diff --git a/CHANGELOG.md b/CHANGELOG.md index 53826469f..6b6e2c1c5 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -33,6 +33,10 @@ All notable changes to this project will be documented in this file. - vector: Build with `--locked` ([#1674]). - nifi: Updated dependencies for `2.6.0` and `2.9.0` ([#1667]). - ci: Bump `stackabletech/actions` to `v0.18.4` ([#1681]). +- java-devel: Pin `versions-maven-plugin` to `2.22.0` for `mvn versions:set`, `maven-help-plugin` to `3.5.2` for `mvn help:evaluate` and `maven-dependency-plugin` to `3.11.0` for `mvn dependency:get`, which otherwise resolve the latest release on every build unless the product POM pins them ([#1682]). +- spark: Remove duplicated arguments from the `mvn dependency:get` calls for `stax2-api` and `woodstox-core` ([#1682]). +- airflow, druid, hbase, nifi, opensearch-dashboards, superset, trino: Install global npm packages (cdxgen, pnpm, yarn, npm) with `--ignore-scripts`, and only resolve versions that were published at least 7 days ago (`--before`) ([#1682]). +- superset: Pin npm to `10.9.9` instead of installing the latest version with `nvm install --latest-npm` ([#1682]). ### Fixed @@ -121,6 +125,7 @@ All notable changes to this project will be documented in this file. [#1677]: https://github.com/stackabletech/docker-images/pull/1677 [#1680]: https://github.com/stackabletech/docker-images/pull/1680 [#1681]: https://github.com/stackabletech/docker-images/pull/1681 +[#1682]: https://github.com/stackabletech/docker-images/pull/1682 [#1683]: https://github.com/stackabletech/docker-images/pull/1683 [#1686]: https://github.com/stackabletech/docker-images/pull/1686 [#1689]: https://github.com/stackabletech/docker-images/pull/1689 diff --git a/airflow/Dockerfile b/airflow/Dockerfile index 87bb30dee..524c73f54 100644 --- a/airflow/Dockerfile +++ b/airflow/Dockerfile @@ -130,7 +130,10 @@ ARCH="${TARGETARCH/amd64/x64}" mkdir -p /opt/node-cdxgen curl "https://repo.stackable.tech/repository/packages/node/node-v${CDXGEN_NODEJS_VERSION}-linux-${ARCH}.tar.xz" | \ tar --extract --xz --directory=/opt/node-cdxgen --strip-components=1 -PATH="/opt/node-cdxgen/bin:$PATH" npm install --global "@cdxgen/cdxgen@${CDXGEN_VERSION}" +# --ignore-scripts keeps the install scripts of (transitive) dependencies from running. +# --before only resolves versions published at least 7 days ago, including the transitive ones, +# so that a freshly published malicious version is not picked up before it is taken down. +PATH="/opt/node-cdxgen/bin:$PATH" npm install --global --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" "@cdxgen/cdxgen@${CDXGEN_VERSION}" EOF COPY airflow/stackable/constraints/${PRODUCT_VERSION}/constraints-python${PYTHON_VERSION}.txt /tmp/constraints.txt @@ -180,7 +183,10 @@ if [ -d "./airflow-core" ]; then # build front-end assets # TODO: Consider making the pnpm version an ARG - npm install -g pnpm@10.18.2 + # --ignore-scripts keeps the install scripts of (transitive) dependencies from running. + # --before only resolves versions published at least 7 days ago, including the transitive ones, + # so that a freshly published malicious version is not picked up before it is taken down. + npm install -g --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" pnpm@10.18.2 pnpm install --frozen-lockfile pnpm run build @@ -212,7 +218,10 @@ else # build front-end assets cd airflow/www # TODO: Consider making the yarn version an ARG - npm install -g yarn@1.22.22 + # --ignore-scripts keeps the install scripts of (transitive) dependencies from running. + # --before only