Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
54 changes: 29 additions & 25 deletions .github/workflows/security-release-gate.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@ jobs:
- name: Check out candidate
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ inputs.release_ref || github.sha }}
ref: ${{ inputs.release_ref || github.event.pull_request.head.sha || github.sha }}
fetch-depth: 0
persist-credentials: false

Expand Down Expand Up @@ -70,7 +70,7 @@ jobs:
test -z "$(git status --porcelain)"
if [[ -n "$RELEASE_REF" ]]; then
test "$GITHUB_EVENT_NAME" = workflow_dispatch
[[ "$RELEASE_REF" =~ ^v5\.7\.4$ ]]
[[ "$RELEASE_REF" =~ ^v5\.7\.5$ ]]
test "$(git cat-file -t "$RELEASE_REF")" = tag
test "$(git rev-parse HEAD)" = "$(git rev-parse "${RELEASE_REF}^{commit}")"
fi
Expand All @@ -95,7 +95,9 @@ jobs:
shell: bash
run: |
set -euo pipefail
core_tests='com.hazelcast.aws.AwsMetadataApiTest,com.hazelcast.azure.TagTest,com.hazelcast.config.XmlSchemaSourceSecurityTest,com.hazelcast.console.ConsoleAppTest,com.hazelcast.core.server.HazelcastMemberStarterTest,com.hazelcast.dataconnection.impl.JdbcDataConnectionTest,com.hazelcast.dataconnection.impl.JdbcUrlPolicyTest,com.hazelcast.dataconnection.impl.hazelcastdataconnection.HazelcastDataConnectionConfigLoaderTest,com.hazelcast.dataconnection.impl.jdbcproperties.HikariTranslatorTest,com.hazelcast.flakeidgen.impl.FlakeIdGeneratorProxyTest,com.hazelcast.gcp.LabelTest,com.hazelcast.gcp.UtilsTest,com.hazelcast.internal.config.ConfigLoaderSecurityTest,com.hazelcast.internal.diagnostics.DiagnosticsLogFileTest,com.hazelcast.internal.serialization.impl.ByteArrayObjectDataIntegrationTest,com.hazelcast.internal.serialization.impl.ObjectDataInputStreamIntegrationTest,com.hazelcast.internal.serialization.impl.UnsafeObjectDataInputIntegrationTest,com.hazelcast.internal.util.ClockTest,com.hazelcast.internal.util.HashUtilTest,com.hazelcast.internal.util.SecureFileAccessTest,com.hazelcast.internal.util.collection.LongHashSetTest,com.hazelcast.internal.util.concurrent.BackoffIdleStrategyTest,com.hazelcast.internal.util.phonehome.PhoneHomeDifferentConfigTest,com.hazelcast.internal.util.phonehome.PhoneHomeIntegrationTest,com.hazelcast.internal.util.XmlUtilTest,com.hazelcast.jet.impl.submitjob.memberside.JobUploadStatusTest,com.hazelcast.jet.impl.submitjob.memberside.validator.JarOnClientValidatorTest,com.hazelcast.jet.retry.impl.IntervalFunctionTest,com.hazelcast.kubernetes.KubernetesApiOriginPolicyTest,com.hazelcast.kubernetes.KubernetesConfigTest,com.hazelcast.spi.discovery.multicast.MulticastDiscoveryStrategyTest,com.hazelcast.spi.utils.RestClientTest,com.hazelcast.spi.utils.RetryUtilsTest'
scripts/pasturestack-build-runtime preflight
python scripts/test-pasturestack-jackson-release.py -v
core_tests='com.hazelcast.aws.AwsMetadataApiTest,com.hazelcast.azure.TagTest,com.hazelcast.config.XmlSchemaSourceSecurityTest,com.hazelcast.console.ConsoleAppTest,com.hazelcast.core.server.HazelcastMemberStarterTest,com.hazelcast.dataconnection.impl.JdbcDataConnectionTest,com.hazelcast.dataconnection.impl.JdbcUrlPolicyTest,com.hazelcast.dataconnection.impl.hazelcastdataconnection.HazelcastDataConnectionConfigLoaderTest,com.hazelcast.dataconnection.impl.jdbcproperties.HikariTranslatorTest,com.hazelcast.flakeidgen.impl.FlakeIdGeneratorProxyTest,com.hazelcast.gcp.LabelTest,com.hazelcast.gcp.UtilsTest,com.hazelcast.internal.config.ConfigLoaderSecurityTest,com.hazelcast.internal.diagnostics.DiagnosticsLogFileTest,com.hazelcast.internal.serialization.impl.ByteArrayObjectDataIntegrationTest,com.hazelcast.internal.serialization.impl.ObjectDataInputStreamIntegrationTest,com.hazelcast.internal.serialization.impl.UnsafeObjectDataInputIntegrationTest,com.hazelcast.internal.util.ClockTest,com.hazelcast.internal.util.HashUtilTest,com.hazelcast.internal.util.SecureFileAccessTest,com.hazelcast.internal.util.collection.LongHashSetTest,com.hazelcast.internal.util.concurrent.BackoffIdleStrategyTest,com.hazelcast.internal.util.phonehome.PhoneHomeDifferentConfigTest,com.hazelcast.internal.util.phonehome.PhoneHomeIntegrationTest,com.hazelcast.internal.util.XmlUtilTest,com.hazelcast.jet.impl.submitjob.memberside.JobUploadStatusTest,com.hazelcast.jet.impl.submitjob.memberside.validator.JarOnClientValidatorTest,com.hazelcast.jet.impl.util.JsonUtilTest,com.hazelcast.jet.json.impl.JsonUtilImplTest,com.hazelcast.jet.retry.impl.IntervalFunctionTest,com.hazelcast.kubernetes.KubernetesApiOriginPolicyTest,com.hazelcast.kubernetes.KubernetesConfigTest,com.hazelcast.spi.discovery.multicast.MulticastDiscoveryStrategyTest,com.hazelcast.spi.utils.RestClientTest,com.hazelcast.spi.utils.RetryUtilsTest'
all_tests="$core_tests,com.hazelcast.jet.sql.impl.parse.QueryParserTest,com.hazelcast.buildutils.ExportPackageViewerTest,com.hazelcast.jet.cdc.OperationTest"
timeout --signal=TERM --kill-after=30s 30m ./mvnw -B \
