Commit Graph

49 Commits

Author SHA1 Message Date
dependabot[bot] 5e7c2820a4 Bump com.google.guava:guava from 31.1-jre to 33.5.0-jre (#813)
Bumps [com.google.guava:guava](https://github.com/google/guava) from 31.1-jre to 33.5.0-jre.
- [Release notes](https://github.com/google/guava/releases)
- [Commits](https://github.com/google/guava/commits)

---
updated-dependencies:
- dependency-name: com.google.guava:guava
  dependency-version: 33.5.0-jre
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-12 11:50:46 -07:00
nthmost-orkes bc5839f710 Merge main into upgrade-protobuf-4.33.0 2025-12-03 16:02:45 -08:00
nthmost-orkes 2548ea0536 Upgrade protobuf-java to 4.33.0 to address security vulnerability
- Update protobuf-java from 3.25.5 to 4.33.0 (addresses CVE announced Jan 2025)
- Update protobuf-gradle-plugin from 0.8.19 to 0.9.5
- Use protoc 3.25.5 for code generation (maintains gRPC compatibility)
- Fix hardcoded protobuf version in annotations-processor

Closes #644
Closes #232
Closes #231
2025-12-03 14:51:04 -08:00
dependabot[bot] 45b7411715 Bump com.github.jknack:handlebars from 4.3.1 to 4.5.0
Bumps [com.github.jknack:handlebars](https://github.com/jknack/handlebars.java) from 4.3.1 to 4.5.0.
- [Release notes](https://github.com/jknack/handlebars.java/releases)
- [Commits](https://github.com/jknack/handlebars.java/compare/v4.3.1...v4.5.0)

---
updated-dependencies:
- dependency-name: com.github.jknack:handlebars
  dependency-version: 4.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-11-10 14:21:26 +00:00
Viren Baraiya 0b48fe9018 Update README.md 2024-07-07 13:49:28 -07:00
Dennis Caldwell ac00735d42 Fix CVEs in 3.16. (#46)
* Upgraded ES7 to 7.17.16, alpine to 3.19

* Update ElasticSearch to 7.17.16, some sdk tests are failing.

* Server would not run, StackOverflow - 54742540 had this handy fix.

* Use the new image in test container.

* Update Spring Boot to 3.2.1. One failing test in end to end.

* Handle the change in exceptions from Spring Framework.

* Update AWS SDK for CVE fix.

* Replace generic import with specific class.

* Removed dependencies.lock file from projects. No longer used.
2024-01-30 14:56:51 -08:00
Viren Baraiya a8f1260105 deployment preparation 2024-01-05 14:13:30 -08:00
c4lm dbbc9a86f1 Merge branch 'main' into community-docs-cleanup-2
# Conflicts:
#	CONTRIBUTING.md
2023-12-22 02:35:11 +04:00
c4lm 9d584168fe cleanup docs 2023-12-21 23:28:28 +04:00
Viren Baraiya 83b7eef9b3 fix typo 2023-12-20 11:41:30 -08:00
Viren Baraiya 71b2b5731d license header changes 2023-12-20 11:20:22 -08:00
LuisLainez 064b0a6292 Issue/upgrade to spring (#3828)
SB3 upgrades
2023-10-31 09:08:06 -07:00
Jamie DeMichele b88c27d6e0 Allow for an upgrade of log4j2 versions by loosening constraint (#3321)
* Allow for an upgrade of log4j2 versions

* Update lock
2023-01-26 13:43:02 -08:00
Aravindan Ramkumar 0787f8477a authorization for StartWorkflowOperation 2022-10-13 13:55:41 -07:00
dependabot[bot] c306bf8d7c Bump protobuf-java from 3.21.6 to 3.21.7 (#3266)
Bumps [protobuf-java](https://github.com/protocolbuffers/protobuf) from 3.21.6 to 3.21.7.
- [Release notes](https://github.com/protocolbuffers/protobuf/releases)
- [Changelog](https://github.com/protocolbuffers/protobuf/blob/main/generate_changelog.py)
- [Commits](https://github.com/protocolbuffers/protobuf/compare/v3.21.6...v3.21.7)

