<!-- 
RSS generated by JIRA (1001.0.0-SNAPSHOT#100246-sha1:7a5c50119eb0633d306e14180817ddef5e80c75d) at Thu Feb 08 23:29:27 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary add field=key&field=summary to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>FOLIO Jira</title>
    <link>https://folio-org.atlassian.net</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>1001.0.0-SNAPSHOT</version>
        <build-number>100246</build-number>
        <build-date>07-02-2024</build-date>
    </build-info>

<item>
            <title>[FOLIO-3618] Rebuild folioci/jenkins-slave-all for java-17 and java-11</title>
                <link>https://folio-org.atlassian.net/browse/FOLIO-3618</link>
                <project id="10290" key="FOLIO">FOLIO</project>
                    <description>&lt;p&gt;These docker images are used by Jenkins for all back-end modules &#8211; specified via their Jenkinsfile which version java-17 or java-11 (&lt;a href=&quot;https://dev.folio.org/faqs/how-to-specify-backend-java-ci/&quot; class=&quot;external-link&quot; rel=&quot;nofollow noreferrer&quot;&gt;see doc&lt;/a&gt;). The java-11 is used for platform and reference environments.&lt;/p&gt;

&lt;p&gt;Rebuild folio-tools/jenkins-slave-docker via Dockerfile.jammy-java-17 and Dockerfile.jammy-java-11&lt;/p&gt;

&lt;p&gt;The latest docker images&lt;/p&gt;
&lt;ul&gt;
	&lt;li&gt;&quot;folioci/jenkins-slave-all:java-17&quot; and &quot;3.0.6&quot;.&lt;/li&gt;
	&lt;li&gt;&quot;folioci/jenkins-slave-all:java-11&quot; and &quot;2.10.6&quot;.&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;use openssl 3.0.2-0ubuntu1.6 that has two severe security vulnerabilities:&lt;/p&gt;
&lt;ul&gt;
	&lt;li&gt;&lt;a href=&quot;https://www.openssl.org/news/secadv/20221101.txt&quot; class=&quot;external-link&quot; rel=&quot;nofollow noreferrer&quot;&gt;https://www.openssl.org/news/secadv/20221101.txt&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2022-3602&quot; class=&quot;external-link&quot; rel=&quot;nofollow noreferrer&quot;&gt;https://nvd.nist.gov/vuln/detail/CVE-2022-3602&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2022-3786&quot; class=&quot;external-link&quot; rel=&quot;nofollow noreferrer&quot;&gt;https://nvd.nist.gov/vuln/detail/CVE-2022-3786&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;&lt;a href=&quot;https://snyk.io/blog/new-openssl-critical-vulnerability/&quot; class=&quot;external-link&quot; rel=&quot;nofollow noreferrer&quot;&gt;https://snyk.io/blog/new-openssl-critical-vulnerability/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;An Ubuntu patch is available: &lt;a href=&quot;https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.7&quot; class=&quot;external-link&quot; rel=&quot;nofollow noreferrer&quot;&gt;https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.7&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;When rebuilding jenkins-slave the patch will automatically be used. No other work than doing the rebuild is required.&lt;/p&gt;</description>
                <environment></environment>
        <key id="82369">FOLIO-3618</key>
            <summary>Rebuild folioci/jenkins-slave-all for java-17 and java-11</summary>
                <type id="10003" iconUrl="https://folio-org.atlassian.net/rest/api/2/universal_avatar/view/type/issuetype/avatar/10318?size=medium">Task</type>
                                            <priority id="10000" iconUrl="https://dev.folio.org/assets/jira-priority/jira-p1.svg">P1</priority>
                        <status id="6" iconUrl="https://folio-org.atlassian.net/images/icons/statuses/closed.png" description="The issue is considered finished, the resolution is correct. Issues which are closed can be reopened.">Closed</status>
                    <statusCategory id="3" key="done" colorName="green"/>
                                    <resolution id="10003">Done</resolution>
                                                        <assignee accountid="61cd0ca0bce5e00069e98be7">David Crossley</assignee>
                                                                <reporter accountid="61cd0ca0bce5e00069e98be7">David Crossley</reporter>
                                    <labels>
                            <label>security</label>
                    </labels>
                <created>Wed, 26 Oct 2022 04:15:05 +0000</created>
                <updated>Thu, 3 Nov 2022 10:13:43 +0000</updated>
                            <resolved>Thu, 3 Nov 2022 03:02:35 +0000</resolved>
                                                                        <due></due>
                            <votes>0</votes>
                                    <watches>2</watches>
                                                                <comments>
                                                            <comment id="198316" author="61cd0ca0bce5e00069e98be7" created="Thu, 3 Nov 2022 00:24:38 +0000"  >&lt;p&gt;Thanks Julian for adding that clarification.&lt;/p&gt;</comment>
                                                            <comment id="198317" author="61cd0ca0bce5e00069e98be7" created="Thu, 3 Nov 2022 03:02:19 +0000"  >&lt;p&gt;The new images are built, tested, and pushed as:&lt;br/&gt;
&quot;folioci/jenkins-slave-all:java-17&quot; and &quot;3.0.7&quot;.&lt;br/&gt;
&quot;folioci/jenkins-slave-all:java-11&quot; and &quot;2.10.7&quot;.&lt;/p&gt;

