-
Notifications
You must be signed in to change notification settings - Fork 272
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Reproducible builds for plugins (and clients?) #2728
Comments
[Triage] Hi @MaxKsyunz , Can you please elaborate more on what do you mean by "reproducible"? Also what is expected to happen more precisely? |
Reproducible builds mean that two builds of the same source will generate the same binary. There's a site with more info. The main goal is greater security but it also improves developer experience as well. Here's a simplified of example how this affects development.
graph LR;
opensearch-sql ---> jackson-core;
opensearch-sql ---> opensearch-rest-high-level-client;
opensearch-rest-high-level-client ---> jackson-core;
Due to CVEs, Now someone needs to update As soon as this PR is merged, we'll run into this as well. |
Here's another issue in the same vane.
|
Hi @MaxKsyunz , Is this issue still valid? |
Seems like resolved right here now: Thanks. |
Is your feature request related to a problem? Please describe
Plugin builds depend on libraries from OpenSearch core. They also use a lot of the same packages.
jackson-databind
is a good example.Whenever core libraries bump the version of any such package, plugin builds start to fail until they bump the version as well.
It's disruptive whenever this happens.
Describe the solution you'd like
Plugin builds to be reproducible.
Describe alternatives you've considered
No response
Additional context
No response
The text was updated successfully, but these errors were encountered: