Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
60 commits
Select commit Hold shift + click to select a range
091a67e
Update base image (#873)
yaalsn Jan 26, 2024
00b0671
Update base image (#874)
yaalsn Jan 26, 2024
efcd6a8
Use the Apache images to run tests, in order to avoid permission issu…
shibd Apr 3, 2024
4c15b6c
Bump json-smart from 2.4.7 to 2.4.9 (#622)
dependabot[bot] Apr 10, 2024
885b679
Bump jackson-databind from 2.13.4.1 to 2.13.4.2 (#630)
dependabot[bot] Apr 10, 2024
111628c
Bump org.apache.commons:commons-compress from 1.21 to 1.26.0 (#892)
dependabot[bot] Apr 10, 2024
0d55ceb
cve: upgrade depend version (#944) (#947)
shibd Apr 11, 2024
eed86b3
fix: Read JSON directly from the original data when formatType=json (…
shibd Apr 30, 2024
8802a76
[fix]: fix Parquet/Avro format with separated key value avro-avro mes…
nicoloboschi May 9, 2024
2696f0d
[improve] Allow user-specified S3 path (#5)
mukesh154 May 22, 2024
21c3ad3
Fix checkstyle
mukesh-ctds Jun 18, 2024
51b566a
Revert "Fix checkstyle"
mukesh-ctds Jun 18, 2024
fc48d59
Revert "[improve] Allow user-specified S3 path (#5)"
mukesh-ctds Jun 18, 2024
5c01a16
Revert "[fix]: fix Parquet/Avro format with separated key value avro-…
mukesh-ctds Jun 18, 2024
e4a9bb2
Upgrade: Code sync with upstream branch-3.2 (#6)
mukesh-ctds Jun 18, 2024
76908c2
[maven-release-plugin] prepare release pulsar-io-cloud-storage-3.2.0
mukesh-ctds Jun 18, 2024
06392e4
[maven-release-plugin] prepare for next development iteration
mukesh-ctds Jun 18, 2024
5dd0810
Revert "[maven-release-plugin] prepare for next development iteration"
mukesh-ctds Jun 18, 2024
e16e382
Revert "[maven-release-plugin] prepare release pulsar-io-cloud-storag…
mukesh-ctds Jun 18, 2024
5119aa2
[maven-release-plugin] prepare release v3.2.0
mukesh-ctds Jun 18, 2024
9a46a60
[maven-release-plugin] prepare for next development iteration
mukesh-ctds Jun 18, 2024
56fd467
Removed duplicate avro version for runtime (#7)
nikhil-ctds Jul 16, 2024
3bd8418
[maven-release-plugin] prepare release v3.2.1
nikhil-ctds Jul 17, 2024
0a6c578
[maven-release-plugin] prepare for next development iteration
nikhil-ctds Jul 17, 2024
e660c90
Upgrade Avro to 1.11.4 to address CVE-2024-47561
nikhil-ctds Oct 4, 2024
db61b59
[maven-release-plugin] prepare release v3.2.2
nikhil-ctds Oct 5, 2024
cdfed3a
[maven-release-plugin] prepare for next development iteration
nikhil-ctds Oct 5, 2024
bae0fb1
Upgrade protobuf3 & async-http-client to address CVE-2024-7254 & CVE-…
nikhil-ctds Apr 28, 2025
f60387a
[maven-release-plugin] prepare release pulsar-io-cloud-storage-3.2.3
ganesh-ctds Apr 29, 2025
d9e4c36
[maven-release-plugin] prepare for next development iteration
ganesh-ctds Apr 29, 2025
f86fd31
Revert "[maven-release-plugin] prepare for next development iteration"
ganesh-ctds Apr 29, 2025
b840645
Revert "[maven-release-plugin] prepare release pulsar-io-cloud-storag…
ganesh-ctds Apr 29, 2025
4a13599
[maven-release-plugin] prepare release v3.2.3
ganesh-ctds Apr 29, 2025
b371845
[maven-release-plugin] prepare for next development iteration
ganesh-ctds Apr 29, 2025
7c0d7b4
bump parquet version (#13)
ganesh-ctds May 6, 2025
2e0e01a
[maven-release-plugin] prepare release v3.2.4
ganesh-ctds May 6, 2025
e238adb
[maven-release-plugin] prepare for next development iteration
ganesh-ctds May 6, 2025
cdea49b
Update pom.xml to resolve vulnerabilities
manas-ctds Dec 8, 2025
403818e
AS-4121: Update pom.xml to resolve vulnerabilities (#14)
manas-ctds Dec 9, 2025
d1fba74
[maven-release-plugin] prepare release v3.2.5
manas-ctds Dec 9, 2025
a0bc4e3
[maven-release-plugin] prepare for next development iteration
manas-ctds Dec 9, 2025
a32eac3
Upgrade dependencies to address multiple CVEs (#15)
manas-ctds Dec 18, 2025
dea6ad4
[maven-release-plugin] prepare release v3.2.6
manas-ctds Dec 19, 2025
ccb3fb6
[maven-release-plugin] prepare for next development iteration
manas-ctds Dec 19, 2025
3afe37e
Bump netty & aircompressor versions to fix CVE (#16)
ganesh-ctds Mar 9, 2026
21ada94
[maven-release-plugin] prepare release v3.2.7
ganesh-ctds Mar 12, 2026
31b82dd
[maven-release-plugin] prepare for next development iteration
ganesh-ctds Mar 12, 2026
9bba0d1
Upgrade dependencies to remediate CVEs (#17)
manas-ctds Apr 28, 2026
77636c6
[maven-release-plugin] prepare release v3.2.8
manas-ctds Apr 29, 2026
aeafcc4
[maven-release-plugin] prepare for next development iteration
manas-ctds Apr 29, 2026
99a5136
Bump dependencies to remediate multiple CVEs (#18)
manas-ctds Jun 9, 2026
3fd806d
Upgrade netty to 4.1.135.Final to remediate CVE-2026-44249, CVE-2026-…
manas-ctds Jun 12, 2026
11856ac
[maven-release-plugin] prepare release v3.2.9
manas-ctds Jun 12, 2026
e628a7d
[maven-release-plugin] prepare for next development iteration
manas-ctds Jun 12, 2026
82cd4fc
Updated pulsar version to latest in 3.1.4.x for bouncycastle vulnerab…
sandeep-ctds Jul 27, 2026
1a792e2
AS-4628: Updated pulsar version to latest in 3.1.4.x for bouncycastle…
sandeep-ctds Jul 27, 2026
9ff4f5e
[maven-release-plugin] prepare release v3.2.10
sandeep-ctds Aug 3, 2026
9e3e613
[maven-release-plugin] prepare for next development iteration
sandeep-ctds Aug 3, 2026
a3f4c80
Added sonarqube scanning to PR, commit and workflows
sandeep-ctds Aug 20, 2026
75d1c63
Updated sonarqube.yaml to use sonar_host_url from vars
sandeep-ctds Aug 20, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
26 changes: 26 additions & 0 deletions .github/workflows/ds-release.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
name: DS Release

