Skip to content

[pull] master from jenkins-infra:master#7

Open
pull[bot] wants to merge 1544 commits intoThompson1985:masterfrom
jenkins-infra:master
Open

[pull] master from jenkins-infra:master#7
pull[bot] wants to merge 1544 commits intoThompson1985:masterfrom
jenkins-infra:master

Conversation

@pull
Copy link
Copy Markdown

@pull pull bot commented Aug 29, 2024

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

@pull pull bot added ⤵️ pull merge-conflict Resolve conflicts manually labels Aug 29, 2024
ayushman189 and others added 30 commits March 31, 2026 16:24
* Fix: Corrected 404 broken link for Bug Bounty Program

Updated the link to point to the correct December 2025 blog post.

* Update content/blog/2026/03/2026-03-02-contributor-summit.adoc

Co-authored-by: Kris Stern <88480540+krisstern@users.noreply.github.com>

---------

Co-authored-by: Kris Stern <88480540+krisstern@users.noreply.github.com>
Fix grammar: "appear" -> "appears" in tutorial docs

Fix subject-verb agreement where "a new column *Test* appear"
should be "appears" (singular subject requires singular verb).

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
…9001)

Bumps [updatecli/updatecli-action](https://github.com/updatecli/updatecli-action) from 2.100.0 to 3.0.0.
- [Release notes](https://github.com/updatecli/updatecli-action/releases)
- [Commits](updatecli/updatecli-action@v2.100.0...v3.0.0)

---
updated-dependencies:
- dependency-name: updatecli/updatecli-action
  dependency-version: 3.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Kris Stern <88480540+krisstern@users.noreply.github.com>
Compress Images

Co-authored-by: timja <21194782+timja@users.noreply.github.com>
Bumps [rack](https://github.com/rack/rack) from 2.2.22 to 2.2.23.
- [Release notes](https://github.com/rack/rack/releases)
- [Changelog](https://github.com/rack/rack/blob/main/CHANGELOG.md)
- [Commits](rack/rack@v2.2.22...v2.2.23)

---
updated-dependencies:
- dependency-name: rack
  dependency-version: 2.2.23
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [lodash](https://github.com/lodash/lodash) from 4.17.23 to 4.18.1.
- [Release notes](https://github.com/lodash/lodash/releases)
- [Commits](lodash/lodash@4.17.23...4.18.1)

---
updated-dependencies:
- dependency-name: lodash
  dependency-version: 4.18.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
fix: preserve :// scheme separator in absolute_link

Co-authored-by: Hervé Le Meur <91831478+lemeurherve@users.noreply.github.com>
Add 2.555.1 to Java Support Policy as first LTS to require Java 21

Release is scheduled for Apr 15, 2026.  Release candidate is already
available.  There is no compelling reason to delay the update of the
Java Support Policy.
Update link to MIT technical writing resource
We've had multi-platform for many years

Includes ARM, s390x, ppc64le

Recently added RISC-V

Co-authored-by: Kris Stern <88480540+krisstern@users.noreply.github.com>
* Update platform SIG leads, participants, and description

Switch meeting frequency to once a month and move it one hour earlier.

Update descriptions to more accurately reflect the current work and
likely future work of the platform SIG.

Improve the phrasing in some areas and complete the phrasing in others.

Testing done:

Confirmed that the page is correct when generated locally

* Add Kris Stern as a participant

Co-authored-by: Kris Stern <88480540+krisstern@users.noreply.github.com>

---------

Co-authored-by: Kris Stern <88480540+krisstern@users.noreply.github.com>
It is listed in the near term column but there has been no progress on
it in many years.

Co-authored-by: Zbynek Konecny <zbynek@geogebra.org>
It was listed in the "current" section but there has not been any effort
in Jenkins on Kubernetes online meetups for many years.
* added blog post about plugin of the month april 2026

* adjusted title

* added pictures and a short interactive video

* typeo for youtube

* adjusted video size
Compress Images

Co-authored-by: krisstern <88480540+krisstern@users.noreply.github.com>
…ol in 2026 (#9031)

* feat(blog): jetbrains report highlights jenkins as a popular ci/cd tool in 2026

* Apply suggestions from code review

Co-authored-by: Stefan Spieker <S.Spieker@gmx.net>

---------

Co-authored-by: Stefan Spieker <S.Spieker@gmx.net>
Compress Images

Co-authored-by: krisstern <88480540+krisstern@users.noreply.github.com>
Co-authored-by: jenkins-infra-changelog-generator <86592549+jenkins-infra-changelog-generator[bot]@users.noreply.github.com>
)

chore: Bump Jenkins oldest stable supported version in the "Choosing ...