---
updated-dependencies:
- dependency-name: com.google.protobuf:protobuf-java
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-10-03 14:22:35 -07:00
dependabot[bot] ae06fce952 Bump protobuf-java from 3.21.5 to 3.21.6 (#3247)
Bumps [protobuf-java](https://github.com/protocolbuffers/protobuf) from 3.21.5 to 3.21.6.
- [Release notes](https://github.com/protocolbuffers/protobuf/releases)
- [Changelog](https://github.com/protocolbuffers/protobuf/blob/main/generate_changelog.py)
- [Commits](https://github.com/protocolbuffers/protobuf/compare/v3.21.5...v3.21.6)

---
updated-dependencies:
- dependency-name: com.google.protobuf:protobuf-java
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-09-19 14:23:44 -07:00
dependabot[bot] 52ba7ceaf9 Bump protobuf-java from 3.21.4 to 3.21.5 (#3179)
Bumps [protobuf-java](https://github.com/protocolbuffers/protobuf) from 3.21.4 to 3.21.5.
- [Release notes](https://github.com/protocolbuffers/protobuf/releases)
- [Changelog](https://github.com/protocolbuffers/protobuf/blob/main/generate_changelog.py)
- [Commits](https://github.com/protocolbuffers/protobuf/compare/v3.21.4...v3.21.5)

---
updated-dependencies:
- dependency-name: com.google.protobuf:protobuf-java
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-08-15 22:52:23 -07:00
Anoop Panicker c526c65a73 remove obsolete TODOs and refactor (#3161)
* remove obsolete TODOs and refactor

* spotless

* using mockbean

* Revert "using mockbean"

This reverts commit e1cb9867c78ae7c5884b7212339c9cea56485154.

* revert changes to event processor

* fix tests
2022-08-10 13:12:20 -07:00
jxu-nflx ab14727093 Jxu/cassandra serde (#3144)
CI / build (push) Has been cancelled
CI / build-ui (push) Has been cancelled
* Ignore empty field in json serialization

* Add afterburner module to optimize json serializers and deserializers
2022-08-05 13:09:00 -07:00
dependabot[bot] e93c3ae29d Bump protobuf-java from 3.21.3 to 3.21.4 (#3140)
CI / build (push) Has been cancelled
CI / build-ui (push) Has been cancelled
Bumps [protobuf-java](https://github.com/protocolbuffers/protobuf) from 3.21.3 to 3.21.4.
- [Release notes](https://github.com/protocolbuffers/protobuf/releases)
- [Changelog](https://github.com/protocolbuffers/protobuf/blob/main/generate_changelog.py)
- [Commits](https://github.com/protocolbuffers/protobuf/compare/v3.21.3...v3.21.4)

---
updated-dependencies:
- dependency-name: com.google.protobuf:protobuf-java
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-08-01 14:42:19 -07:00
dependabot[bot] 1a105c97de Bump protobuf-java from 3.21.1 to 3.21.3 (#3128)
Bumps [protobuf-java](https://github.com/protocolbuffers/protobuf) from 3.21.1 to 3.21.3.
- [Release notes](https://github.com/protocolbuffers/protobuf/releases)
- [Changelog](https://github.com/protocolbuffers/protobuf/blob/main/generate_changelog.py)
- [Commits](https://github.com/protocolbuffers/protobuf/compare/v3.21.1...v3.21.3)

