Skip to content

[Snyk] Security upgrade org.opensearch.client:opensearch-java from 3.4.0 to 3.6.0#27048

Open
chirag-madlani wants to merge 2 commits intomainfrom
snyk-fix-e5c084890c8489659c8c42a73d9a243a
Open

[Snyk] Security upgrade org.opensearch.client:opensearch-java from 3.4.0 to 3.6.0#27048
chirag-madlani wants to merge 2 commits intomainfrom
snyk-fix-e5c084890c8489659c8c42a73d9a243a

Conversation

@chirag-madlani
Copy link
Copy Markdown
Collaborator

@chirag-madlani chirag-madlani commented Apr 5, 2026

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the maven dependencies of this project.

Snyk changed the following file(s):

  • openmetadata-shaded-deps/opensearch-dep/pom.xml

Vulnerabilities that will be fixed with an upgrade:

Issue Upgrade
high severity Denial of Service (DoS)
SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-15857052
org.opensearch.client:opensearch-java:
3.4.0 -> 3.6.0
No Known Exploit

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Denial of Service (DoS)


Summary by Gitar

  • Feature addition:
    • Added export functionality for search in commit 9da7bea4.

This will update automatically on new commits.

Copilot AI review requested due to automatic review settings April 5, 2026 04:20
@github-actions github-actions Bot added safe to test Add this label to run secure Github workflows on PRs UI UI specific issues labels Apr 5, 2026
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the shaded OpenSearch Java client dependency used by the server to address a reported DoS vulnerability in a transitive Apache HttpComponents Core 5 dependency path.

Changes:

  • Bump org.opensearch.client:opensearch-java from 3.4.0 to 3.6.0 in the OpenSearch shaded-deps module.

@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented Apr 5, 2026

🔴 Playwright Results — 93 failure(s), 15 flaky

✅ 271 passed · ❌ 93 failed · 🟡 15 flaky · ⏭️ 80 skipped

Shard Passed Failed Flaky Skipped
🔴 Shard 1 271 93 15 80

Genuine Failures (failed on all attempts)

Features/DataAssetRulesEnabled.spec.ts › Verify the ApiEndpoint Entity Action items after rules is Enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/DataAssetRulesEnabled.spec.ts › Verify the Table Entity Action items after rules is Enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/DataAssetRulesEnabled.spec.ts › Verify the Store Procedure Entity Action items after rules is Enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/DataAssetRulesEnabled.spec.ts › Verify the Dashboard Entity Action items after rules is Enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/DataAssetRulesEnabled.spec.ts › Verify the Pipeline Entity Action items after rules is Enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/DataAssetRulesEnabled.spec.ts › Verify the Topic Entity Action items after rules is Enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/DataAssetRulesEnabled.spec.ts › Verify the MlModel Entity Action items after rules is Enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/DataAssetRulesEnabled.spec.ts › Verify the Container Entity Action items after rules is Enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/DataAssetRulesEnabled.spec.ts › Verify the SearchIndex Entity Action items after rules is Enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/DataAssetRulesEnabled.spec.ts › Verify the DashboardDataModel Entity Action items after rules is Enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/DataAssetRulesEnabled.spec.ts › Verify the Metric Entity Action items after rules is Enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/DataAssetRulesEnabled.spec.ts › Verify the Chart Entity Action items after rules is Enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/DataAssetRulesEnabled.spec.ts › Verify the Directory Entity Action items after rules is Enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/DataAssetRulesEnabled.spec.ts › Verify the File Entity Action items after rules is Enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/DataAssetRulesEnabled.spec.ts › Verify the Spreadsheet Entity Action items after rules is Enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/DataAssetRulesEnabled.spec.ts › Verify the Worksheet Entity Action items after rules is Enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/DataAssetRulesEnabled.spec.ts › Verify the Api Service Entity Action items after rules is Enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/DataAssetRulesEnabled.spec.ts › Verify the Api Collection Entity Action items after rules is Enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/DataAssetRulesEnabled.spec.ts › Verify the Database Service Entity Action items after rules is Enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/DataAssetRulesEnabled.spec.ts › Verify the Dashboard Service Entity Action items after rules is Enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/DataAssetRulesEnabled.spec.ts › Verify the Messaging Service Entity Action items after rules is Enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/DataAssetRulesEnabled.spec.ts › Verify the MlModel Service Entity Action items after rules is Enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/DataAssetRulesEnabled.spec.ts › Verify the Pipeline Service Entity Action items after rules is Enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/DataAssetRulesEnabled.spec.ts › Verify the SearchIndex Service Entity Action items after rules is Enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/DataAssetRulesEnabled.spec.ts › Verify the Storage Service Entity Action items after rules is Enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/DataAssetRulesEnabled.spec.ts › Verify the Database Entity Action items after rules is Enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/DataAssetRulesEnabled.spec.ts › Verify the Database Schema Entity Action items after rules is Enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/DataAssetRulesEnabled.spec.ts › Verify the Drive Service Entity Action items after rules is Enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/DataAssetRulesEnabled.spec.ts › should enforce single domain selection for glossary term when entity rules are enabled (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m
Features/CustomizeDetailPage.spec.ts › Topic - customization should work (shard 1)
�[31mTest timeout of 180000ms exceeded.�[39m

... and 63 more failures

🟡 15 flaky test(s) (passed on retry)
  • Features/CustomizeDetailPage.spec.ts › Validate Glossary Term details page after customization of tabs (shard 1, 1 retry)
  • Features/NavigationBlocker.spec.ts › should not show navigation blocker after saving changes (shard 1, 1 retry)
  • Pages/Customproperties-part1.spec.ts › Integer (shard 1, 2 retries)
  • Pages/Customproperties-part1.spec.ts › Integer (shard 1, 2 retries)
  • Pages/Customproperties-part1.spec.ts › Integer (shard 1, 2 retries)
  • Pages/Customproperties-part1.spec.ts › Duration (shard 1, 2 retries)
  • Pages/Customproperties-part1.spec.ts › Integer (shard 1, 2 retries)
  • Pages/Customproperties-part1.spec.ts › Sql Query (shard 1, 2 retries)
  • Pages/Customproperties-part1.spec.ts › Integer (shard 1, 2 retries)
  • Pages/Customproperties-part1.spec.ts › Integer (shard 1, 2 retries)
  • Pages/Customproperties-part1.spec.ts › Number (shard 1, 2 retries)
  • Pages/Customproperties-part1.spec.ts › Integer (shard 1, 2 retries)
  • Pages/Customproperties-part1.spec.ts › Integer (shard 1, 2 retries)
  • Pages/Customproperties-part1.spec.ts › Sql Query (shard 1, 2 retries)
  • Pages/Customproperties-part1.spec.ts › Integer (shard 1, 2 retries)

📦 Download artifacts

How to debug locally
# Download playwright-test-results-<shard> artifact and unzip
npx playwright show-trace path/to/trace.zip    # view trace

@gitar-bot
Copy link
Copy Markdown

gitar-bot Bot commented Apr 18, 2026

Code Review ✅ Approved

Security upgrade of opensearch-java to version 3.6.0 successfully updates dependencies. No issues found.

Options

Display: compact → Showing less information.

Comment with these commands to change:

Compact
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Gitar

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

safe to test Add this label to run secure Github workflows on PRs UI UI specific issues

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants