<!-- 
RSS generated by JIRA (1001.0.0-SNAPSHOT#100246-sha1:7a5c50119eb0633d306e14180817ddef5e80c75d) at Thu Feb 08 23:26:34 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary add field=key&field=summary to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>FOLIO Jira</title>
    <link>https://folio-org.atlassian.net</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>1001.0.0-SNAPSHOT</version>
        <build-number>100246</build-number>
        <build-date>07-02-2024</build-date>
    </build-info>

<item>
            <title>[FOLIO-3228] Cleanup and upgrade/rebuild Dockerfile.focal-java-11</title>
                <link>https://folio-org.atlassian.net/browse/FOLIO-3228</link>
                <project id="10290" key="FOLIO">FOLIO</project>
                    <description>&lt;ul&gt;
	&lt;li&gt;Remove Dockerfile.agent-focal-java-11 and Dockerfile.xenial-java-8. They are not maintained and shouldn&apos;t been used any longer.&lt;/li&gt;
	&lt;li&gt;Remove Ruby, no longer needed. Ruby 2.4 has multiple vulnerabilities. Solves &lt;a href=&quot;https://folio-org.atlassian.net/browse/FOLIO-3164&quot; class=&quot;external-link&quot; rel=&quot;nofollow noreferrer&quot;&gt;https://folio-org.atlassian.net/browse/FOLIO-3164&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;Update PostgreSQL from 10 to 12. Solves &lt;a href=&quot;https://folio-org.atlassian.net/browse/FOLIO-3167&quot; class=&quot;external-link&quot; rel=&quot;nofollow noreferrer&quot;&gt;https://folio-org.atlassian.net/browse/FOLIO-3167&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;Update Docker from 20.10.6 to 20.10.7.&lt;/li&gt;
	&lt;li&gt;Update Ansible from 2.9.21 to 2.9.23.&lt;/li&gt;
&lt;/ul&gt;


&lt;ul&gt;
	&lt;li&gt;The re-build also updates many other important tools:&lt;/li&gt;
&lt;/ul&gt;


