Re: [E] Re: [OpenDaylight TSC] Log4Shell impacts on ODL releases


Chokka, Manoj
 

Hi Daniel,

Since the changes are already done, could you prioritize silicon-SR4 first and then others.

Thank you,

BR, Manoj

On Thu, Jan 20, 2022 at 4:01 PM Robert Varga <nite@...> wrote:
On 20/01/2022 08:26, Daniel de la Rosa wrote:
> Hello Robert

Hey Daniel,

> On Mon, Jan 10, 2022 at 5:42 AM Robert Varga <nite@...
> <mailto:nite@...>> wrote:
>
>     Hello everyone,
>
>     these winter holidays we got a present in the form of Log4Shell, which
>     affects pretty much all artifacts we have ever released.
>
>     As per our release lifecycle rules, this means that:
>
>     - all release trains up to and including Aluminium are past their
>     End of
>     Life and will not be receiving a community-driven release
>
>     - Silicon is currently in its Security Support period past its last
>     scheduled Service Release, hence will receive an unscheduled
>     security-driven SR4 in near future
>
>
> We can review this in the TSC but I think we can release Silicon SR4
> after Phosphorus SR2 and before Sulfur. Thoughts?

Actually, these updates are already pushed out on the branch, i.e.
https://jenkins.opendaylight.org/releng/view/autorelease/job/autorelease-release-silicon-mvn35-openjdk11/537/
should be okay to release.

Regards,
Robert





Join TSC@lists.opendaylight.org to automatically receive all group messages.