Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,9 @@ All notable changes to this project will be documented in this file.
- vector: Build with `--locked` ([#1674]).
- nifi: Updated dependencies for `2.6.0` and `2.9.0` ([#1667]).
- ci: Bump `stackabletech/actions` to `v0.18.4` ([#1681]).
- java-devel: Pin `versions-maven-plugin` to `2.22.0` for `mvn versions:set`, which otherwise resolves the latest release on every build unless the product POM pins it ([#1682]).
- airflow, druid, hbase, nifi, opensearch-dashboards, superset, trino: Install global npm packages (cdxgen, pnpm, yarn, npm) with `--ignore-scripts`, and only resolve versions that were published at least 7 days ago (`--before`) ([#1682]).
- superset: Pin npm to `10.9.9` instead of installing the latest version with `nvm install --latest-npm` ([#1682]).

### Fixed

Expand Down Expand Up @@ -113,6 +116,7 @@ All notable changes to this project will be documented in this file.
[#1676]: https://github.com/stackabletech/docker-images/pull/1676
[#1677]: https://github.com/stackabletech/docker-images/pull/1677
[#1681]: https://github.com/stackabletech/docker-images/pull/1681
[#1682]: https://github.com/stackabletech/docker-images/pull/1682

## [26.7.0] - 2026-07-21

Expand Down
15 changes: 12 additions & 3 deletions airflow/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -130,7 +130,10 @@ ARCH="${TARGETARCH/amd64/x64}"
mkdir -p /opt/node-cdxgen
curl "https://repo.stackable.tech/repository/packages/node/node-v${CDXGEN_NODEJS_VERSION}-linux-${ARCH}.tar.xz" | \
tar --extract --xz --directory=/opt/node-cdxgen --strip-components=1
PATH="/opt/node-cdxgen/bin:$PATH" npm install --global "@cdxgen/cdxgen@${CDXGEN_VERSION}"
# --ignore-scripts keeps the install scripts of (transitive) dependencies from running.
# --before only resolves versions published at least 7 days ago, including the transitive ones,
# so that a freshly published malicious version is not picked up before it is taken down.
PATH="/opt/node-cdxgen/bin:$PATH" npm install --global --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" "@cdxgen/cdxgen@${CDXGEN_VERSION}"
EOF

COPY airflow/stackable/constraints/${PRODUCT_VERSION}/constraints-python${PYTHON_VERSION}.txt /tmp/constraints.txt
Expand Down Expand Up @@ -180,7 +183,10 @@ if [ -d "./airflow-core" ]; then

# build front-end assets
# TODO: Consider making the pnpm version an ARG
npm install -g pnpm@10.18.2
# --ignore-scripts keeps the install scripts of (transitive) dependencies from running.
# --before only resolves versions published at least 7 days ago, including the transitive ones,
# so that a freshly published malicious version is not picked up before it is taken down.
npm install -g --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" pnpm@10.18.2
pnpm install --frozen-lockfile
pnpm run build

Expand Down Expand Up @@ -212,7 +218,10 @@ else
# build front-end assets
cd airflow/www
# TODO: Consider making the yarn version an ARG
npm install -g yarn@1.22.22
# --ignore-scripts keeps the install scripts of (transitive) dependencies from running.
# --before only resolves versions published at least 7 days ago, including the transitive ones,
# so that a freshly published malicious version is not picked up before it is taken down.
npm install -g --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" yarn@1.22.22
yarn install --frozen-lockfile
yarn run build

Expand Down
7 changes: 5 additions & 2 deletions druid/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,10 @@ ARCH="${TARGETARCH/amd64/x64}"
mkdir -p /opt/node-cdxgen
curl "https://repo.stackable.tech/repository/packages/node/node-v${CDXGEN_NODEJS_VERSION}-linux-${ARCH}.tar.xz" | \
tar --extract --xz --directory=/opt/node-cdxgen --strip-components=1
PATH="/opt/node-cdxgen/bin:$PATH" npm install --global "@cdxgen/cdxgen@${CDXGEN_VERSION}"
# --ignore-scripts keeps the install scripts of (transitive) dependencies from running.
# --before only resolves versions published at least 7 days ago, including the transitive ones,
# so that a freshly published malicious version is not picked up before it is taken down.
PATH="/opt/node-cdxgen/bin:$PATH" npm install --global --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" "@cdxgen/cdxgen@${CDXGEN_VERSION}"
EOF

