Skip to content

[Backport main] Add ci.opensearch.org/m2/ mirror for plugin resolution (sql) - #5666

Merged
peterzhuamazon merged 1 commit into
opensearch-project:mainfrom
opensearch-ci-bot:backport/backport-5664-to-main
Jul 31, 2026
Merged

[Backport main] Add ci.opensearch.org/m2/ mirror for plugin resolution (sql)#5666
peterzhuamazon merged 1 commit into
opensearch-project:mainfrom
opensearch-ci-bot:backport/backport-5664-to-main

Conversation

@opensearch-ci-bot

Copy link
Copy Markdown
Contributor

Backport fe20ba6 from #5664.

…rch-project#5664)

* Add ci.opensearch.org/m2/ mirror for plugin resolution (sql)

Signed-off-by: shreyah963 <shreyab963@gmail.com>

* Address order issues

Signed-off-by: Peter Zhu <zhujiaxi@amazon.com>

---------

Signed-off-by: shreyah963 <shreyab963@gmail.com>
Signed-off-by: Peter Zhu <zhujiaxi@amazon.com>
Co-authored-by: Peter Zhu <zhujiaxi@amazon.com>
(cherry picked from commit fe20ba6)
Signed-off-by: opensearch-ci-bot <opensearch-infra@amazon.com>
@github-actions

Copy link
Copy Markdown
Contributor

PR Code Analyzer ❗

AI-powered 'Code-Diff-Analyzer' found issues on commit d630e76.

PathLineSeverityDescription
settings.gradle9highNew Maven repository added at 'https://ci.opensearch.org/m2/' — a second URL on the same host as the existing 'https://ci.opensearch.org/maven2/' but under a different path. This is a build plugin/dependency source change that must be flagged per mandatory rule. The '/m2/' path is not the same endpoint as '/maven2/', and it is unclear whether this URL is an official, maintained, or controlled OpenSearch artifact repository. A malicious actor with access to this path could serve tampered build plugins or dependencies.

The table above displays the top 10 most important findings.

Total: 1 | Critical: 0 | High: 1 | Medium: 0 | Low: 0


Pull Requests Author(s): Please update your Pull Request according to the report above.

Repository Maintainer(s): You can bypass diff analyzer by adding label skip-diff-analyzer after reviewing the changes carefully, then re-run failed actions. To re-enable the analyzer, remove the label, then re-run all actions.


⚠️ Note: The Code-Diff-Analyzer helps protect against potentially harmful code patterns. Please ensure you have thoroughly reviewed the changes beforehand.

Thanks.

@peterzhuamazon
peterzhuamazon merged commit 2852724 into opensearch-project:main Jul 31, 2026
35 of 40 checks passed
@opensearch-ci-bot
opensearch-ci-bot deleted the backport/backport-5664-to-main branch July 31, 2026 21:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants