Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@ All notable changes to this project will be documented in this file.
- stats-exporter: Add `0.31.0` ([#1664]).
- airflow: Add `3.3.1`, deprecate `3.2.2` ([#1665]).
- opensearch: Add `3.8.0` ([#1669]).
- opensearch: Add the `repository-azure` plugin ([#1689]).
- opensearch-dashboards: Add `3.8.0` ([#1675]).
- nifi: Ship `QueryNiFiReportingTask` with the image ([#1676]).
- nifi: Add `2.12.0` ([#1667]).
Expand Down Expand Up @@ -120,6 +121,7 @@ All notable changes to this project will be documented in this file.
[#1680]: https://github.com/stackabletech/docker-images/pull/1680
[#1681]: https://github.com/stackabletech/docker-images/pull/1681
[#1683]: https://github.com/stackabletech/docker-images/pull/1683
[#1689]: https://github.com/stackabletech/docker-images/pull/1689

## [26.7.0] - 2026-07-21

Expand Down
1 change: 1 addition & 0 deletions opensearch/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -67,6 +67,7 @@ tar -xzf "artifacts/dist/opensearch-min-${PRODUCT_VERSION}-linux-${ARCH}.tar.gz"
# (stackable/patches/<version>/0005-Scope-CycloneDX-SBOM-to-shipped-components-only.patch)
# to include them in the shippedPlugins list, otherwise their dependencies will
# be missing from the SBOM.
unzip artifacts/core-plugins/repository-azure-${PRODUCT_VERSION}.zip -d /stackable/opensearch-${PRODUCT_VERSION}/plugins/repository-azure/
unzip artifacts/core-plugins/repository-s3-${PRODUCT_VERSION}.zip -d /stackable/opensearch-${PRODUCT_VERSION}/plugins/repository-s3/
mv /stackable/opensearch-${PRODUCT_VERSION}/plugins/repository-s3/config /stackable/opensearch-${PRODUCT_VERSION}/config/repository-s3
unzip artifacts/core-plugins/telemetry-otel-${PRODUCT_VERSION}.zip -d /stackable/opensearch-${PRODUCT_VERSION}/plugins/telemetry-otel/
Expand Down
Original file line number Diff line number Diff line change
@@ -1,19 +1,20 @@
From 7469915d465acd03e09cc6400941b20713e4f4d2 Mon Sep 17 00:00:00 2001
From 12860d8c0cbcbc9019895f09b125cc49cd75fc60 Mon Sep 17 00:00:00 2001
From: dervoeti <lukas.krug@stackable.tech>
Date: Thu, 26 Mar 2026 20:51:26 +0000
Subject: Scope CycloneDX SBOM to shipped components only

Exclude plugin subprojects that are not included in the opensearch-min
distribution from the CycloneDX BOM generation. Only repository-s3 and
telemetry-otel are shipped from the local build. Other plugins like
ingest-attachment (which pulls in tika-core) are not installed in the
Stackable image and should not appear in the runtime SBOM.
distribution from the CycloneDX BOM generation. Only repository-azure,
repository-s3 and telemetry-otel are shipped from the local build. Other
plugins like ingest-attachment (which pulls in tika-core) are not
installed in the Stackable image and should not appear in the runtime
SBOM.
---
build.gradle | 34 ++++++++++++++++++++++++++++++++++
1 file changed, 34 insertions(+)

diff --git a/build.gradle b/build.gradle
index 78a15b418e7..b8cbb13be3d 100644
index 78a15b418e7..1770e1afec9 100644
--- a/build.gradle
+++ b/build.gradle
@@ -78,6 +78,40 @@ allprojects {
Expand All @@ -22,7 +23,7 @@ index 78a15b418e7..b8cbb13be3d 100644
cyclonedxBom {
+ // Only include subprojects that are part of the opensearch-min distribution
+ // (server, libs, modules) plus the core plugins shipped in the Stackable
+ // image (repository-s3 and telemetry-otel). This prevents build-only plugin
+ // image (repository-azure, repository-s3 and telemetry-otel). This prevents build-only plugin
+ // dependencies (e.g. tika-core from ingest-attachment) from appearing in the
+ // runtime SBOM as false positives.
+ // The test framework, the test fixtures, the QA projects and the benchmarks are not
Expand All @@ -35,7 +36,7 @@ index 78a15b418e7..b8cbb13be3d 100644
+ // ends up asserting versions that are not in the image.
+ // Note that :distribution must not be excluded. The launchers and CLI tools under
+ // :distribution:tools are shipped in lib/tools.
+ def shippedPlugins = ['repository-s3', 'telemetry-otel'] as Set
+ def shippedPlugins = ['repository-azure', 'repository-s3', 'telemetry-otel'] as Set
+ skipProjects = subprojects.findAll { sub ->
+ (sub.path.startsWith(':plugins:') && !(sub.name in shippedPlugins)) ||
+ sub.path.startsWith(':example-plugins') ||
Expand Down
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
From 7e1d87238369e4e4546df1dc25a6e6f019122cc6 Mon Sep 17 00:00:00 2001
From 149b20962fba02568a0630576ab569ca29b14fe5 Mon Sep 17 00:00:00 2001
From: Razvan-Daniel Mihai <84674+razvan@users.noreply.github.com>
Date: Mon, 22 Jun 2026 16:46:43 +0200
Subject: Add CycloneDX plugin
Expand All @@ -9,7 +9,7 @@ Subject: Add CycloneDX plugin
2 files changed, 37 insertions(+), 2 deletions(-)