on:
push:
tags:
- 'v*'

jobs:
create-release:
permissions: write-all
runs-on: ubuntu-latest

steps:
- uses: actions/checkout@v2
- name: Set up JDK 17
uses: actions/setup-java@v2
with:
java-version: '17'
distribution: 'adopt'
- name: Build with Maven
run: mvn -B package -DskipTests -Dcheckstyle.skip
- uses: ncipollo/release-action@v1
with:
artifacts: "**/target/*.nar"
token: ${{ secrets.GITHUB_TOKEN }}
generateReleaseNotes: true
2 changes: 1 addition & 1 deletion .github/workflows/pr-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ on:
pull_request:
push:
branches:
- master
- 3.2_ds

jobs:
build:
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ jobs:
PULSAR_VERSION=`mvn -q -Dexec.executable=echo -Dexec.args='${pulsar.version}' --non-recursive exec:exec 2>/dev/null`
REPO=`mvn -q -Dexec.executable=echo -Dexec.args='${project.artifactId}' --non-recursive exec:exec 2>/dev/null`
IMAGE_REPO=streamnative/${REPO}
RUNNER_IMAGE=docker.cloudsmith.io/streamnative/staging/pulsar-functions-java-runner:${PULSAR_VERSION}
RUNNER_IMAGE=streamnative/pulsar-functions-java-runner:${PULSAR_VERSION}
docker pull ${RUNNER_IMAGE}
docker build --build-arg PULSAR_VERSION="$PULSAR_VERSION" -t ${IMAGE_REPO}:${CONNECTOR_VERSION} -f ./image/Dockerfile ./
docker push ${IMAGE_REPO}:${CONNECTOR_VERSION}
106 changes: 106 additions & 0 deletions .github/workflows/sonarqube.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,106 @@
name: SonarQube Scan