USER ${STACKABLE_USER_UID}
Expand Down Expand Up @@ -80,7 +83,7 @@ rm /tmp/DRUID_SOURCE_DIR
ORIGINAL_VERSION=$(mvn help:evaluate -Dexpression=project.version -q -DforceStdout)
NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}"

mvn versions:set -DnewVersion=$NEW_VERSION
mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION

# Make Maven aware of custom Stackable libraries
cp -r /stackable/patched-libs/maven/* /stackable/.m2/repository
Expand Down
2 changes: 1 addition & 1 deletion hadoop/hadoop/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -83,7 +83,7 @@ cd "$(/stackable/patchable --images-repo-root=src checkout hadoop/hadoop ${PRODU
ORIGINAL_VERSION=$(mvn help:evaluate -Dexpression=project.version -q -DforceStdout)
NEW_VERSION=${PRODUCT_VERSION}-stackable${RELEASE_VERSION}

mvn versions:set -DnewVersion=${NEW_VERSION}
mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=${NEW_VERSION}

# Since we skip building the hadoop-pipes module, we need to set the version to the original version so it can be pulled from Maven Central
sed -e '/<artifactId>hadoop-pipes<\/artifactId>/,/<\/dependency>/ { s/<version>.*<\/version>/<version>'"$ORIGINAL_VERSION"'<\/version>/ }' -i hadoop-tools/hadoop-tools-dist/pom.xml
Expand Down
2 changes: 1 addition & 1 deletion hbase/hbase-operator-tools/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ NEW_VERSION="${HBASE_OPERATOR_TOOLS_VERSION}-stackable${RELEASE_VERSION}"
FULL_HBASE_OPERATOR_TOOLS_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}" # This includes the HBase version and the Stackable release suffix
PATCHED_HBASE_VERSION="${HBASE_VERSION}-stackable${RELEASE_VERSION}"

mvn versions:set -DnewVersion=$NEW_VERSION
mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION

# Create snapshot of the source code including custom patches
tar -czf /stackable/hbase-operator-tools-${FULL_HBASE_OPERATOR_TOOLS_VERSION}-src.tar.gz .
Expand Down
7 changes: 5 additions & 2 deletions hbase/hbase/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,10 @@ ARCH="${TARGETARCH/amd64/x64}"
mkdir -p /opt/node-cdxgen
curl "https://repo.stackable.tech/repository/packages/node/node-v${CDXGEN_NODEJS_VERSION}-linux-${ARCH}.tar.xz" | \
tar --extract --xz --directory=/opt/node-cdxgen --strip-components=1
PATH="/opt/node-cdxgen/bin:$PATH" npm install --global "@cdxgen/cdxgen@${CDXGEN_VERSION}"
# --ignore-scripts keeps the install scripts of (transitive) dependencies from running.
# --before only resolves versions published at least 7 days ago, including the transitive ones,
# so that a freshly published malicious version is not picked up before it is taken down.
PATH="/opt/node-cdxgen/bin:$PATH" npm install --global --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" "@cdxgen/cdxgen@${CDXGEN_VERSION}"

microdnf update
microdnf install python3
Expand Down Expand Up @@ -70,7 +73,7 @@ cp -r /stackable/patched-libs/maven/* /stackable/.m2/repository
ORIGINAL_VERSION=$(mvn help:evaluate -Dexpression=project.version -q -DforceStdout)
NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}"

mvn versions:set -DnewVersion=$NEW_VERSION
mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION

# Create snapshot of the source code including custom patches
tar -czf /stackable/hbase-${NEW_VERSION}-src.tar.gz .
Expand Down
2 changes: 1 addition & 1 deletion hbase/phoenix/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ cd "$(/stackable/patchable --images-repo-root=src checkout phoenix ${PHOENIX_VER
ORIGINAL_VERSION=$(mvn help:evaluate -Dexpression=project.version -q -DforceStdout)
NEW_VERSION="${PHOENIX_VERSION}-stackable${RELEASE_VERSION}"

mvn versions:set -DnewVersion=$NEW_VERSION
mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION

# Create snapshot of the source code including custom patches
tar -czf /stackable/phoenix-${PRODUCT_VERSION}-stackable${RELEASE_VERSION}-src.tar.gz .
Expand Down
2 changes: 1 addition & 1 deletion hive/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -54,7 +54,7 @@ cd "$BUILD_SRC_DIR"
cp -r /stackable/patched-libs/maven/* /stackable/.m2/repository