---
updated-dependencies:
- dependency-name: com.google.protobuf:protobuf-java
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-07-25 14:10:54 -07:00
Aravindan Ramkumar fe135aa4c5 added junit-vintage-engine and dependency updates 2022-06-30 16:22:54 -07:00
Aravindan Ramkumar 5c906f3407 Merge branch 'main' of github.com:Netflix/conductor into client_requesthandler
# Conflicts:
#	client/dependencies.lock
#	common/dependencies.lock
#	grpc-client/dependencies.lock
#	grpc-server/dependencies.lock
#	rest/dependencies.lock
#	server/dependencies.lock
#	test-harness/dependencies.lock
2022-06-06 09:19:00 -07:00
dependabot[bot] 90b8d8f1e1 Bump protobuf-java from 3.20.1 to 3.21.1 (#3014)
* Bump protobuf-java from 3.20.1 to 3.21.1

Bumps [protobuf-java](https://github.com/protocolbuffers/protobuf) from 3.20.1 to 3.21.1.
- [Release notes](https://github.com/protocolbuffers/protobuf/releases)
- [Changelog](https://github.com/protocolbuffers/protobuf/blob/main/generate_changelog.py)
- [Commits](https://github.com/protocolbuffers/protobuf/compare/v3.20.1...v3.21.1)

---
updated-dependencies:
- dependency-name: com.google.protobuf:protobuf-java
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

* updated locks

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Anoop Panicker <apanicker@netflix.com>
2022-05-31 16:18:23 -07:00
Aravindan Ramkumar a08510db39 dependecy lock update for SB 2.6.7 2022-05-18 09:07:38 -07:00
Peter Lau b78ce49d66 Update logo in README and Swagger UI (#2990)
Also remove duplicated content in README.
2022-05-17 12:42:04 -07:00
Aravindan Ramkumar d0add13ec5 merge main 2022-05-16 15:38:16 -07:00
Anoop Panicker e739c34a81 remove guava from common module;handle exceptions in sweeper 2022-04-26 15:03:20 -07:00
dependabot[bot] b67b139708 Bump protobuf-java from 3.20.0 to 3.20.1
Bumps [protobuf-java](https://github.com/protocolbuffers/protobuf) from 3.20.0 to 3.20.1.
- [Release notes](https://github.com/protocolbuffers/protobuf/releases)
- [Changelog](https://github.com/protocolbuffers/protobuf/blob/main/generate_changelog.py)
- [Commits](https://github.com/protocolbuffers/protobuf/compare/v3.20.0...v3.20.1)

---
updated-dependencies:
- dependency-name: com.google.protobuf:protobuf-java
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-04-25 13:21:48 +00:00
Aravindan Ramkumar b0925acd76 1. added explicit dependency for junit
2. added version override for groovy
2022-04-19 15:02:11 -07:00
Aravindan Ramkumar a40c297533 SB 2.6.6 changes 2022-04-19 14:31:25 -07:00
Anoop Panicker c7ab4fd115 updated dependencies 2022-04-07 13:12:30 -07:00
dependabot[bot] 779edb481a Bump protobuf-java from 3.19.4 to 3.20.0
Bumps [protobuf-java](https://github.com/protocolbuffers/protobuf) from 3.19.4 to 3.20.0.
- [Release notes](https://github.com/protocolbuffers/protobuf/releases)
- [Changelog](https://github.com/protocolbuffers/protobuf/blob/main/generate_changelog.py)
- [Commits](https://github.com/protocolbuffers/protobuf/compare/v3.19.4...v3.20.0)

---
updated-dependencies:
- dependency-name: com.google.protobuf:protobuf-java
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-04-06 17:27:40 +00:00
Aravindan Ramkumar ec1bb60359 dependencies.lock update 2022-03-14 21:58:04 +00:00
dependabot[bot] f38cc0362e Bump guava from 25.1-jre to 31.1-jre
Bumps [guava](https://github.com/google/guava) from 25.1-jre to 31.1-jre.
- [Release notes](https://github.com/google/guava/releases)
- [Commits](https://github.com/google/guava/commits)

---
updated-dependencies:
- dependency-name: com.google.guava:guava
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-03-14 21:58:04 +00:00
jxu-nflx c70a0376bc Add previousStatus filed to WorkflowModel (#2816)
CI / build (push) Has been cancelled
CI / build-ui (push) Has been cancelled
* Add previousStatus filed to WorkflowModel