-pl hazelcast,hazelcast-sql,hazelcast-build-utils,extensions/cdc-debezium,extensions/mongodb \
Expand Down Expand Up @@ -156,6 +158,8 @@ jobs:
com.hazelcast.jet.impl.deployment.ProcessorClassLoaderTest
com.hazelcast.jet.impl.submitjob.memberside.JobUploadStatusTest
com.hazelcast.jet.impl.submitjob.memberside.validator.JarOnClientValidatorTest
com.hazelcast.jet.impl.util.JsonUtilTest
com.hazelcast.jet.json.impl.JsonUtilImplTest
com.hazelcast.jet.retry.impl.IntervalFunctionTest
com.hazelcast.kubernetes.KubernetesApiOriginPolicyTest
com.hazelcast.kubernetes.KubernetesConfigTest
Expand Down Expand Up @@ -205,10 +209,10 @@ jobs:
run: |
set -euo pipefail
PASTURESTACK_OUTPUT_DIR=dist scripts/pasturestack-build-runtime
test -s dist/hazelcast-5.7.4.jar
sha256sum dist/hazelcast-5.7.4.jar | tee evidence/hazelcast-5.7.4.jar.sha256
jar tf dist/hazelcast-5.7.4.jar | grep -Fxq META-INF/LICENSE
jar tf dist/hazelcast-5.7.4.jar | grep -Fxq META-INF/NOTICE
test -s dist/hazelcast-5.7.5.jar
sha256sum dist/hazelcast-5.7.5.jar | tee evidence/hazelcast-5.7.5.jar.sha256
jar tf dist/hazelcast-5.7.5.jar | grep -Fxq META-INF/LICENSE
jar tf dist/hazelcast-5.7.5.jar | grep -Fxq META-INF/NOTICE
native_resources=(
hazelcast/src/main/resources/affinity_helper.c
hazelcast/src/main/resources/affinity_helper.h
Expand All @@ -223,7 +227,7 @@ jobs:
trap 'rm -rf "$extracted_native"' EXIT
(
cd "$extracted_native"
jar xf "$GITHUB_WORKSPACE/dist/hazelcast-5.7.4.jar" \
jar xf "$GITHUB_WORKSPACE/dist/hazelcast-5.7.5.jar" \
lib/linux-x86/libicmp_helper.so \
lib/linux-x86_64/libaffinity_helper.so \
lib/linux-x86_64/libicmp_helper.so
Expand All @@ -234,7 +238,7 @@ jobs:
"$extracted_native/lib/linux-x86_64/libaffinity_helper.so"
cmp hazelcast-tpc-engine/src/main/resources/lib/linux-x86_64/libicmp_helper.so \
"$extracted_native/lib/linux-x86_64/libicmp_helper.so"
if jar tf dist/hazelcast-5.7.4.jar | grep -Eq '(^|/)(jet_to_python[^/]*|[^/]+\.py)$'; then
if jar tf dist/hazelcast-5.7.5.jar | grep -Eq '(^|/)(jet_to_python[^/]*|[^/]+\.py)$'; then
echo 'The core runtime artifact unexpectedly contains Python extension resources.' >&2
exit 1
fi
Expand Down Expand Up @@ -312,9 +316,9 @@ jobs:
-Dfile=pom.xml -DpomFile=pom.xml
./mvnw -B org.apache.maven.plugins:maven-install-plugin:3.1.4:install-file \
-Dfile=hazelcast-parent/pom.xml -DpomFile=hazelcast-parent/pom.xml
test -s hazelcast-tpc-engine/target/hazelcast-tpc-engine-5.7.4.jar
test -s hazelcast-tpc-engine/target/hazelcast-tpc-engine-5.7.5.jar
./mvnw -B org.apache.maven.plugins:maven-install-plugin:3.1.4:install-file \
-Dfile=hazelcast-tpc-engine/target/hazelcast-tpc-engine-5.7.4.jar \
-Dfile=hazelcast-tpc-engine/target/hazelcast-tpc-engine-5.7.5.jar \
-DpomFile=hazelcast-tpc-engine/pom.xml
timeout --signal=TERM --kill-after=30s 15m ./mvnw -B \
org.apache.maven.plugins:maven-help-plugin:3.5.2:effective-pom \
Expand All @@ -333,7 +337,7 @@ jobs:
-DoutputFormat=json \
-DoutputReactorProjects=false \
-DoutputDirectory="$PWD/evidence" \
-DoutputName=hazelcast-5.7.4.cdx \
-DoutputName=hazelcast-5.7.5.cdx \
-DschemaVersion=1.6 \
org.cyclonedx:cyclonedx-maven-plugin:2.9.3:makeBom
printf '%s %s\n%s %s\n' \
Expand Down Expand Up @@ -383,18 +387,18 @@ jobs:
"$TRIVY_IMAGE" rootfs --pkg-types library \
--cache-dir /root/.cache/trivy --skip-db-update --offline-scan \
--scanners vuln --severity CRITICAL,HIGH --format json \
--output /evidence/hazelcast-5.7.4.trivy.json /artifact/hazelcast-5.7.4.jar
--output /evidence/hazelcast-5.7.5.trivy.json /artifact/hazelcast-5.7.5.jar
docker run --rm --network none \
-v "$PWD/evidence:/evidence" \
-v "$trivy_cache:/root/.cache/trivy" \
"$TRIVY_IMAGE" sbom \
--cache-dir /root/.cache/trivy --skip-db-update --skip-java-db-update --offline-scan \
--scanners vuln --severity CRITICAL,HIGH --format json \
--output /evidence/hazelcast-5.7.4.sbom.trivy.json \
/evidence/hazelcast-5.7.4.cdx.json
--output /evidence/hazelcast-5.7.5.sbom.trivy.json \
/evidence/hazelcast-5.7.5.cdx.json
sha256sum evidence/maven-effective-pom.xml \
evidence/maven-runtime-dependency-tree.json evidence/hazelcast-5.7.4.cdx.json \
evidence/hazelcast-5.7.4.sbom.trivy.json evidence/hazelcast-5.7.4.trivy.json \
evidence/maven-runtime-dependency-tree.json evidence/hazelcast-5.7.5.cdx.json \
evidence/hazelcast-5.7.5.sbom.trivy.json evidence/hazelcast-5.7.5.trivy.json \
evidence/evidence-tools.sha256 \
evidence/native-resources.sha256 evidence/runtime-toolchain-boundary.txt \
> evidence/security-evidence.sha256
Expand All @@ -405,7 +409,7 @@ jobs:
set -euo pipefail
python scripts/pasturestack-verify-maven-evidence.py \
--effective-pom evidence/maven-effective-pom.xml \
--sbom evidence/hazelcast-5.7.4.cdx.json \
--sbom evidence/hazelcast-5.7.5.cdx.json \
--dependency-tree evidence/maven-runtime-dependency-tree.json \
--summary evidence/maven-evidence-summary.txt
sha256sum evidence/maven-evidence-summary.txt >> evidence/security-evidence.sha256
Expand All @@ -418,9 +422,9 @@ jobs:
return json.load(stream)