&lt;ul&gt;
	&lt;li&gt;Update Node from 12.22.1 to 12.22.2 ( &lt;a href=&quot;https://nodejs.org/en/blog/release/v12.22.2/&quot; class=&quot;external-link&quot; rel=&quot;nofollow noreferrer&quot;&gt;https://nodejs.org/en/blog/release/v12.22.2/&lt;/a&gt; ) fixing
	&lt;ul&gt;
		&lt;li&gt;CVE-2021-27290: npm upgrade - ssri Regular Expression Denial of Service (ReDoS) (High)&lt;/li&gt;
		&lt;li&gt;CVE-2021-22918: libuv upgrade - Out of bounds read (Medium)&lt;/li&gt;
		&lt;li&gt;CVE-2021-22921: Windows installer - Node Installer Local Privilege Escalation (Medium)&lt;/li&gt;
		&lt;li&gt;CVE-2021-23362: npm upgrade - hosted-git-info Regular Expression Denial of Service (ReDoS) (Medium)&lt;/li&gt;
	&lt;/ul&gt;
	&lt;/li&gt;
	&lt;li&gt;Google Chrome 91.0.4472.114 - &lt;a href=&quot;https://chromereleases.googleblog.com/search/label/Stable%20updates&quot; class=&quot;external-link&quot; rel=&quot;nofollow noreferrer&quot;&gt;https://chromereleases.googleblog.com/search/label/Stable%20updates&lt;/a&gt;
	&lt;ul&gt;
		&lt;li&gt;Critical CVE-2021-30544: Use after free in BFCache.&lt;/li&gt;
		&lt;li&gt;High CVE-2021-30521: Heap buffer overflow in Autofill.&lt;/li&gt;
		&lt;li&gt;High CVE-2021-30522: Use after free in WebAudio.&lt;/li&gt;
		&lt;li&gt;High CVE-2021-30523: Use after free in WebRTC.&lt;/li&gt;
		&lt;li&gt;High CVE-2021-30524: Use after free in TabStrip.&lt;/li&gt;
		&lt;li&gt;High CVE-2021-30525: Use after free in TabGroups.&lt;/li&gt;
		&lt;li&gt;High CVE-2021-30526: Out of bounds write in TabStrip.&lt;/li&gt;
		&lt;li&gt;High CVE-2021-30527: Use after free in WebUI.&lt;/li&gt;
		&lt;li&gt;High CVE-2021-30528: Use after free in WebAuthentication.&lt;/li&gt;
		&lt;li&gt;High CVE-2021-30545: Use after free in Extensions.&lt;/li&gt;
		&lt;li&gt;High CVE-2021-30546: Use after free in Autofill.&lt;/li&gt;
		&lt;li&gt;High CVE-2021-30547: Out of bounds write in ANGLE.&lt;/li&gt;
		&lt;li&gt;High CVE-2021-30548: Use after free in Loader.&lt;/li&gt;
		&lt;li&gt;High CVE-2021-30549: Use after free in Spell check.&lt;/li&gt;
		&lt;li&gt;High CVE-2021-30550: Use after free in Accessibility.&lt;/li&gt;
		&lt;li&gt;High CVE-2021-30551: Type Confusion in V8.&lt;/li&gt;
		&lt;li&gt;High CVE-2021-30554: Use after free in WebGL&lt;/li&gt;
		&lt;li&gt;High CVE-2021-30555: Use after free in Sharing.&lt;/li&gt;
		&lt;li&gt;High CVE-2021-30556: Use after free in WebAudio.&lt;/li&gt;
		&lt;li&gt;High CVE-2021-30557: Use after free in TabGroups.&lt;/li&gt;
		&lt;li&gt;Medium CVE-2021-30529: Use after free in Bookmarks.&lt;/li&gt;
		&lt;li&gt;Medium CVE-2021-30530: Out of bounds memory access in WebAudio.&lt;/li&gt;
		&lt;li&gt;Medium CVE-2021-30531: Insufficient policy enforcement in Content Security Policy.&lt;/li&gt;
		&lt;li&gt;Medium CVE-2021-30532: Insufficient policy enforcement in Content Security Policy.&lt;/li&gt;
		&lt;li&gt;Medium CVE-2021-30533: Insufficient policy enforcement in PopupBlocker.&lt;/li&gt;
		&lt;li&gt;Medium CVE-2021-30534: Insufficient policy enforcement in iFrameSandbox.&lt;/li&gt;
		&lt;li&gt;Medium CVE-2021-30535: Double free in ICU.&lt;/li&gt;
		&lt;li&gt;Medium CVE-2021-30542: Use after free in Tab Strip&lt;/li&gt;
		&lt;li&gt;Medium CVE-2021-30543: Use after free in Tab Strip.&lt;/li&gt;
		&lt;li&gt;Medium CVE-2021-30558: Insufficient policy enforcement in content security policy.&lt;/li&gt;
		&lt;li&gt;Medium CVE-2021-30552: Use after free in Extensions.&lt;/li&gt;
		&lt;li&gt;Medium CVE-2021-30553: Use after free in Network service.&lt;/li&gt;
		&lt;li&gt;Low CVE-2021-30536: Out of bounds read in V8.&lt;/li&gt;
		&lt;li&gt;Low CVE-2021-30537: Insufficient policy enforcement in cookies.&lt;/li&gt;
		&lt;li&gt;Low CVE-2021-30537: Insufficient policy enforcement in cookies.&lt;/li&gt;
		&lt;li&gt;Low CVE-2021-30539: Insufficient policy enforcement in content security policy.&lt;/li&gt;
		&lt;li&gt;Low CVE-2021-30540: Incorrect security UI in payments.&lt;/li&gt;
	&lt;/ul&gt;
	&lt;/li&gt;
	&lt;li&gt;aws-cli/2.2.17&lt;/li&gt;
	&lt;li&gt;stripes-cli 2.3.1000253&lt;/li&gt;
&lt;/ul&gt;
</description>
                <environment></environment>
        <key id="82137">FOLIO-3228</key>
            <summary>Cleanup and upgrade/rebuild Dockerfile.focal-java-11</summary>
                <type id="10001" iconUrl="https://folio-org.atlassian.net/rest/api/2/universal_avatar/view/type/issuetype/avatar/10303?size=medium">Bug</type>
                                            <priority id="10005" iconUrl="https://dev.folio.org/assets/jira-priority/tbd.svg">TBD</priority>
                        <status id="6" iconUrl="https://folio-org.atlassian.net/images/icons/statuses/closed.png" description="The issue is considered finished, the resolution is correct. Issues which are closed can be reopened.">Closed</status>
                    <statusCategory id="3" key="done" colorName="green"/>
                                    <resolution id="10003">Done</resolution>
                                                        <assignee accountid="61cd0ca0bce5e00069e98be7">David Crossley</assignee>
                                                                <reporter accountid="5ee89462f7aa140abd82d11d">Julian Ladisch</reporter>
                                    <labels>
                            <label>security</label>
                    </labels>
                <created>Mon, 5 Jul 2021 07:57:39 +0000</created>
                <updated>Thu, 8 Jul 2021 14:20:24 +0000</updated>
                            <resolved>Thu, 8 Jul 2021 04:57:06 +0000</resolved>
                                                                    <component>Continuous Integration</component>
                        <due></due>
                            <votes>0</votes>
                                    <watches>2</watches>
                                                                <comments>
                                                            <comment id="197843" author="5ee89462f7aa140abd82d11d" created="Mon, 5 Jul 2021 08:02:16 +0000"  >&lt;p&gt;Pull request: &lt;a href=&quot;https://github.com/folio-org/folio-tools/pull/187&quot; class=&quot;external-link&quot; rel=&quot;nofollow noreferrer&quot;&gt;https://github.com/folio-org/folio-tools/pull/187&lt;/a&gt;&lt;/p&gt;</comment>
                                                            <comment id="197845" author="61cd0ca0bce5e00069e98be7" created="Thu, 8 Jul 2021 02:47:22 +0000"  >&lt;p&gt;The new &quot;java-11-test&quot; Jenkins build image has been constructed, deployed, and tested with ui-checkin, mod-notes, and refenv folio-snapshot-test.&lt;/p&gt;