* Add check to only update previousStatus if status changed

* Update dependency lock files
2022-03-08 16:49:07 -08:00
dependabot[bot] f090c767d0 Bump protobuf-java from 3.5.1 to 3.19.4
Bumps [protobuf-java](https://github.com/protocolbuffers/protobuf) from 3.5.1 to 3.19.4.
- [Release notes](https://github.com/protocolbuffers/protobuf/releases)
- [Changelog](https://github.com/protocolbuffers/protobuf/blob/master/generate_changelog.py)
- [Commits](https://github.com/protocolbuffers/protobuf/compare/v3.5.1...v3.19.4)

---
updated-dependencies:
- dependency-name: com.google.protobuf:protobuf-java
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-03-07 23:21:33 +00:00
dependabot[bot] 2239cacb17 Bump javapoet from 1.11.+ to 1.13.0
Bumps [javapoet](https://github.com/square/javapoet) from 1.11.+ to 1.13.0.
- [Release notes](https://github.com/square/javapoet/releases)
- [Changelog](https://github.com/square/javapoet/blob/master/CHANGELOG.md)
- [Commits](https://github.com/square/javapoet/commits/javapoet-1.13.0)

---
updated-dependencies:
- dependency-name: com.squareup:javapoet
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-03-07 15:20:49 -08:00
Anoop Panicker 6064810bce Merge pull request #2673 from Netflix/dependabot/gradle/com.github.jknack-handlebars-4.3.0
Bump handlebars from 4.0.+ to 4.3.0
2022-03-07 14:30:47 -08:00
Anoop Panicker 6ff240ade2 upgrade log4j to 2.17.1 2022-02-01 13:53:54 -08:00
dependabot[bot] 2ae49f0f04 Bump handlebars from 4.0.+ to 4.3.0
Bumps [handlebars](https://github.com/jknack/handlebars.java) from 4.0.+ to 4.3.0.
- [Release notes](https://github.com/jknack/handlebars.java/releases)
- [Commits](https://github.com/jknack/handlebars.java/commits/v4.3.0)

---
updated-dependencies:
- dependency-name: com.github.jknack:handlebars
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-01-31 17:28:43 +00:00
Aravindan Ramkumar 3e15c77d6b Merge branch 'main' of github.com:Netflix/conductor into gradle_netflixoss_upgrade
# Conflicts:
#	core/src/main/java/com/netflix/conductor/service/AdminServiceImpl.java
2022-01-28 14:58:38 -08:00
Jiaofen Xu c89e78081d Add formatting plugin 2022-01-11 10:09:21 -08:00
Anoop Panicker 83b967a720 updated openapi version to 1.6.+ 2021-12-28 15:01:49 -08:00
Aravindan Ramkumar 71e67c18bf upgraded nebulaoss to 10.4.0 2021-12-20 15:14:08 -08:00
Aravindan Ramkumar 5aebd2c14b upgraded gradle to 7.3.2 2021-12-20 14:57:10 -08:00
Romain c1d68dcbe0 update log4j to 2.17 to avoid DoS vulnerability (#2659)
* update log4j to 2.17 to avoid DoS vulnerability

* generateLock and saveLock

Co-authored-by: romain amichaud <romain.amichaud@exfo.com>
2021-12-20 14:19:28 -08:00
Larry Diamond 8283459938 Performance improvement by replacing StringBuffer with StringBuilder 2021-12-06 14:07:17 -08:00
boney9 080edb6ad3 Fixes #2446 - Move the protogen annotations to local code and make it… (#2575)
* Fixes #2446 - Move the protogen annotations to local code and make it more like a monorepo. `protogen` dependencies are not published in maven central and clients using it will run into jar lookup issues

* Attempt to fix CI issue that seems to because annotations module is published as 11
2021-11-15 16:33:01 -08:00