent-pom.tar.xz": "23e97b26ff8efd391bccd0cf215bb0ec2e7ac6caf2b9394b61766bfb9b110bb7",

SPECS/javapackages-bootstrap/javapackages-bootstrap.spec

Lines changed: 5 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@
1313

1414
Name: javapackages-bootstrap
1515
Version: 1.5.0
16-
Release: 7%{?dist}
16+
Release: 6%{?dist}
1717
Summary: A means of bootstrapping Java Packages Tools
1818
# For detailed info see the file javapackages-bootstrap-PACKAGE-LICENSING
1919
License: ASL 2.0 and ASL 1.1 and (ASL 2.0 or EPL-2.0) and (EPL-2.0 or GPLv2 with exceptions) and MIT and (BSD with advertising) and BSD-3-Clause and EPL-1.0 and EPL-2.0 and CDDL-1.0 and xpp and CC0 and Public Domain
@@ -87,7 +87,7 @@ Source1057: maven-parent-pom.tar.xz
8787
Source1058: maven-plugin-testing.tar.xz
8888
Source1059: maven-plugin-tools.tar.xz
8989
Source1060: maven-remote-resources-plugin.tar.xz
90-
Source1061: maven-resolver-1.7.0.tar.xz
90+
Source1061: maven-resolver.tar.xz
9191
Source1062: maven-resources-plugin.tar.xz
9292
Source1063: maven-resources.tar.xz
9393
Source1064: maven-shared-incremental.tar.xz
@@ -97,7 +97,7 @@ Source1067: maven-source-plugin.tar.xz
9797
Source1068: maven-surefire.tar.xz
9898
Source1069: maven-verifier.tar.xz
9999
Source1070: maven-wagon.tar.xz
100-
Source1071: maven-3.8.1.tar.xz
100+
Source1071: maven.tar.xz
101101
Source1072: mockito.tar.xz
102102
Source1073: modello.tar.xz
103103
Source1074: mojo-parent-pom.tar.xz
@@ -141,7 +141,6 @@ Patch1: 0001-Remove-usage-of-ArchiveStreamFactory.patch
141141
Patch2: CVE-2023-37460.patch
142142
Patch3: Internal-Java-API.patch
143143
Patch4: CVE-2021-36373.patch
144-
Patch5: CVE-2021-26291.patch
145144

146145
Provides: bundled(ant) = 1.10.9
147146
Provides: bundled(apache-parent) = 23
@@ -203,7 +202,7 @@ Provides: bundled(maven-parent) = 34
203202
Provides: bundled(maven-plugin-testing) = 3.3.0
204203
Provides: bundled(maven-plugin-tools) = 3.6.0
205204
Provides: bundled(maven-remote-resources-plugin) = 1.7.0
206-
Provides: bundled(maven-resolver) = 1.7.0
205+
Provides: bundled(maven-resolver) = 1.6.1
207206
Provides: bundled(maven-resources-plugin) = 3.2.0
208207
Provides: bundled(maven-resources) = 1.4
209208
Provides: bundled(maven-shared-incremental) = 1.1
@@ -213,7 +212,7 @@ Provides: bundled(maven-source-plugin) = 3.2.1
213212
Provides: bundled(maven-surefire) = 3.0.0~M3
214213
Provides: bundled(maven-verifier) = 1.7.2
215214
Provides: bundled(maven-wagon) = 3.4.2
216-
Provides: bundled(maven) = 3.8.1
215+
Provides: bundled(maven) = 3.6.3
217216
Provides: bundled(mockito) = 3.7.13
218217
Provides: bundled(modello) = 1.11
219218
Provides: bundled(mojo-parent) = 60
@@ -306,8 +305,6 @@ pushd "downstream/ant"
306305
%patch4 -p1
307306
popd
308307

309-
%patch5 -p1
310-
311308
# remove guava.xml from javapackage-bootstrap 1.5.0
312309
# import guava.xml 32.1.3 from Fedora 40
313310
# edit version from guava.properties
@@ -392,10 +389,6 @@ sed -i 's|/usr/lib/jvm/java-11-openjdk|%{java_home}|' %{buildroot}%{launchersPat
392389
%doc AUTHORS
393390

394391
%changelog
395-
* Tue May 13 2025 Kanishk Bansal <[email protected]> - 1.5.0-7
396-
- Update maven to 3.8.1 and maven-resolver to 1.7.0 to fix CVE-2021-26291
397-
- Add the CVE-2021-26291.patch to enable these upgrades
398-
399392
* Wed Feb 26 2025 Kshitiz Godara <[email protected]> - 1.5.0-6
400393
- Patch CVE-2021-36373 and CVE-2021-36374.
401394

0 commit comments

Comments
 (0)