... a version" page

Made with ❤️️ by updatecli

Co-authored-by: GitHub Actions <41898282+github-actions[bot]@users.noreply.github.com>
* Update Blue Ocean warning with deprecation date

CloudBees CI BlueOcean Deprecation
https://docs.cloudbees.com/docs/cloudbees-ci-kb/latest/troubleshooting-guides/admin-monitor-blueocean-removal
says:

Point users to Pipeline Graph View as the first choice to replace Blue Ocean.

> Starting with the July 2026 CloudBees CI release, Blue Ocean ... will
> reach end-of-life (EOL) and will no longer be supported. After this
> date, Blue Ocean ... will not receive updates, security patches, or
> technical support

Fixes #9040

* Better phrasing

* Place the 'plugin' word inside the link
…6.2-alpine3.23 (#9043)

chore: Update the value of the golang docker image for pipelines in t...

... he 'Hello World!' tutorial

Made with ❤️️ by updatecli

Co-authored-by: GitHub Actions <41898282+github-actions[bot]@users.noreply.github.com>
…lpine3.23 (#9044)

chore: Update the value of the python docker image for scripts in the...

...  'Hello World!' tutorial

Made with ❤️️ by updatecli

Co-authored-by: GitHub Actions <41898282+github-actions[bot]@users.noreply.github.com>
Bumps [addressable](https://github.com/sporkmonger/addressable) from 2.8.4 to 2.9.0.
- [Changelog](https://github.com/sporkmonger/addressable/blob/main/CHANGELOG.md)
- [Commits](sporkmonger/addressable@addressable-2.8.4...addressable-2.9.0)

---
updated-dependencies:
- dependency-name: addressable
  dependency-version: 2.9.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* add a blog post about a german petition for an open source petition

* Fix link syntax error

* Compress image file

* Update content/blog/2026/04/2026-04-10-open-source-ehrenamt.adoc

Co-authored-by: Mark Waite <mark.earl.waite@gmail.com>

* added missing slash

---------

Co-authored-by: Mark Waite <mark.earl.waite@gmail.com>
Compress Images

Co-authored-by: MarkEWaite <156685+MarkEWaite@users.noreply.github.com>
Verify war file signature with GPG, not Digicert signing certificate

We've been signing the Jenkins war file with a GPG private key since 2011.
Switch the verification instructuions for the Jenkins war file from the
code signing certificate that we purchase from Digicert to the GPG key
that we generate and maintain ourselves.

The Digicert code signing certificate expires May 16, 2026 as noted in:

* jenkins-infra/helpdesk#4923

Code signing certificate processes were changed significantly in 2023.
The changes require secure storage of the code signing certificate
using either a hardware security module or a hardened cloud service.
We are likely to use the Microsoft Artifact Signing Service to sign our
MSI file.  However, there are indications that the Microsoft Artifact
Signing Service is not able to sign jar files and war files.

Since we've been signing our installer with a GPG key for a very long
time, let's change the documentation to describe how to verify the GPG
signed war file.  Even if we ultimately find a way to use a 2026 code
signing certificate to sign the war file, we'll have helped our users
transition to verifying with the same tool that we use to verify the
war file in our container images.

Testing done:

* Checked that each command works as expected on a Linux computer

Surprises:

I was surprised that updates.jenkins.io does not deliver the ".asc"
file, while get.jenkins.io does deliver it.  We might want to extend
updates.jenkins.io to also deliver it.l

I was surprised that the GPG public key is not available from
get.jenkins.io.  It seems like a good idea that it should be available
there.  Not required, just an idea to consider.

Co-authored-by: Kris Stern <88480540+krisstern@users.noreply.github.com>
…alpine3.23 (#9048)

chore: Update the value of the php docker image for pipelines in the ...

... 'Hello World!' tutorial

Made with ❤️️ by updatecli

Co-authored-by: GitHub Actions <41898282+github-actions[bot]@users.noreply.github.com>
* docs: clarify VS Code setup and JDK alignment

* refine VS Code JDK note per review feedback

* docs: refine VS Code JDK note with references

---------

Co-authored-by: Kris Stern <88480540+krisstern@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

⤵️ pull merge-conflict Resolve conflicts manually

Projects

None yet

Development

Successfully merging this pull request may close these issues.