on:
push:
branches:
- 4.0_ds
- 3.2_ds
pull_request:
types: [opened, synchronize, reopened]
branches:
- 4.0_ds
- 3.2_ds
workflow_dispatch:
inputs:
scan_type:
description: 'Type of scan to run'
required: true
type: choice
options:
- branch
- pr
default: branch
ref:
description: 'Commit SHA, branch, or tag to check out and scan (leave blank to use the default branch)'
required: false
type: string
default: ''

concurrency:
group: sonarqube-${{ github.ref }}
cancel-in-progress: true

env:
TRUSTSTORE_PATH: ./ibm_castorevpcprod
# Maven tuning — mirrors settings used across the rest of the CI workflows.
MAVEN_OPTS: >-
-Xss1500k
-Xmx2048m
-XX:+UnlockDiagnosticVMOptions
-XX:+IgnoreUnrecognizedVMOptions
-XX:GCLockerRetryAllocationCount=100
-Daether.connector.http.reuseConnections=false
-Daether.connector.requestTimeout=60000
-Dhttp.keepAlive=false
-Dmaven.wagon.http.pool=false
-Dmaven.wagon.http.retryHandler.class=standard
-Dmaven.wagon.http.retryHandler.count=3
-Dmaven.wagon.http.retryHandler.requestSentEnabled=true
-Dmaven.wagon.http.serviceUnavailableRetryStrategy.class=standard
-Dmaven.wagon.rto=60000

jobs:
sonarqube-scan:
name: SonarQube Scan
runs-on: ubuntu-latest

steps:
- name: Checkout repository
uses: actions/checkout@v4
with:
# Full history required for accurate blame and new-code period detection.
fetch-depth: 0
# When triggered manually with a specific ref (commit SHA, branch, tag),
# check out that ref; otherwise fall back to the default event ref.
ref: ${{ (github.event_name == 'workflow_dispatch' && inputs.ref != '') && inputs.ref || github.ref }}

- name: Set up JDK 17
uses: actions/setup-java@v4
with:
distribution: corretto
java-version: '17'
cache: maven

# Decode the IBM truststore from the base64 secret and write it to disk.
# Secret is bound to an env var to avoid shell-injection (S7636).
- name: Decode IBM SonarQube truststore
env:
TRUSTSTORE_B64: ${{ secrets.IBM_SONARQUBE_CERT_TRUSTSTORE_BASE64 }}
run: |
echo "$TRUSTSTORE_B64" | base64 --decode > "${{ env.TRUSTSTORE_PATH }}"

# Produce .class files required by SonarQube's Java bytecode analyser.
- name: Build
run: mvn -B package -DskipTests --no-transfer-progress

# Pinned to v8.2.1 (SHA: 22918119ff8e1ca75a623e15c8296b6ea4fbe28f).
- name: Run SonarQube scan
uses: SonarSource/sonarqube-scan-action@22918119ff8e1ca75a623e15c8296b6ea4fbe28f
env:
SONAR_TOKEN: ${{ secrets.IBM_SONARQUBE_API_TOKEN }}
SONAR_HOST_URL: ${{ vars.SONAR_HOST_URL }}
with:
args: >
-D sonar.projectKey=${{ vars.SONAR_PROJECT_KEY }}
-D sonar.projectName=${{ vars.SONAR_PROJECT_NAME }}
-D sonar.java.source=17
-D sonar.sources=.
-D sonar.exclusions=**/proto/**,**/shade/**,**/shaded/**,**/target/**
-D sonar.java.binaries=**/target/classes
-D sonar.scanner.truststorePath=${{ env.TRUSTSTORE_PATH }}
-D sonar.scanner.truststorePassword=${{ secrets.IBM_SONARQUBE_CERT_PASSWORD }}
${{ (github.event_name == 'pull_request' || (github.event_name == 'workflow_dispatch' && inputs.scan_type == 'pr'))
&& format('-Dsonar.pullrequest.key={0} -Dsonar.pullrequest.branch={1} -Dsonar.pullrequest.base={2}',
github.event.pull_request.number, github.head_ref, github.base_ref)
|| format('-Dsonar.branch.name={0}',
(github.event_name == 'workflow_dispatch' && inputs.ref != '') && inputs.ref || github.ref_name) }}
2 changes: 1 addition & 1 deletion image/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -18,5 +18,5 @@
#

ARG PULSAR_VERSION
FROM docker.cloudsmith.io/streamnative/staging/pulsar-functions-java-runner:${PULSAR_VERSION}
FROM streamnative/pulsar-functions-java-runner:${PULSAR_VERSION}
COPY --chown=$UID:$GID target/*.nar /pulsar/connectors/
Loading
Loading