From a59bd041e9eb318e1f0f07f0c496ea80e430e7eb Mon Sep 17 00:00:00 2001 From: Tiago Bento Date: Tue, 29 Oct 2024 17:01:37 -0400 Subject: [PATCH 1/4] . --- .../Containerfile | 4 +- .../pom.xml | 57 ++++++++++--------- 2 files changed, 32 insertions(+), 29 deletions(-) diff --git a/packages/dev-deployment-kogito-quarkus-blank-app-image/Containerfile b/packages/dev-deployment-kogito-quarkus-blank-app-image/Containerfile index 9fad06ed812..d593ff44c4f 100644 --- a/packages/dev-deployment-kogito-quarkus-blank-app-image/Containerfile +++ b/packages/dev-deployment-kogito-quarkus-blank-app-image/Containerfile @@ -30,7 +30,7 @@ COPY --chown=$USER_ID:$USER_ID dist-dev/quarkus-app $HOME_PATH/app/ COPY --chown=$USER_ID:$USER_ID dist-dev/settings.xml /tmp/kogito/.m2/settings.xml # Pre-populate local Maven repository for faster startup -RUN ./mvnw clean package -B -nsu --settings /tmp/kogito/.m2/settings.xml -Dmaven.test.skip -Dmaven.repo.local=/tmp/kogito/.m2/repository -Dquarkus.http.non-application-root-path=${ROOT_PATH}/q -Dquarkus.http.root-path=${ROOT_PATH} \ +RUN ./mvnw -Dmaven=3.9.6 clean package -B -nsu --settings /tmp/kogito/.m2/settings.xml -Dmaven.test.skip -Dmaven.repo.local=/tmp/kogito/.m2/repository -Dquarkus.http.non-application-root-path=${ROOT_PATH}/q -Dquarkus.http.root-path=${ROOT_PATH} \ && chgrp -R 0 $HOME_PATH/app && chmod -R g=u $HOME_PATH/app && chgrp -R 0 /tmp/kogito && chmod -R g=u /tmp/kogito && chgrp -R 0 /.m2 && chmod -R g=u /.m2 USER $USER_ID @@ -39,4 +39,4 @@ EXPOSE 8080 ENTRYPOINT ["/bin/bash", "-c"] -CMD ["dev-deployment-upload-service && cp -r $HOME_PATH/app/. /tmp/app && cd /tmp/app && ./mvnw quarkus:dev -o -s=/tmp/kogito/.m2/settings.xml -Dquarkus.analytics.disabled=true -Ddebug=false -Dmaven.repo.local=/tmp/kogito/.m2/repository -Dquarkus.http.non-application-root-path=${ROOT_PATH}/q -Dquarkus.http.root-path=${ROOT_PATH}"] +CMD ["dev-deployment-upload-service && cp -r $HOME_PATH/app/. /tmp/app && cd /tmp/app && ./mvnw -Dmaven=3.9.6 quarkus:dev -o -s=/tmp/kogito/.m2/settings.xml -Dquarkus.analytics.disabled=true -Ddebug=false -Dmaven.repo.local=/tmp/kogito/.m2/repository -Dquarkus.http.non-application-root-path=${ROOT_PATH}/q -Dquarkus.http.root-path=${ROOT_PATH}"] diff --git a/packages/dev-deployment-kogito-quarkus-blank-app/pom.xml b/packages/dev-deployment-kogito-quarkus-blank-app/pom.xml index b2f9abac4cd..ffaa583a7d1 100644 --- a/packages/dev-deployment-kogito-quarkus-blank-app/pom.xml +++ b/packages/dev-deployment-kogito-quarkus-blank-app/pom.xml @@ -25,11 +25,8 @@ - - org.apache - apache - 32 - + + 4.0.0 org.kie.kogito @@ -47,7 +44,7 @@ 3.4.1 3.13.0 - 3.2.0 + 3.3.1 3.0.0-M7 3.5.0 3.1.3 @@ -55,7 +52,6 @@ 3.12.1 3.6.1 3.4.1 - 3.2.0 3.4.0 1.6.0 @@ -67,6 +63,7 @@ 4.13.2 1.26.1 0.5 + 2.16.1 @@ -214,7 +211,6 @@ - org.apache.maven.plugins maven-site-plugin ${version.maven.site.plugin} @@ -231,24 +227,6 @@ - org.apache.maven.plugins - maven-remote-resources-plugin - ${version.maven.remote.resources.plugin} - - - org.apache.commons - commons-compress - ${version.org.apache.commons.commons-compress} - - - org.iq80.snappy - snappy - ${version.org.iq80.snappy} - - - - - org.apache.maven.plugins maven-jar-plugin ${version.maven.jar.plugin} @@ -260,7 +238,6 @@ - org.apache.maven.plugins maven-surefire-plugin ${version.maven.surefire.plugin} @@ -276,6 +253,32 @@ + + maven-resources-plugin + ${version.maven.resources.plugin} + + + + + commons-io + commons-io + ${version.commons-io} + + + + + maven-compiler-plugin + ${version.maven.compiler.plugin} + + + + + commons-io + commons-io + ${version.commons-io} + + + From bc2be1d619872f14612d3db233d6fe73fc85887c Mon Sep 17 00:00:00 2001 From: Alex Porcelli Date: Wed, 30 Oct 2024 12:08:07 -0400 Subject: [PATCH 2/4] KIE-ISSUES#1594: bumping protobuf (fix CVE) --- .../dev-deployment-kogito-quarkus-blank-app/pom.xml | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/packages/dev-deployment-kogito-quarkus-blank-app/pom.xml b/packages/dev-deployment-kogito-quarkus-blank-app/pom.xml index ffaa583a7d1..7c0a83a4420 100644 --- a/packages/dev-deployment-kogito-quarkus-blank-app/pom.xml +++ b/packages/dev-deployment-kogito-quarkus-blank-app/pom.xml @@ -64,6 +64,7 @@ 1.26.1 0.5 2.16.1 + 3.25.5 @@ -91,6 +92,16 @@ + + com.google.protobuf + protobuf-java + ${version.com.google.protobuf} + + + com.google.protobuf + protobuf-java-util + ${version.com.google.protobuf} + org.apache.commons commons-compress From fa44334030e975baa8e1a15c25b9d88221524930 Mon Sep 17 00:00:00 2001 From: Alex Porcelli Date: Wed, 30 Oct 2024 13:00:09 -0400 Subject: [PATCH 3/4] KIE-ISSUES#1594: adding repo info + comments --- .../pom.xml | 24 +++++++++++++++++++ 1 file changed, 24 insertions(+) diff --git a/packages/dev-deployment-kogito-quarkus-blank-app/pom.xml b/packages/dev-deployment-kogito-quarkus-blank-app/pom.xml index 7c0a83a4420..dd7d6ae4844 100644 --- a/packages/dev-deployment-kogito-quarkus-blank-app/pom.xml +++ b/packages/dev-deployment-kogito-quarkus-blank-app/pom.xml @@ -92,6 +92,8 @@ + + com.google.protobuf protobuf-java @@ -350,4 +352,26 @@ + + + + apache.snapshots + Apache Snapshot Repository + https://repository.apache.org/snapshots + + false + + + + + + apache.snapshots + Apache Snapshot Repository + https://repository.apache.org/snapshots + + false + + + + From 890e98e51703137fe819ba1aab69c6c6dddb4c7d Mon Sep 17 00:00:00 2001 From: Alex Porcelli Date: Wed, 30 Oct 2024 13:34:00 -0400 Subject: [PATCH 4/4] ops --- .../pom.xml | 38 +++++++++---------- 1 file changed, 18 insertions(+), 20 deletions(-) diff --git a/packages/dev-deployment-kogito-quarkus-blank-app/pom.xml b/packages/dev-deployment-kogito-quarkus-blank-app/pom.xml index dd7d6ae4844..0708db7b997 100644 --- a/packages/dev-deployment-kogito-quarkus-blank-app/pom.xml +++ b/packages/dev-deployment-kogito-quarkus-blank-app/pom.xml @@ -353,25 +353,23 @@ - - - apache.snapshots - Apache Snapshot Repository - https://repository.apache.org/snapshots - - false - - - - - - apache.snapshots - Apache Snapshot Repository - https://repository.apache.org/snapshots - - false - - - + + apache.snapshots + Apache Snapshot Repository + https://repository.apache.org/snapshots + + false + + + + + apache.snapshots + Apache Snapshot Repository + https://repository.apache.org/snapshots + + false + + +