resolves versions published at least 7 days ago, including the transitive ones, + # so that a freshly published malicious version is not picked up before it is taken down. + npm install -g --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" yarn@1.22.22 yarn install --frozen-lockfile yarn run build diff --git a/druid/Dockerfile b/druid/Dockerfile index adbbb6bb0..4ba6e1470 100644 --- a/druid/Dockerfile +++ b/druid/Dockerfile @@ -48,7 +48,10 @@ ARCH="${TARGETARCH/amd64/x64}" mkdir -p /opt/node-cdxgen curl "https://repo.stackable.tech/repository/packages/node/node-v${CDXGEN_NODEJS_VERSION}-linux-${ARCH}.tar.xz" | \ tar --extract --xz --directory=/opt/node-cdxgen --strip-components=1 -PATH="/opt/node-cdxgen/bin:$PATH" npm install --global "@cdxgen/cdxgen@${CDXGEN_VERSION}" +# --ignore-scripts keeps the install scripts of (transitive) dependencies from running. +# --before only resolves versions published at least 7 days ago, including the transitive ones, +# so that a freshly published malicious version is not picked up before it is taken down. +PATH="/opt/node-cdxgen/bin:$PATH" npm install --global --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" "@cdxgen/cdxgen@${CDXGEN_VERSION}" EOF USER ${STACKABLE_USER_UID} @@ -77,10 +80,10 @@ RUN --mount=type=cache,id=maven-${PRODUCT_VERSION},uid=${STACKABLE_USER_UID},tar cd "$(cat /tmp/DRUID_SOURCE_DIR)" || exit 1 rm /tmp/DRUID_SOURCE_DIR -ORIGINAL_VERSION=$(mvn help:evaluate -Dexpression=project.version -q -DforceStdout) +ORIGINAL_VERSION=$(mvn "org.apache.maven.plugins:maven-help-plugin:${HELP_MAVEN_PLUGIN_VERSION}:evaluate" -Dexpression=project.version -q -DforceStdout) NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}" -mvn versions:set -DnewVersion=$NEW_VERSION +mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION # Make Maven aware of custom Stackable libraries cp -r /stackable/patched-libs/maven/* /stackable/.m2/repository diff --git a/hadoop/hadoop/Dockerfile b/hadoop/hadoop/Dockerfile index d8208e8db..0423365bb 100644 --- a/hadoop/hadoop/Dockerfile +++ b/hadoop/hadoop/Dockerfile @@ -80,10 +80,10 @@ USER ${STACKABLE_USER_UID} RUN <hadoop-pipes<\/artifactId>/,/<\/dependency>/ { s/.*<\/version>/'"$ORIGINAL_VERSION"'<\/version>/ }' -i hadoop-tools/hadoop-tools-dist/pom.xml diff --git a/hbase/hbase-operator-tools/Dockerfile b/hbase/hbase-operator-tools/Dockerfile index 62e487346..f7487c070 100644 --- a/hbase/hbase-operator-tools/Dockerfile +++ b/hbase/hbase-operator-tools/Dockerfile @@ -41,12 +41,12 @@ cd "$(/stackable/patchable --images-repo-root=src checkout hbase/hbase-operator- # Make Maven aware of custom Stackable libraries cp -r /stackable/patched-libs/maven/* /stackable/.m2/repository -ORIGINAL_VERSION=$(mvn help:evaluate -Dexpression=project.version -q -DforceStdout) +ORIGINAL_VERSION=$(mvn "org.apache.maven.plugins:maven-help-plugin:${HELP_MAVEN_PLUGIN_VERSION}:evaluate" -Dexpression=project.version -q -DforceStdout) NEW_VERSION="${HBASE_OPERATOR_TOOLS_VERSION}-stackable${RELEASE_VERSION}" FULL_HBASE_OPERATOR_TOOLS_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}" # This includes the HBase version and the Stackable release suffix PATCHED_HBASE_VERSION="${HBASE_VERSION}-stackable${RELEASE_VERSION}" -mvn versions:set -DnewVersion=$NEW_VERSION +mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION # Create snapshot of the source code including custom patches tar -czf /stackable/hbase-operator-tools-${FULL_HBASE_OPERATOR_TOOLS_VERSION}-src.tar.gz . diff --git a/hbase/hbase/Dockerfile b/hbase/hbase/Dockerfile index 899accc9e..605a80bea 