# generateBackupPoms=false is needed for the Hive 4.0.0 build to succeed, otherwise it fails with the obscure reason: `Too many files with unapproved license`
mvn versions:set -DnewVersion=$NEW_VERSION -DartifactId=* -DgroupId=* -DgenerateBackupPoms=false
mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION -DartifactId=* -DgroupId=* -DgenerateBackupPoms=false

# Create snapshot of the source code including custom patches
tar -czf /stackable/hive-${NEW_VERSION}-src.tar.gz .
Expand Down
2 changes: 1 addition & 1 deletion hive/hive-metastore-opa-authorizer/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,7 @@ tar -czf /stackable/opa-authorizer-src/hive-metastore-opa-authorizer-${AUTHORIZE
cp -r /stackable/patched-libs/maven/* /stackable/.m2/repository

# Set version
mvn versions:set -DnewVersion=${AUTHORIZER_VERSION}
mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=${AUTHORIZER_VERSION}

# The if part can be removed once we do no longer support Hive 3.x.x
# Hive 3.1.3 only works with the shaded jar
Expand Down
6 changes: 6 additions & 0 deletions java-devel/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -68,6 +68,12 @@ EOF
ENV JAVA_HOME="/usr/lib/jvm/temurin-${PRODUCT_VERSION}-jdk"
ENV MAVEN_ARGS="--batch-mode --no-transfer-progress"

# Plugins that are invoked by prefix on the command line (e.g. `mvn versions:set`) resolve to their
# latest release unless the project POM pins them, so their version would change silently between builds.
# Find the latest version here: https://github.com/mojohaus/versions/releases
# renovate: datasource=maven packageName=org.codehaus.mojo:versions-maven-plugin
ENV VERSIONS_MAVEN_PLUGIN_VERSION="2.22.0"

ARG GITHUB_RUN_ATTEMPT="<unknown>"
ENV GITHUB_RUN_ATTEMPT=${GITHUB_RUN_ATTEMPT}

Expand Down
7 changes: 5 additions & 2 deletions nifi/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,10 @@ ARCH="${TARGETARCH/amd64/x64}"
mkdir -p /opt/node-cdxgen
curl "https://repo.stackable.tech/repository/packages/node/node-v${CDXGEN_NODEJS_VERSION}-linux-${ARCH}.tar.xz" | \
tar --extract --xz --directory=/opt/node-cdxgen --strip-components=1
PATH="/opt/node-cdxgen/bin:$PATH" npm install --global "@cdxgen/cdxgen@${CDXGEN_VERSION}"
# --ignore-scripts keeps the install scripts of (transitive) dependencies from running.
# --before only resolves versions published at least 7 days ago, including the transitive ones,
# so that a freshly published malicious version is not picked up before it is taken down.
PATH="/opt/node-cdxgen/bin:$PATH" npm install --global --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" "@cdxgen/cdxgen@${CDXGEN_VERSION}"
EOF

USER ${STACKABLE_USER_UID}
Expand All @@ -56,7 +59,7 @@ cd "$(/stackable/patchable --images-repo-root=src checkout nifi ${PRODUCT_VERSIO
ORIGINAL_VERSION=$(mvn help:evaluate -Dexpression=project.version -q -DforceStdout)
NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}"

mvn versions:set -DnewVersion=$NEW_VERSION
mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION

# Create snapshot of the source code including custom patches
tar -czf /stackable/nifi-${NEW_VERSION}-src.tar.gz .
Expand Down
2 changes: 1 addition & 1 deletion omid/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@ RUN --mount=type=cache,id=maven-omid-${PRODUCT_VERSION},uid=${STACKABLE_USER_UID
ORIGINAL_VERSION=$(mvn help:evaluate -Dexpression=project.version -q -DforceStdout)
NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}"

mvn versions:set -DnewVersion=$NEW_VERSION
mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION

# Create snapshot of the source code including custom patches
tar -czf /stackable/omid-${NEW_VERSION}-src.tar.gz .
Expand Down
10 changes: 8 additions & 2 deletions opensearch-dashboards/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -141,7 +141,10 @@ microdnf clean all
rm -rf /var/cache/yum
curl "https://repo.stackable.tech/repository/packages/node/node-v${NODEJS_VERSION}-linux-${ARCH}.tar.xz" | \
tar --extract --xz --directory=/usr/local --strip-components=1
npm install -g yarn@${YARN_VERSION}
# --ignore-scripts keeps the install scripts of (transitive) dependencies from running.
# --before only resolves versions published at least 7 days ago, including the transitive ones,
# so that a freshly published malicious version is not picked up before it is taken down.
npm install -g --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" yarn@${YARN_VERSION}