source = load('evidence/source-security.json')
artifact = load('evidence/hazelcast-5.7.4.trivy.json')
dependency_scan = load('evidence/hazelcast-5.7.4.sbom.trivy.json')
sbom = load('evidence/hazelcast-5.7.4.cdx.json')
artifact = load('evidence/hazelcast-5.7.5.trivy.json')
dependency_scan = load('evidence/hazelcast-5.7.5.sbom.trivy.json')
sbom = load('evidence/hazelcast-5.7.5.cdx.json')
maven_tree = load('evidence/maven-runtime-dependency-tree.json')
source_vulnerabilities = [
item
Expand Down Expand Up @@ -506,7 +510,7 @@ jobs:
or None in component_purls
or len(component_refs) != len(set(component_refs))
or len(component_purls) != len(set(component_purls))
or maven_root != ('com.hazelcast', 'hazelcast', '5.7.4')
or maven_root != ('com.hazelcast', 'hazelcast', '5.7.5')
or sbom_root != maven_root
or root_ref not in dependency_refs
or dependency_refs != allowed_refs
Expand All @@ -524,7 +528,7 @@ jobs:
docker run --rm --network none \
-v "$PWD/evidence:/evidence:ro" \
cyclonedx/cyclonedx-cli:0.33.1@sha256:252c2e26f468c25fea1e63ecde1bc3198ad6e9dbb57f5ed3236bddcb2281b3a7 \
validate --input-file /evidence/hazelcast-5.7.4.cdx.json \
validate --input-file /evidence/hazelcast-5.7.5.cdx.json \
--input-format json --input-version v1_6 --fail-on-errors

