Uploaded image for project: 'Red Hat Fuse'
  1. Red Hat Fuse
  2. ENTESB-19671

The supported trait jolokia doesn't use productised artifacts

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Blocker Blocker
    • camel-k-1.10
    • camel-k-1.8
    • Camel-K
    • None

      Clarification:

      • What does Build From Source mean for Camel K?
      • Should Camel K comply with Build From Source?

      Following artefacts used by jolokia trait aren't productised:

      • camel-management/camel-quarkus-management
      • mvn:org.jolokia:jolokia-jvm:jar:1.7.1

      https://github.com/apache/camel-k/blob/3cedfa0ddcb840db933d1574a20b46a7dcfab38e/pkg/trait/jolokia.go#L61-L66

      CEQ understanding of Build From Source means:

      • If any supported functionality of a product isn't backed up by redhat built jars, the product doesn't comply with Build From Source.
      • If you don't use redhat build jars, CVE detection done by ProdSec may not work.

      I suspect that this haven't been checked in the past.

            cmiranda@redhat.com Claudio Miranda
            vkasala@redhat.com Viliam Kasala
            Votes:
            0 Vote for this issue
            Watchers:
            8 Start watching this issue

              Created:
              Updated:
              Resolved: