Update dependency org.jenkins-ci.plugins.workflow:workflow-job to v1295 [SECURITY] #97
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.42
->1295.v395eb_7400005
Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
GitHub Vulnerability Alerts
CVE-2023-32977
Jenkins Pipeline: Job Plugin 1292.v27d8cc3e2602 and earlier does not escape the display name of the build that caused an earlier build to be aborted, when "Do not allow concurrent builds" is set.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to set build display names immediately.
The Jenkins security team is not aware of any plugins that allow the exploitation of this vulnerability, as the build name must be set before the build starts.
Pipeline: Job Plugin 1295.v395eb_7400005 escapes the display name of the build that caused an earlier build to be aborted.
Release Notes
jenkinsci/workflow-job-plugin (org.jenkins-ci.plugins.workflow:workflow-job)
v1295.v395eb_7400005
Compare Source
v1292.v27d8cc3e2602
Compare Source
👷 Changes for plugin developers
📦 Dependency updates
v1289.1291.vb_7c188e7e7df
Compare Source
v1289.vd1c337fd5354
Compare Source
👷 Changes for plugin developers
pipeline-groovy-lib
to test classpath (#340) @basil📦 Dependency updates
v1284.v2fe8ed4573d4
Compare Source
👷 Changes for plugin developers
MemoryCleanupTest
due to INSANE NCDFE (#336) @jglickv1282.ve6d865025906
Compare Source
🐛 Bug fixes
👻 Maintenance
📦 Dependency updates
v1268.v6eb_e2ee1a_85a
Compare Source
👷 Changes for plugin developers
stage
(#325) @jglick📦 Dependency updates
v1254.v3f64639b_11dd
Compare Source
👷 Changes for plugin developers
📦 Dependency updates
v1249.v7d974144cc14
Compare Source
🐛 Bug fixes
NewNodeConsoleNote.annotate
(#300) @jglickv1246.v6110f5347f1f
Compare Source
🐛 Bug fixes
WorkflowRun.doTerm
anddoKill
need to redirect back to the build (#303) @jglick👻 Maintenance
CODEOWNERS
(#299) @jglick📦 Dependency updates
v1239.v71b_b_a_124a_725
Compare Source
🚀 New features and improvements
v1236.vc3a_d1602f439
Compare Source
🚀 New features and improvements
📦 Dependency updates
v1232.v5a_4c994312f1
Compare Source
🚀 New features and improvements
📦 Dependency updates
v1229.vb_7c2419a_b_558
Compare Source
🐛 Bug fixes
Descriptor#bindJSON
notStaplerRequest#bindJSON
(#284) @jglickv1226.v44f718dcfe1f
Compare Source
🚀 New features and improvements
v1207.1209.v69351208a_5a_7
Compare Source
v1207.ve6191ff089f8
Compare Source
👷 Changes for plugin developers
v1206.vc48d96b_930b_2
Compare Source
🚀 New features and improvements
WorkflowRun#isInProgress
topublic
(#278) @jmdesprez📦 Dependency updates
v1203.v7b_7023424efe
Compare Source
🚀 New features and improvements
👻 Maintenance
v1189.va_d37a_e9e4eda_
Compare Source
👷 Changes for plugin developers
📦 Dependency updates
v1186.v8def1a_5f3944
Compare Source
🐛 Bug fixes
FlowExecutionListener.fireResumed
a bit later (#260) @jglickv1182.v60a_e6279b_579
Compare Source
🚀 New features and improvements
v1181.va_25d15548158
Compare Source
🐛 Bug fixes
WorkflowJob.submit
honor overrides ofFlowDefinitionDescriptor.newInstance
(jenkinsci/workflow-job-plugin@a25d155) @yaroslavafenkinv1180.v04c4e75dce43
Compare Source
👷 Changes for plugin developers
📦 Dependency updates
v1174.1176.va_29023983d67
Compare Source
v1174.vdcb_d054cf74a_
Compare Source
🚀 New features and improvements
📝 Documentation updates
v1167.v8fe861b_09ef9
Compare Source
🚀 New features and improvements
🐛 Bug fixes
📦 Dependency updates
🚦 Tests
@ASTTest
which fail whenLibraryDecorator
is present (#208) @jglickv1156.v7539182e7b_d5
Compare Source
🚀 New features and improvements
📦 Dependency updates
👻 Maintenance
v1145.v7f2433caa07f
🚀 New features and improvements
buildCaption
text into single line. (#207) @uhafner👻 Maintenance
Jenkinsfile
(#224) @basil🚦 Tests
reuseForks
(#220) @jglickConfiguration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.