# cdxgen requires Node >= 24, which is newer than the Node version OpenSearch Dashboards
# is built with, so it gets its own Node installation in /opt/node-cdxgen and is invoked
Expand All @@ -150,7 +153,10 @@ npm install -g yarn@${YARN_VERSION}
mkdir -p /opt/node-cdxgen
curl "https://repo.stackable.tech/repository/packages/node/node-v${CDXGEN_NODEJS_VERSION}-linux-${ARCH}.tar.xz" | \
tar --extract --xz --directory=/opt/node-cdxgen --strip-components=1
PATH="/opt/node-cdxgen/bin:$PATH" npm install --global "@cdxgen/cdxgen@${CDXGEN_VERSION}"
# --ignore-scripts keeps the install scripts of (transitive) dependencies from running.
# --before only resolves versions published at least 7 days ago, including the transitive ones,
# so that a freshly published malicious version is not picked up before it is taken down.
PATH="/opt/node-cdxgen/bin:$PATH" npm install --global --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" "@cdxgen/cdxgen@${CDXGEN_VERSION}"
EOF

USER ${STACKABLE_USER_UID}
Expand Down
2 changes: 1 addition & 1 deletion precompiled/hadoop/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -61,7 +61,7 @@ cd "$(/stackable/patchable --images-repo-root=src checkout precompiled/hadoop ${
ORIGINAL_VERSION=$(mvn help:evaluate -Dexpression=project.version -q -DforceStdout)
NEW_VERSION=${PRODUCT_VERSION}-stackable${RELEASE_VERSION}

mvn versions:set -DnewVersion=${NEW_VERSION}
mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=${NEW_VERSION}

# Since we skip building the hadoop-pipes module, we need to set the version to the original version so it can be pulled from Maven Central
sed -e '/<artifactId>hadoop-pipes<\/artifactId>/,/<\/dependency>/ { s/<version>.*<\/version>/<version>'"$ORIGINAL_VERSION"'<\/version>/ }' -i hadoop-tools/hadoop-tools-dist/pom.xml
Expand Down
2 changes: 1 addition & 1 deletion spark-k8s/Dockerfile.3
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ cd "$(/stackable/patchable --images-repo-root=src checkout spark-k8s ${PRODUCT_V

NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}"

mvn versions:set -DnewVersion=$NEW_VERSION
mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION

# Create snapshot of the source code including custom patches
tar -czf /stackable/spark-${PRODUCT_VERSION}-stackable${RELEASE_VERSION}-src.tar.gz .
Expand Down
2 changes: 1 addition & 1 deletion spark-k8s/Dockerfile.4
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ cd "$(/stackable/patchable --images-repo-root=src checkout spark-k8s ${PRODUCT_V

NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}"

mvn versions:set -DnewVersion=$NEW_VERSION
mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION

# Create snapshot of the source code including custom patches
tar -czf /stackable/spark-${PRODUCT_VERSION}-stackable${RELEASE_VERSION}-src.tar.gz .
Expand Down
2 changes: 1 addition & 1 deletion spark-k8s/hbase-connectors/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -78,7 +78,7 @@ cd "$(/stackable/patchable --images-repo-root=src checkout spark-k8s/hbase-conne

NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}"

mvn versions:set -DnewVersion=$NEW_VERSION
mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION

# Create snapshot of the source code including custom patches
tar -czf /stackable/hbase-connector-${NEW_VERSION}-src.tar.gz .
Expand Down
13 changes: 10 additions & 3 deletions superset/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -46,6 +46,7 @@ ARG CDXGEN_NODEJS_VERSION
ARG CDXGEN_SPEC_VERSION
ARG UV_VERSION
ARG NODEJS_VERSION
ARG NPM_VERSION
ARG NVM_VERSION
ARG STACKABLE_USER_UID

Expand Down Expand Up @@ -101,8 +102,11 @@ mkdir -p "${NVM_DIR}"
curl "https://repo.stackable.tech/repository/packages/nvm/nvm-${NVM_VERSION}.sh" -o "${NVM_DIR}/nvm.sh"
. "${NVM_DIR}/nvm.sh"

