Skip to content

Turn on CI/CD build for http-java17 example#175

Open
chrisf-aarnet wants to merge 7 commits into
unikraft-cloud:mainfrom
chrisf-aarnet:main
Open

Turn on CI/CD build for http-java17 example#175
chrisf-aarnet wants to merge 7 commits into
unikraft-cloud:mainfrom
chrisf-aarnet:main

Conversation

@chrisf-aarnet

Copy link
Copy Markdown

There is currently no automated integration test for the http-java17 example or badge in the README.md.

This pull request adds the GitHub workflow to test this example (which seems currently to be failing).

Chris Fegan and others added 7 commits July 6, 2025 18:27
Remove the explicitly set runtime as CI/CD experiment

Signed-off-by: chrisf-aarnet <65877535+chrisf-aarnet@users.noreply.github.com>
Change to use the official java runtime.


specific argument:
--runtime index.unikraft.io/official/java:17 \


Signed-off-by: chrisf-aarnet <65877535+chrisf-aarnet@users.noreply.github.com>
Add more CI/CD debugging for java-http workflow


Signed-off-by: chrisf-aarnet <65877535+chrisf-aarnet@users.noreply.github.com>
Update the runtime for http-java CI/CD to one that exists

Signed-off-by: chrisf-aarnet <65877535+chrisf-aarnet@users.noreply.github.com>
nurof3n pushed a commit that referenced this pull request Mar 24, 2026
Update the following packages to fix security vulnerabilities:
- Authlib 1.6.5 -> 1.6.9 (critical: JWS JWK Header Injection, high: alg:none bypass, Bleichenbacher, OIDC hash binding, medium: account takeover)
- cryptography 46.0.3 -> 46.0.5 (high: SECT curve subgroup attack)
- fastmcp 2.13.2 -> 2.14.5 (high: OAuth proxy token reuse, MCP CVE-2025-66416)
- mcp 1.23.1 -> 1.26.0 (required by fastmcp 2.14.x)
- PyJWT 2.10.1 -> 2.12.1 (high: unknown crit header extensions)
- python-multipart 0.0.20 -> 0.0.22 (high: arbitrary file write)
- urllib3 2.5.0 -> 2.6.3 (high: decompression bomb bypass, streaming API issues)

Note: diskcache 5.6.3 has no fix available (alert #227).

Resolves dependabot alerts #175, #176, #184, #190, #198, #209, #225, #275, #283, #291, #293, #295, #297.

Signed-off-by: Razvan Deaconescu <razvand@unikraft.io>
dragosgheorghioiu pushed a commit that referenced this pull request Apr 7, 2026
Update the following packages to fix security vulnerabilities:
- Authlib 1.6.5 -> 1.6.9 (critical: JWS JWK Header Injection, high: alg:none bypass, Bleichenbacher, OIDC hash binding, medium: account takeover)
- cryptography 46.0.3 -> 46.0.5 (high: SECT curve subgroup attack)
- fastmcp 2.13.2 -> 2.14.5 (high: OAuth proxy token reuse, MCP CVE-2025-66416)
- mcp 1.23.1 -> 1.26.0 (required by fastmcp 2.14.x)
- PyJWT 2.10.1 -> 2.12.1 (high: unknown crit header extensions)
- python-multipart 0.0.20 -> 0.0.22 (high: arbitrary file write)
- urllib3 2.5.0 -> 2.6.3 (high: decompression bomb bypass, streaming API issues)

Note: diskcache 5.6.3 has no fix available (alert #227).

Resolves dependabot alerts #175, #176, #184, #190, #198, #209, #225, #275, #283, #291, #293, #295, #297.

Signed-off-by: Razvan Deaconescu <razvand@unikraft.io>
dragosgheorghioiu pushed a commit that referenced this pull request Apr 7, 2026
Update the following packages to fix security vulnerabilities:
- Authlib 1.6.5 -> 1.6.9 (critical: JWS JWK Header Injection, high: alg:none bypass, Bleichenbacher, OIDC hash binding, medium: account takeover)
- cryptography 46.0.3 -> 46.0.5 (high: SECT curve subgroup attack)
- fastmcp 2.13.2 -> 2.14.5 (high: OAuth proxy token reuse, MCP CVE-2025-66416)
- mcp 1.23.1 -> 1.26.0 (required by fastmcp 2.14.x)
- PyJWT 2.10.1 -> 2.12.1 (high: unknown crit header extensions)
- python-multipart 0.0.20 -> 0.0.22 (high: arbitrary file write)
- urllib3 2.5.0 -> 2.6.3 (high: decompression bomb bypass, streaming API issues)

Note: diskcache 5.6.3 has no fix available (alert #227).

Resolves dependabot alerts #175, #176, #184, #190, #198, #209, #225, #275, #283, #291, #293, #295, #297.

Signed-off-by: Razvan Deaconescu <razvand@unikraft.io>
dragosgheorghioiu pushed a commit that referenced this pull request Apr 7, 2026
Update the following packages to fix security vulnerabilities:
- Authlib 1.6.5 -> 1.6.9 (critical: JWS JWK Header Injection, high: alg:none bypass, Bleichenbacher, OIDC hash binding, medium: account takeover)
- cryptography 46.0.3 -> 46.0.5 (high: SECT curve subgroup attack)
- fastmcp 2.13.2 -> 2.14.5 (high: OAuth proxy token reuse, MCP CVE-2025-66416)
- mcp 1.23.1 -> 1.26.0 (required by fastmcp 2.14.x)
- PyJWT 2.10.1 -> 2.12.1 (high: unknown crit header extensions)
- python-multipart 0.0.20 -> 0.0.22 (high: arbitrary file write)
- urllib3 2.5.0 -> 2.6.3 (high: decompression bomb bypass, streaming API issues)

Note: diskcache 5.6.3 has no fix available (alert #227).

Resolves dependabot alerts #175, #176, #184, #190, #198, #209, #225, #275, #283, #291, #293, #295, #297.

Signed-off-by: Razvan Deaconescu <razvand@unikraft.io>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant