Re: Log4Shell impacts on ODL releases


Robert Varga
 

On 20/01/2022 08:26, Daniel de la Rosa wrote:
Hello Robert
Hey Daniel,

On Mon, Jan 10, 2022 at 5:42 AM Robert Varga <nite@... <mailto:nite@...>> wrote:
Hello everyone,
these winter holidays we got a present in the form of Log4Shell, which
affects pretty much all artifacts we have ever released.
As per our release lifecycle rules, this means that:
- all release trains up to and including Aluminium are past their
End of
Life and will not be receiving a community-driven release
- Silicon is currently in its Security Support period past its last
scheduled Service Release, hence will receive an unscheduled
security-driven SR4 in near future
We can review this in the TSC but I think we can releaseĀ Silicon SR4 after Phosphorus SR2 and beforeĀ Sulfur. Thoughts?
Actually, these updates are already pushed out on the branch, i.e. https://jenkins.opendaylight.org/releng/view/autorelease/job/autorelease-release-silicon-mvn35-openjdk11/537/ should be okay to release.

Regards,
Robert

Join TSC@lists.opendaylight.org to automatically receive all group messages.