100644 --- a/hbase/hbase/Dockerfile +++ b/hbase/hbase/Dockerfile @@ -32,7 +32,10 @@ ARCH="${TARGETARCH/amd64/x64}" mkdir -p /opt/node-cdxgen curl "https://repo.stackable.tech/repository/packages/node/node-v${CDXGEN_NODEJS_VERSION}-linux-${ARCH}.tar.xz" | \ tar --extract --xz --directory=/opt/node-cdxgen --strip-components=1 -PATH="/opt/node-cdxgen/bin:$PATH" npm install --global "@cdxgen/cdxgen@${CDXGEN_VERSION}" +# --ignore-scripts keeps the install scripts of (transitive) dependencies from running. +# --before only resolves versions published at least 7 days ago, including the transitive ones, +# so that a freshly published malicious version is not picked up before it is taken down. +PATH="/opt/node-cdxgen/bin:$PATH" npm install --global --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" "@cdxgen/cdxgen@${CDXGEN_VERSION}" microdnf update microdnf install python3 @@ -67,10 +70,10 @@ cd "$(/stackable/patchable --images-repo-root=src checkout hbase/hbase ${PRODUCT # Make Maven aware of custom Stackable libraries cp -r /stackable/patched-libs/maven/* /stackable/.m2/repository -ORIGINAL_VERSION=$(mvn help:evaluate -Dexpression=project.version -q -DforceStdout) +ORIGINAL_VERSION=$(mvn "org.apache.maven.plugins:maven-help-plugin:${HELP_MAVEN_PLUGIN_VERSION}:evaluate" -Dexpression=project.version -q -DforceStdout) NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}" -mvn versions:set -DnewVersion=$NEW_VERSION +mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION # Create snapshot of the source code including custom patches tar -czf /stackable/hbase-${NEW_VERSION}-src.tar.gz . diff --git a/hbase/phoenix/Dockerfile b/hbase/phoenix/Dockerfile index 468f5a43c..3dc2f40b6 100644 --- a/hbase/phoenix/Dockerfile +++ b/hbase/phoenix/Dockerfile @@ -35,10 +35,10 @@ cp -r /stackable/patched-libs/maven/* /stackable/.m2/repository cd "$(/stackable/patchable --images-repo-root=src checkout phoenix ${PHOENIX_VERSION})" -ORIGINAL_VERSION=$(mvn help:evaluate -Dexpression=project.version -q -DforceStdout) +ORIGINAL_VERSION=$(mvn "org.apache.maven.plugins:maven-help-plugin:${HELP_MAVEN_PLUGIN_VERSION}:evaluate" -Dexpression=project.version -q -DforceStdout) NEW_VERSION="${PHOENIX_VERSION}-stackable${RELEASE_VERSION}" -mvn versions:set -DnewVersion=$NEW_VERSION +mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION # Create snapshot of the source code including custom patches tar -czf /stackable/phoenix-${PRODUCT_VERSION}-stackable${RELEASE_VERSION}-src.tar.gz . diff --git a/hive/Dockerfile b/hive/Dockerfile index ee1398ab7..2e22ac19e 100644 --- a/hive/Dockerfile +++ b/hive/Dockerfile @@ -54,7 +54,7 @@ cd "$BUILD_SRC_DIR" cp -r /stackable/patched-libs/maven/* /stackable/.m2/repository # generateBackupPoms=false is needed for the Hive 4.0.0 build to succeed, otherwise it fails with the obscure reason: `Too many files with unapproved license` -mvn versions:set -DnewVersion=$NEW_VERSION -DartifactId=* -DgroupId=* -DgenerateBackupPoms=false +mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION -DartifactId=* -DgroupId=* -DgenerateBackupPoms=false # Create snapshot of the source code including custom patches tar -czf /stackable/hive-${NEW_VERSION}-src.tar.gz . diff --git a/hive/hive-metastore-opa-authorizer/Dockerfile b/hive/hive-metastore-opa-authorizer/Dockerfile index 63e2f95ae..32259e761 100644 --- a/hive/hive-metastore-opa-authorizer/Dockerfile +++ b/hive/hive-metastore-opa-authorizer/Dockerfile @@ -41,7 +41,7 @@ tar -czf /stackable/opa-authorizer-src/hive-metastore-opa-authorizer-${AUTHORIZE cp -r /stackable/patched-libs/maven/* /stackable/.m2/repository # Set version -mvn versions:set -DnewVersion=${AUTHORIZER_VERSION} +mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=${AUTHORIZER_VERSION} # The if part can be removed once we do no longer support Hive 3.x.x # Hive 3.1.3 only works with the shaded jar diff --git a/java-devel/Dockerfile b/java-devel/Dockerfile index 3530f6568..9d267e7c5 100644 --- a/java-devel/Dockerfile +++ b/java-devel/Dockerfile @@ -68,6 +68,18 @@ EOF ENV JAVA_HOME="/usr/lib/jvm/temurin-${PRODUCT_VERSION}-jdk" ENV MAVEN_ARGS="--batch-mode --no-transfer-progress" +# Plugins that are invoked by prefix on the command line (e.g. `mvn versions:set`) resolve to their +# latest release unless the project POM pins them, so their version would change silently between builds. +# Find the latest version here: https://github.com/mojohaus/versions/releases +# renovate: datasource=maven packageName=org.codehaus.mojo:versions-maven-plugin +ENV VERSIONS_MAVEN_PLUGIN_VERSION=2.22.0 +# Find the latest version here: https://github.com/apache/maven-help-plugin/releases +# renovate: datasource=maven packageName=org.apache.maven.plugins:maven-help-plugin +ENV HELP_MAVEN_PLUGIN_VERSION=3.5.2 +# Find the latest version here: https://github.com/apache/maven-dependency-plugin/releases +# renovate: datasource=maven packageName=org.apache.maven.plugins:maven-dependency-plugin +ENV DEPENDENCY_MAVEN_PLUGIN_VERSION=3.11.0 + ARG GITHUB_RUN_ATTEMPT="" ENV GITHUB_RUN_ATTEMPT=${GITHUB_RUN_ATTEMPT} diff --git a/nifi/Dockerfile b/nifi/Dockerfile index 06e133a24..fa5dcc69a 100644 --- a/nifi/Dockerfile +++ b/nifi/Dockerfile @@ -32,7 +32,10 @@ ARCH="${TARGETARCH/amd64/x64}" mkdir -p /opt/node-cdxgen curl "https://repo.stackable.tech/repository/packages/node/node-v${CDXGEN_NODEJS_VERSION}-linux-${ARCH}.tar.xz" | \ tar --extract --xz --directory=/opt/node-cdxgen --strip-components=1 -PATH="/opt/node-cdxgen/bin:$PATH" npm install --global "@cdxgen/cdxgen@${CDXGEN_VERSION}" +# --ignore-scripts keeps the install scripts of (transitive) dependencies from running. +# --before only resolves versions published at least 7 days ago, including the transitive ones, +# so that a freshly published malicious version is not picked up before it is taken down. +PATH="/opt/node-cdxgen/bin:$PATH" npm install --global --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" "@cdxgen/cdxgen@${CDXGEN_VERSION}" EOF USER ${STACKABLE_USER_UID} @@ -53,10 +56,10 @@ curl 'https://repo.stackable.tech/repository/m2/tech/stackable/nifi/stackable-bc cd "$(/stackable/patchable --images-repo-root=src checkout nifi ${PRODUCT_VERSION})" -ORIGINAL_VERSION=$(mvn help:evaluate -Dexpression=project.version -q -DforceStdout) +ORIGINAL_VERSION=$(mvn "org.apache.maven.plugins:maven-help-plugin:${HELP_MAVEN_PLUGIN_VERSION}:evaluate" -Dexpression=project.version -q -DforceStdout) NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}" -mvn versions:set -DnewVersion=$NEW_VERSION +mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION # Create snapshot of the source code including custom patches tar -czf /stackable/nifi-${NEW_VERSION}-src.tar.gz . diff --git a/omid/Dockerfile b/omid/Dockerfile index af261ca7d..7d9ea7ed4 100644 --- a/omid/Dockerfile +++ b/omid/Dockerfile @@ -29,10 +29,10 @@ RUN --mount=type=cache,id=maven-omid-${PRODUCT_VERSION},uid=${STACKABLE_USER_UID set -x cd "$(/stackable/patchable --images-repo-root=src checkout omid ${PRODUCT_VERSION})" - ORIGINAL_VERSION=$(mvn help:evaluate -Dexpression=project.version -q -DforceStdout) + ORIGINAL_VERSION=$(mvn "org.apache.maven.plugins:maven-help-plugin:${HELP_MAVEN_PLUGIN_VERSION}:evaluate" -Dexpression=project.version -q -DforceStdout) NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}" - mvn versions:set -DnewVersion=$NEW_VERSION + mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION # Create snapshot of the source code including custom patches tar -czf /stackable/omid-${NEW_VERSION}-src.tar.gz . diff --git a/opensearch-dashboards/Dockerfile b/opensearch-dashboards/Dockerfile index 0f258802c..e5912d930 100644 --- a/opensearch-dashboards/Dockerfile +++ b/opensearch-dashboards/Dockerfile @@ -141,7 +141,10 @@ microdnf clean all rm -rf /var/cache/yum curl "https://repo.stackable.tech/repository/packages/node/node-v${NODEJS_VERSION}-linux-${ARCH}.tar.xz" | \ tar --extract --xz --directory=/usr/local --strip-components=1 -npm install -g yarn@${YARN_VERSION} +# --ignore-scripts keeps the install scripts of (transitive) dependencies from running. +# --before only resolves versions published at least 7 days ago, including the transitive ones, +# so that a freshly published malicious version is not picked up before it is taken down. +npm install -g --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" yarn@${YARN_VERSION} # cdxgen requires Node >= 24, which is newer than the Node version OpenSearch Dashboards # is built with, so it gets its own Node installation in /opt/node-cdxgen and is invoked @@ -150,7 +153,10 @@ npm install -g yarn@${YARN_VERSION} mkdir -p /opt/node-cdxgen curl "https://repo.stackable.tech/repository/packages/node/node-v${CDXGEN_NODEJS_VERSION}-linux-${ARCH}.tar.xz" | \ tar --extract --xz --directory=/opt/node-cdxgen --strip-components=1 -PATH="/opt/node-cdxgen/bin:$PATH" npm install --global "@cdxgen/cdxgen@${CDXGEN_VERSION}" +# --ignore-scripts keeps the install scripts of (transitive) dependencies from running. +# --before only resolves versions published at least 7 days ago, including the transitive ones, +# so that a freshly published malicious version is not picked up before it is taken down. +PATH="/opt/node-cdxgen/bin:$PATH" npm install --global --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" "@cdxgen/cdxgen@${CDXGEN_VERSION}" EOF USER ${STACKABLE_USER_UID} diff --git a/precompiled/hadoop/Dockerfile b/precompiled/hadoop/Dockerfile index 396d20297..71450f18f 100644 --- a/precompiled/hadoop/Dockerfile +++ b/precompiled/hadoop/Dockerfile @@ -58,10 +58,10 @@ USER ${STACKABLE_USER_UID} RUN <hadoop-pipes<\/artifactId>/,/<\/dependency>/ { s/.*<\/version>/'"$ORIGINAL_VERSION"'<\/version>/ }' -i hadoop-tools/hadoop-tools-dist/pom.xml diff --git a/spark-k8s/Dockerfile.3 b/spark-k8s/Dockerfile.3 index ade35e6c9..808efef0b 100644 --- a/spark-k8s/Dockerfile.3 +++ b/spark-k8s/Dockerfile.3 @@ -24,7 +24,7 @@ cd "$(/stackable/patchable --images-repo-root=src checkout spark-k8s ${PRODUCT_V NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}" -mvn versions:set -DnewVersion=$NEW_VERSION +mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION # Create snapshot of the source code including custom patches tar -czf /stackable/spark-${PRODUCT_VERSION}-stackable${RELEASE_VERSION}-src.tar.gz . @@ -166,15 +166,15 @@ WORKDIR /stackable/spark-${PRODUCT_VERSION}-stackable${RELEASE_VERSION}/dist/ext RUN <=22.9.0. +npm-version = "10.9.9" # Independent of Superset, use the latest release: https://github.com/nvm-sh/nvm/releases nvm-version = "v0.40.4" @@ -58,5 +60,8 @@ python-version = "3.12" uv-version = "0.11.18" # https://github.com/apache/superset/blob/6.1.0/superset-frontend/.nvmrc nodejs-version = "22.22.0" +# superset-frontend requires npm ^10.8.1 (https://github.com/apache/superset/blob/6.1.0/superset-frontend/package.json, +# search for `"engines"`). The latest 10.x release. +npm-version = "10.9.9" # Independent of Superset, use the latest release: https://github.com/nvm-sh/nvm/releases nvm-version = "v0.40.4" diff --git a/trino/airlift/Dockerfile b/trino/airlift/Dockerfile index 1858a032a..f27e66a9d 100644 --- a/trino/airlift/Dockerfile +++ b/trino/airlift/Dockerfile @@ -21,7 +21,7 @@ cd "$(/stackable/patchable --images-repo-root=src checkout trino/airlift ${PRODU NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}" -mvn versions:set -DnewVersion=$NEW_VERSION -DartifactId='*' -DgroupId='*' -DgenerateBackupPoms=false +mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION -DartifactId='*' -DgroupId='*' -DgenerateBackupPoms=false mvn \ install \ diff --git a/trino/storage-connector/Dockerfile b/trino/storage-connector/Dockerfile index 0156405e6..9a0bcd851 100644 --- a/trino/storage-connector/Dockerfile +++ b/trino/storage-connector/Dockerfile @@ -30,7 +30,7 @@ NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}" # Create snapshot of the source code including custom patches tar -czf /stackable/trino-storage-connector-${NEW_VERSION}-src.tar.gz . -mvn versions:set -DnewVersion=${NEW_VERSION} +mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=${NEW_VERSION} mvn \ package \ diff --git a/trino/trino/Dockerfile b/trino/trino/Dockerfile index 1e234adc3..10bca7fa2 100644 --- a/trino/trino/Dockerfile +++ b/trino/trino/Dockerfile @@ -30,7 +30,10 @@ ARCH="${TARGETARCH/amd64/x64}" mkdir -p /opt/node-cdxgen curl "https://repo.stackable.tech/repository/packages/node/node-v${CDXGEN_NODEJS_VERSION}-linux-${ARCH}.tar.xz" | \ tar --extract --xz --directory=/opt/node-cdxgen --strip-components=1 -PATH="/opt/node-cdxgen/bin:$PATH" npm install --global "@cdxgen/cdxgen@${CDXGEN_VERSION}" +# --ignore-scripts keeps the install scripts of (transitive) dependencies from running. +# --before only resolves versions published at least 7 days ago, including the transitive ones, +# so that a freshly published malicious version is not picked up before it is taken down. +PATH="/opt/node-cdxgen/bin:$PATH" npm install --global --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" "@cdxgen/cdxgen@${CDXGEN_VERSION}" microdnf update microdnf install python3 @@ -51,7 +54,7 @@ cp -r /stackable/patched-libs/maven/* /root/.m2/repository NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}" -mvn versions:set -DnewVersion=$NEW_VERSION +mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION # Create snapshot of the source code including custom patches tar -czf /stackable/trino-${NEW_VERSION}-src.tar.gz . diff --git a/zookeeper/Dockerfile b/zookeeper/Dockerfile index e0ed9e4a1..a844a5569 100644 --- a/zookeeper/Dockerfile +++ b/zookeeper/Dockerfile @@ -30,10 +30,10 @@ cp -r /stackable/patched-logback-libs/* /stackable/.m2/repository cd "$(/stackable/patchable --images-repo-root=src checkout zookeeper ${PRODUCT_VERSION})" -ORIGINAL_VERSION=$(mvn help:evaluate -Dexpression=project.version -q -DforceStdout) +ORIGINAL_VERSION=$(mvn "org.apache.maven.plugins:maven-help-plugin:${HELP_MAVEN_PLUGIN_VERSION}:evaluate" -Dexpression=project.version -q -DforceStdout) NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}" -mvn versions:set -DnewVersion=$NEW_VERSION +mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION # Create snapshot of the source code including custom patches tar -czf /stackable/zookeeper-${NEW_VERSION}-src.tar.gz .