- name: Upload review evidence
Expand All @@ -539,12 +543,12 @@ jobs:
include-hidden-files: false

- name: Retain exact reviewed release artifact
if: success() && inputs.release_ref != ''
if: success()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: distributed-cache-release-${{ steps.candidate.outputs.source_sha }}
path: |
dist/hazelcast-5.7.4.jar
dist/hazelcast-5.7.5.jar
evidence/
if-no-files-found: error
retention-days: 30
Expand Down
8 changes: 4 additions & 4 deletions Dockerfile.pasturestack
Original file line number Diff line number Diff line change
Expand Up @@ -19,12 +19,12 @@ FROM scratch

ARG VCS_REF
LABEL org.opencontainers.image.title="PastureStack Distributed Cache Runtime" \
org.opencontainers.image.description="PastureStack artifact 5.7.4 with Hazelcast cluster runtime 5.7.3 and reviewed security updates" \
org.opencontainers.image.description="PastureStack artifact 5.7.5 with Hazelcast cluster runtime 5.7.3 and reviewed security updates" \
org.opencontainers.image.source="https://github.com/PastureStack/distributed-cache-runtime" \
org.opencontainers.image.revision="$VCS_REF" \
org.opencontainers.image.licenses="Apache-2.0 OR LicenseRef-Hazelcast-Community" \
org.opencontainers.image.vendor="PastureStack"