&lt;p&gt;Also tagged and deployed as &quot;2.9.0&quot; and &quot;java-11&quot;.&lt;/p&gt;

&lt;p&gt;There are a few tweaks needed to pull/187 (see comments there) and then that configuration can be merged.&lt;/p&gt;

&lt;p&gt;Thanks Julian.&lt;/p&gt;</comment>
                    </comments>
                <issuelinks>
                            <issuelinktype id="10008">
                    <name>Defines</name>
                                            <outwardlinks description="defines">
                                        <issuelink>
            <issuekey id="82050">FOLIO-3164</issuekey>
        </issuelink>
                            </outwardlinks>
                                                        </issuelinktype>
                            <issuelinktype id="10003">
                    <name>Relates</name>
                                                                <inwardlinks description="relates to">
                                        <issuelink>
            <issuekey id="82053">FOLIO-3167</issuekey>
        </issuelink>
                            </inwardlinks>
                                    </issuelinktype>
                    </issuelinks>
                <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                <customfield id="customfield_10000" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummarycf">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10057" key="com.atlassian.jira.plugin.system.customfieldtypes:select">
                        <customfieldname>Development Team</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue key="10155"><![CDATA[FOLIO DevOps]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                <customfield id="customfield_10063" key="com.atlassian.jira.plugin.system.customfieldtypes:float">
                        <customfieldname>PO Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>0.0</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                            <customfield id="customfield_10019" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>0|i031i7:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    <customfield id="customfield_10020" key="com.pyxis.greenhopper.jira:gh-sprint">
                        <customfieldname>Sprint</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue id="1995">DevOps Sprint 118</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        <customfield id="customfield_10024" key="com.atlassian.jira.ext.charting:firstresponsedate">
                        <customfieldname>[CHART] Date of First Response</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>Thu, 8 Jul 2021 02:47:22 +0000</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10025" key="com.atlassian.jira.ext.charting:timeinstatus">
                        <customfieldname>[CHART] Time in Status</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                    </customfields>
    </item>
</channel>
</rss>