Skip to content

[Backport 2.19] Guard eclipse() to spotless tasks and keep P2 mirror on pinned version (flow-framework) - #1473

Open
peterzhuamazon wants to merge 1 commit into
opensearch-project:2.19from
peterzhuamazon:backport/backport-1471-to-2.19
Open

[Backport 2.19] Guard eclipse() to spotless tasks and keep P2 mirror on pinned version (flow-framework)#1473
peterzhuamazon wants to merge 1 commit into
opensearch-project:2.19from
peterzhuamazon:backport/backport-1471-to-2.19

Conversation

@peterzhuamazon

Copy link
Copy Markdown
Member

Backport f5ba22a from #1471.

…n (flow-framework)

Signed-off-by: Peter Zhu <zhujiaxi@amazon.com>
@github-actions

Copy link
Copy Markdown
Contributor

PR Code Analyzer ❗

AI-powered 'Code-Diff-Analyzer' found issues on commit 8b5b3ba.

Hard block: Issues at High severity or above will block this PR from merging.

PathLineSeverityDescription
build.gradle53highDependency version change: 'com.diffplug.spotless:spotless-plugin-gradle' bumped from 7.0.2 to 8.10.1. Per mandatory supply chain policy, all dependency version changes must be flagged for maintainer verification regardless of apparent legitimacy.
formatter/formatting.gradle44highNew explicit dependency on Eclipse JDT version '4.34' introduced via eclipse('4.34'). Previously the version was resolved implicitly by the spotless plugin default. Pinning to a specific artifact version is a dependency change that must be verified per mandatory supply chain policy.

The table above displays the top 10 most important findings.

Total: 2 | Critical: 0 | High: 2 | Medium: 0 | Low: 0


Pull Requests Author(s): Please update your Pull Request according to the report above.

Repository Maintainer(s): You can bypass diff analyzer by adding label skip-diff-analyzer after reviewing the changes carefully, then re-run failed actions. To re-enable the analyzer, remove the label, then re-run all actions.


⚠️ Note: The Code-Diff-Analyzer helps protect against potentially harmful code patterns. Please ensure you have thoroughly reviewed the changes beforehand.

Thanks.

@peterzhuamazon peterzhuamazon added the skip-diff-analyzer Maintainer to skip code-diff-analyzer check, after reviewing issues in AI analysis. label Sep 10, 2026
@peterzhuamazon peterzhuamazon added enhancement New feature or request release v2.19.6 Issues targeting release v2.19.6 skip-changelog labels Sep 10, 2026
@peterzhuamazon peterzhuamazon self-assigned this Sep 10, 2026
@peterzhuamazon peterzhuamazon removed the v2.19.6 Issues targeting release v2.19.6 label Sep 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request release skip-changelog skip-diff-analyzer Maintainer to skip code-diff-analyzer check, after reviewing issues in AI analysis.

Projects

Status: 👀 In Review
Status: In review

Development

Successfully merging this pull request may close these issues.

2 participants