11package :
22 name : sonarqube
3- version : " 25.12 .0.117093 "
4- epoch : 2 # GHSA-qf7c-7r9h-mm92, GHSA-vc5p-v9hr-52mj
3+ version : " 26.1 .0.118079 "
4+ epoch : 0 # GHSA-qf7c-7r9h-mm92, GHSA-vc5p-v9hr-52mj
55 description : SonarQube is an open source platform for continuous inspection of code quality (Community Build)
66 copyright :
77 - license : LGPL-3.0-or-later
@@ -22,12 +22,12 @@ environment:
2222 - ca-certificates-bundle
2323 - nodejs-18
2424 - npm
25- - openjdk-17 -default-jdk
25+ - openjdk-21 -default-jdk
2626 - yarn
2727 - zstd-dev
2828 environment :
2929 LANG : en_US.UTF-8
30- JAVA_HOME : /usr/lib/jvm/java-17 -openjdk
30+ JAVA_HOME : /usr/lib/jvm/java-21 -openjdk
3131
3232var-transforms :
3333 - from : ${{package.version}}
@@ -40,9 +40,7 @@ pipeline:
4040 with :
4141 repository : https://github.com/SonarSource/sonarqube
4242 tag : ${{package.version}}
43- expected-commit : bd7a1254715e0df950e61d05c9a07cb1ba42552b
44- cherry-picks : |
45- master/c6894b30d37bcfb0d093a3bffb8a31744ca2b489: GHSA-m9gh-789g-q5pv
43+ expected-commit : 0695ca177c73c89db330c94682e80d42d697336c
4644
4745 - name : Bump elasticsearch to 8.19.9 to remediate GHSA-qf7c-7r9h-mm92 and GHSA-vc5p-v9hr-52mj
4846 runs : |
@@ -137,7 +135,7 @@ test:
137135 permissions : 0o770
138136 contents :
139137 packages :
140- - openjdk-17 -default-jvm
138+ - openjdk-21 -default-jvm
141139 - bash
142140 environment :
143141 SONAR_JAVA_PATH : /usr/bin/java
0 commit comments