COPY --from=build /src/dist/hazelcast-5.7.4.jar /opt/pasturestack/vendor/hazelcast-5.7.4.jar
COPY --from=build /src/dist/hazelcast-5.7.4.jar.sha256 /opt/pasturestack/vendor/hazelcast-5.7.4.jar.sha256
COPY LICENSE NOTICE ORIGIN.md SECURITY-MAINTENANCE.md /opt/pasturestack/licenses/
COPY --from=build /src/dist/hazelcast-5.7.5.jar /opt/pasturestack/vendor/hazelcast-5.7.5.jar
COPY --from=build /src/dist/hazelcast-5.7.5.jar.sha256 /opt/pasturestack/vendor/hazelcast-5.7.5.jar.sha256
COPY LICENSE NOTICE ORIGIN.md SECURITY-MAINTENANCE.md RELEASE-NOTES-5.7.5.md /opt/pasturestack/licenses/
2 changes: 1 addition & 1 deletion ORIGIN.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ This repository is derived from the public [Hazelcast repository](https://github
- Upstream boundary commit: `60c31e3750cbad64f5720e2e02f0a9830973193c`
- PastureStack maintenance line: linear commits after that upstream boundary
- Historical maintained artifact: PastureStack Maven artifact 5.7.3-pasturestack.4 (numeric Hazelcast cluster runtime 5.7.3), based on Hazelcast 5.7.0, with reviewed source and dependency security updates
- Current maintained artifact: pure numeric Maven artifact `5.7.4`; product identity and provenance remain in package metadata and release evidence
- Current candidate artifact: pure numeric Maven artifact `5.7.5`, not yet built or published; product identity and provenance remain in package metadata and release evidence. Public `v5.7.4` remains immutable historical evidence.

The upstream Git history, copyright notices, author records, `LICENSE`, `NOTICE`, and file-level license headers are retained. PastureStack's maintenance commits do not replace or relicense upstream work, and PastureStack does not claim authorship of upstream contributions.

Expand Down
9 changes: 6 additions & 3 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,12 @@

Earlier public Maven artifacts remain immutable historical evidence. The
current public GitHub Release is
[`v5.7.4`](https://github.com/PastureStack/distributed-cache-runtime/releases/tag/v5.7.4),
and the maintained artifact version produced by this source is `5.7.4`. Every
current and future PastureStack publication uses a pure numeric version, while
[`v5.7.4`](https://github.com/PastureStack/distributed-cache-runtime/releases/tag/v5.7.4).
This source prepares candidate
artifact `5.7.5`; it has not yet been built, scanned, or published. See
[5.7.5 candidate notes](RELEASE-NOTES-5.7.5.md) for the Jackson-only update and
pending artifact verification. Every current and future PastureStack publication
uses a pure numeric version, while
product identity and provenance remain in metadata rather than the version.
Generated Hazelcast cluster metadata reports numeric runtime version `5.7.3`,
because the cluster protocol does not accept a Maven qualifier. See
Expand Down
21 changes: 21 additions & 0 deletions RELEASE-NOTES-5.7.5.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
# 5.7.5 candidate: Jackson security patch

Status: source candidate only; not yet built, scanned, published, or validated
in a downstream runtime. Public `v5.7.4` remains unchanged historical evidence.

- Update the actual parent properties and imported BOMs from Jackson 2.22.2 to
2.22.3 and from Jackson 3.2.2 to 3.2.3. FasterXML lists fixes for
CVE-2026-91776 (unbounded type-id cache) and CVE-2026-91777 (quadratic
forward-reference resolution) in both
[2.22.3](https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.22.3) and
[3.2.3](https://github.com/FasterXML/jackson/wiki/Jackson-Release-3.2.3).
- Require those exact versions in all four embedded Jackson core/databind
Maven metadata entries. Update reactor coordinates, test-job fixtures,
carrier paths, SBOM identity, and release gates to numeric artifact `5.7.5`.
- Preserve numeric Hazelcast cluster runtime `5.7.3`, business logic, and all
other dependency pins from the candidate's `origin/main` base.

The existing release gate must still build the shaded JAR, run its focused
regression suites, verify resolved Maven/SBOM and packaged metadata, and scan
the actual artifact with current vulnerability data. Source-only checks do not
prove that CVEs are absent from a built artifact or any downstream Engine JAR.
Loading
Loading