# Install the specified version of Node (including the latest compatible version of npm)
nvm install "$NODEJS_VERSION" --latest-npm
# Install the specified versions of Node and npm.
# --latest-npm is not used because it installs whatever npm version is newest at build time.
# See the cdxgen install below for --ignore-scripts and --before.
nvm install "$NODEJS_VERSION"
npm install --global --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" "npm@${NPM_VERSION}"

node --version
npm --version
Expand All @@ -117,7 +121,10 @@ ARCH="${TARGETARCH/amd64/x64}"
mkdir -p /opt/node-cdxgen
curl "https://repo.stackable.tech/repository/packages/node/node-v${CDXGEN_NODEJS_VERSION}-linux-${ARCH}.tar.xz" | \
tar --extract --xz --directory=/opt/node-cdxgen --strip-components=1
PATH="/opt/node-cdxgen/bin:$PATH" npm install --global "@cdxgen/cdxgen@${CDXGEN_VERSION}"
# --ignore-scripts keeps the install scripts of (transitive) dependencies from running.
# --before only resolves versions published at least 7 days ago, including the transitive ones,
# so that a freshly published malicious version is not picked up before it is taken down.
PATH="/opt/node-cdxgen/bin:$PATH" npm install --global --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" "@cdxgen/cdxgen@${CDXGEN_VERSION}"
EOF

# Upgrade pip to the latest version
Expand Down
5 changes: 5 additions & 0 deletions superset/boil-config.toml
Original file line number Diff line number Diff line change
Expand Up @@ -28,6 +28,8 @@ python-version = "3.11"
uv-version = "0.11.18"
# https://github.com/apache/superset/blob/4.1.4/superset-frontend/.nvmrc
nodejs-version = "18.20.1"
# The latest 10.x release. 11.x requires Node ^20.17.0 || >=22.9.0.
npm-version = "10.9.9"
# Independent of Superset, use the latest release: https://github.com/nvm-sh/nvm/releases
nvm-version = "v0.40.4"

Expand Down Expand Up @@ -58,5 +60,8 @@ python-version = "3.12"
uv-version = "0.11.18"
# https://github.com/apache/superset/blob/6.1.0/superset-frontend/.nvmrc
nodejs-version = "22.22.0"
# npm 12 requires Node ^22.22.2, so the latest npm (which --latest-npm used to install) is not
# supported on this Node version. Kept on 10.x like 4.1.4, which is the version Node 22 bundles.
npm-version = "10.9.9"
# Independent of Superset, use the latest release: https://github.com/nvm-sh/nvm/releases
nvm-version = "v0.40.4"
2 changes: 1 addition & 1 deletion trino/airlift/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ cd "$(/stackable/patchable --images-repo-root=src checkout trino/airlift ${PRODU

NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}"

mvn versions:set -DnewVersion=$NEW_VERSION -DartifactId='*' -DgroupId='*' -DgenerateBackupPoms=false
mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION -DartifactId='*' -DgroupId='*' -DgenerateBackupPoms=false

mvn \
install \
Expand Down
2 changes: 1 addition & 1 deletion trino/storage-connector/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -30,7 +30,7 @@ NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}"
# Create snapshot of the source code including custom patches
tar -czf /stackable/trino-storage-connector-${NEW_VERSION}-src.tar.gz .

mvn versions:set -DnewVersion=${NEW_VERSION}
mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=${NEW_VERSION}

mvn \
package \
Expand Down
7 changes: 5 additions & 2 deletions trino/trino/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -30,7 +30,10 @@ ARCH="${TARGETARCH/amd64/x64}"
mkdir -p /opt/node-cdxgen
curl "https://repo.stackable.tech/repository/packages/node/node-v${CDXGEN_NODEJS_VERSION}-linux-${ARCH}.tar.xz" | \
tar --extract --xz --directory=/opt/node-cdxgen --strip-components=1
PATH="/opt/node-cdxgen/bin:$PATH" npm install --global "@cdxgen/cdxgen@${CDXGEN_VERSION}"
# --ignore-scripts keeps the install scripts of (transitive) dependencies from running.
# --before only resolves versions published at least 7 days ago, including the transitive ones,
# so that a freshly published malicious version is not picked up before it is taken down.
PATH="/opt/node-cdxgen/bin:$PATH" npm install --global --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" "@cdxgen/cdxgen@${CDXGEN_VERSION}"

microdnf update
microdnf install python3
Expand All @@ -51,7 +54,7 @@ cp -r /stackable/patched-libs/maven/* /root/.m2/repository

NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}"

mvn versions:set -DnewVersion=$NEW_VERSION
mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION

# Create snapshot of the source code including custom patches
tar -czf /stackable/trino-${NEW_VERSION}-src.tar.gz .
Expand Down
Loading
Loading