&lt;p&gt;&#160;&lt;/p&gt;</comment>
                                                            <comment id="198319" author="5ee89462f7aa140abd82d11d" created="Thu, 3 Nov 2022 10:13:43 +0000"  >&lt;p&gt;Thanks, both new images actually have the patched version:&lt;/p&gt;
&lt;div class=&quot;code panel&quot; style=&quot;border-width: 1px;&quot;&gt;&lt;div class=&quot;codeContent panelContent&quot;&gt;
&lt;pre class=&quot;code-java&quot;&gt;
$ docker exec -it jenkins-slave dpkg-query --list openssl
Desired=Unknown/Install/Remove/Purge/Hold
| Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend
|/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad)
||/ Name &#160; &#160; &#160; &#160; &#160; Version &#160; &#160; &#160; &#160; &#160;Architecture Description
+++-==============-================-============-====================================================
ii &#160;openssl &#160; &#160; &#160; &#160;3.0.2-0ubuntu1.7 amd64 &#160; &#160; &#160; &#160;Secure Sockets Layer toolkit - cryptographic utility &lt;/pre&gt;
&lt;/div&gt;&lt;/div&gt;</comment>
                    </comments>
                    <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                <customfield id="customfield_10000" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummarycf">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10057" key="com.atlassian.jira.plugin.system.customfieldtypes:select">
                        <customfieldname>Development Team</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue key="10155"><![CDATA[FOLIO DevOps]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                <customfield id="customfield_10063" key="com.atlassian.jira.plugin.system.customfieldtypes:float">
                        <customfieldname>PO Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>0.0</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                    <customfield id="customfield_10106" key="com.atlassian.jira.plugin.system.customfieldtypes:select">
                        <customfieldname>RCA Group</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue key="10385"><![CDATA[Related dependency upgrade]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                            <customfield id="customfield_10019" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>0|i05ntf:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    <customfield id="customfield_10020" key="com.pyxis.greenhopper.jira:gh-sprint">
                        <customfieldname>Sprint</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue id="2010">DevOps Sprint 151</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        <customfield id="customfield_10024" key="com.atlassian.jira.ext.charting:firstresponsedate">
                        <customfieldname>[CHART] Date of First Response</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>Thu, 3 Nov 2022 10:13:43 +0000</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10025" key="com.atlassian.jira.ext.charting:timeinstatus">
                        <customfieldname>[CHART] Time in Status</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                    </customfields>
    </item>
</channel>
</rss>