[CI] Restore comparable dependency-review baseline snapshots
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 30/100
Research direction
Start by reviewing the Dependency Review logs and the automatic dependency-submission setup for the ASF repository, then compare its base and head snapshots with the Org runs cited in the issue. An ASF repository administrator is needed to restore comparable snapshots; rerun Dependency Review and verify the missing-base warning is gone and the diff reflects actual dependency changes. Assess the Spring security findings separately, as requested.
Written by the indexing model from the issue text.
Description
Dependency Review on version-upgrade PR #3282 compares a populated head dependency snapshot against an empty base snapshot. It consequently treats existing dependencies as additions and fails on an existing Spring dependency. This is separate from the RPC test failure being repaired in the PR.
Evidence:
- ASF and Org PR #275 use the same source head and base.
- ASF dependency-review log reports base snapshots
0, head snapshots1, and flagsspring-webmvc:5.3.27/ GHSA-pc63-qcmh-9cmg. - The dependency graph comparison reports all 6,083 ASF entries as added. The Org comparison has 210 added and 209 removed entries and no Spring change; Org dependency-review passes.
- Spring 5.3.27 already exists in the base POM. Org has successful Automatic Dependency Submission runs for the base commit; no corresponding ASF run was found.
Requested follow-up:
- Have an ASF repository administrator inspect the automatic dependency submission setup and restore accurate, comparable snapshots for the base and head using the same detector/build inputs.
- Re-run Dependency Review and verify the missing-base warning is gone and the diff represents real dependency changes. A rerun alone cannot populate a missing baseline.
- Assess existing Spring/security findings separately. The Spring advisory requires XsltView and particular view mappings; no XsltView configuration was found in the current PD/Store source, but that static check is not a blanket security clearance.
This follow-up does not request a severity downgrade, advisory exemption, fabricated dependency snapshot, new CI framework, or Spring major-version upgrade in the minimal version PR. Current access has push permission but no ASF repository admin role. See GitHub automatic submission setup.
Release tracking: #3242.
- Dominant language
- Java
- Stars
- 3.2k
- Forks
- 641
- Avg merge
- 2d 9h
- Merged PRs (30d)
- 26
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from apache/hugegraph
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
apache/hugegraph#3231 · 1 comment ·
Maintainers usually reply within 1 day
-
[Bug] Prometheus metrics format bugMay be free again @cui2022 claimed this 59 days ago, and no pull request is open. Openbug
Difficulty 2/5 1-3 hours Newbie friendliness 64/100
apache/hugegraph#3142 · 7 comments ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
Maintainers usually reply within 1 day
-
Difficulty 5/5 Over a week Newbie friendliness 45/100
Maintainers usually reply within 1 day
-
[Bug] Basic auth decodes the credential as ASCII and splits on every colon: a non-ASCII password answers 401, a password with ':' answers 400Possibly taken @arshilkxwork claimed this 1 day ago. Open
Difficulty 1/5 Under an hour Newbie friendliness 35/100
apache/hugegraph#3284 · 1 comment ·
Maintainers usually reply within 1 day
All issues in apache/hugegraph
Similar issues
-
backend
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
bcgov/nr-forest-client#2524 ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 85/100
Sinytra/ForgifiedFabricAPI#298 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 67/100
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 74/100
Maintainers usually reply within 1 day
-
team:Lumberjack
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
OpenLiberty/open-liberty#35998 ·
Maintainers usually reply within 1 day