diff --git a/build.gradle b/build.gradle
index 252d1ed553a..dc520b0acf6 100644
index 252d1ed553a..399af9f0625 100644
--- a/build.gradle
+++ b/build.gradle
@@ -59,6 +59,7 @@ plugins {
Expand All @@ -36,10 +36,10 @@ index 252d1ed553a..dc520b0acf6 100644
+
+ // Only include subprojects that are part of the opensearch-min distribution
+ // (server, libs, modules) plus the core plugins shipped in the Stackable
+ // image (repository-s3 and telemetry-otel). This prevents build-only
+ // image (repository-azure, repository-s3 and telemetry-otel). This prevents build-only
+ // dependencies (e.g. tika-core from ingest-attachment, or test fixtures such
+ // as hdfs-fixture) from appearing in the runtime SBOM as false positives.
+ def shippedPlugins = ['repository-s3', 'telemetry-otel'] as Set
+ def shippedPlugins = ['repository-azure', 'repository-s3', 'telemetry-otel'] as Set
+ def isShipped = project.path == ':server' ||
+ project.path.startsWith(':libs:') ||
+ project.path.startsWith(':modules:') ||
Expand Down
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
From da1488197ea92be58b0daffa30e442d93ed2e5f4 Mon Sep 17 00:00:00 2001
From f02d4dca13a435458798f6b62032ff1eb6036034 Mon Sep 17 00:00:00 2001
From: Siegfried Weber <mail@siegfriedweber.net>
Date: Wed, 6 Aug 2025 13:12:12 +0200
Subject: Use the Nexus Build Repo
Expand Down
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
From 52b4fd3f084400a89f4e9acfc62caa2941356809 Mon Sep 17 00:00:00 2001
From a471e40a574b1cdb5d6b4227b12fa6877955dcc2 Mon Sep 17 00:00:00 2001
From: Benedikt Labrenz <benedikt@labrenz.org>
Date: Tue, 2 Sep 2025 12:01:22 +0200
Subject: stop applying formatting plugin
Expand Down Expand Up @@ -30,7 +30,7 @@ index 732e77934b4..47a7c1b1066 100644
// Add support for incubator modules on supported Java versions.
run.jvmArgs += ['--add-modules=jdk.incubator.vector']
diff --git a/build.gradle b/build.gradle
index dc520b0acf6..9c6f1475781 100644
index 399af9f0625..a86e4557f12 100644
--- a/build.gradle
+++ b/build.gradle
@@ -66,7 +66,6 @@ apply from: 'gradle/build-complete.gradle'
Expand Down
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
From 88acf360a467f9dca7c36f0a6c5b0dffe3daeb3c Mon Sep 17 00:00:00 2001
From c3124bcacad46e5be3b28c1a27b110dc3b3bd086 Mon Sep 17 00:00:00 2001
From: Razvan-Daniel Mihai <84674+razvan@users.noreply.github.com>
Date: Mon, 22 Jun 2026 16:46:43 +0200
Subject: Add CycloneDX plugin
Expand All @@ -9,7 +9,7 @@ Subject: Add CycloneDX plugin
2 files changed, 36 insertions(+), 1 deletion(-)

diff --git a/build.gradle b/build.gradle
index 667bc41b438..2546b0344e6 100644
index 667bc41b438..2c6e9684175 100644
--- a/build.gradle
+++ b/build.gradle
@@ -58,6 +58,7 @@ plugins {
Expand All @@ -27,10 +27,10 @@ index 667bc41b438..2546b0344e6 100644
+
+ // Only include subprojects that are part of the opensearch-min distribution
+ // (server, libs, modules) plus the core plugins shipped in the Stackable
+ // image (repository-s3 and telemetry-otel). This prevents build-only
+ // image (repository-azure, repository-s3 and telemetry-otel). This prevents build-only
+ // dependencies (e.g. tika-core from ingest-attachment, or test fixtures such
+ // as hdfs-fixture) from appearing in the runtime SBOM as false positives.
+ def shippedPlugins = ['repository-s3', 'telemetry-otel'] as Set
+ def shippedPlugins = ['repository-azure', 'repository-s3', 'telemetry-otel'] as Set
+ def isShipped = project.path == ':server' ||
+ project.path.startsWith(':libs:') ||
+ project.path.startsWith(':modules:') ||
Expand Down
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
From f73f15cc82915affc3d2b7f6c6902ecddefe3a04 Mon Sep 17 00:00:00 2001
From df70d2fc17390042c8d9cb42f3a084f2e5dcb939 Mon Sep 17 00:00:00 2001
From: Siegfried Weber <mail@siegfriedweber.net>
Date: Wed, 6 Aug 2025 13:12:12 +0200
Subject: Use the Nexus Build Repo
Expand Down
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
From 800e5834414c0adbd5f2ce24f414c7b9d385348b Mon Sep 17 00:00:00 2001
From 3341a03dcabf217b4e16bed3372d1422914f7227 Mon Sep 17 00:00:00 2001
From: Benedikt Labrenz <benedikt@labrenz.org>
Date: Tue, 2 Sep 2025 12:01:22 +0200
Subject: stop applying formatting plugin
Expand Down Expand Up @@ -31,7 +31,7 @@ index 732e77934b4..47a7c1b1066 100644
// Add support for incubator modules on supported Java versions.
run.jvmArgs += ['--add-modules=jdk.incubator.vector']
diff --git a/build.gradle b/build.gradle
index 2546b0344e6..9eadead35f5 100644
index 2c6e9684175..d36f458331b 100644
--- a/build.gradle
+++ b/build.gradle
@@ -65,7 +65,6 @@ apply from: 'gradle/build-complete.gradle'
Expand Down
Loading