Skip to content

Potential Vulnerability in Cloned Code#109

Open
pr-hung wants to merge 1 commit intoopenjdk:masterfrom
pr-hung:clone-security-fix-1795e2b711
Open

Potential Vulnerability in Cloned Code#109
pr-hung wants to merge 1 commit intoopenjdk:masterfrom
pr-hung:clone-security-fix-1795e2b711

Conversation

@pr-hung
Copy link
Copy Markdown

@pr-hung pr-hung commented Feb 18, 2026

Summary

This PR fixes a potential security vulnerability in cloned code that appears to have missed an upstream security patch.

Details

What this PR does

  • Applies the upstream security fix logic to the cloned implementation in this repository.

References

Please review and merge this PR to ensure your repository is protected against this potential vulnerability.
Thank you for your time !


Progress

  • Change must be properly reviewed (1 review required, with at least 1 Reviewer)
  • Change must not contain extraneous whitespace
  • Commit message must refer to an issue

Error

 ⚠️ OCA signatory status must be verified

Reviewing

Using git

Checkout this PR locally:
$ git fetch https://git.openjdk.org/jdk11u.git pull/109/head:pull/109
$ git checkout pull/109

Update a local copy of the PR:
$ git checkout pull/109
$ git pull https://git.openjdk.org/jdk11u.git pull/109/head

Using Skara CLI tools

Checkout this PR locally:
$ git pr checkout 109

View PR using the GUI difftool:
$ git pr show -t 109

Using diff file

Download this PR as a diff file:
https://git.openjdk.org/jdk11u/pull/109.diff

@bridgekeeper bridgekeeper bot added the oca Needs verification of OCA signatory status label Feb 18, 2026
@bridgekeeper
Copy link
Copy Markdown

bridgekeeper bot commented Feb 18, 2026

Hi @pr-hung, welcome to this OpenJDK project and thanks for contributing!

We do not recognize you as Contributor and need to ensure you have signed the Oracle Contributor Agreement (OCA). If you have not signed the OCA, please follow the instructions. Please fill in your GitHub username in the "Username" field of the application. Once you have signed the OCA, please let us know by writing /signed in a comment in this pull request.

If you already are an OpenJDK Author, Committer or Reviewer, please click here to open a new issue so that we can record that fact. Please use "Add GitHub user pr-hung" as summary for the issue.

If you are contributing this work on behalf of your employer and your employer has signed the OCA, please let us know by writing /covered in a comment in this pull request.

@openjdk
Copy link
Copy Markdown

openjdk bot commented Feb 18, 2026

❗ This change is not yet ready to be integrated.
See the Progress checklist in the description for automated requirements.

@pr-hung pr-hung marked this pull request as ready for review February 19, 2026 02:25
@gnu-andrew
Copy link
Copy Markdown
Member

If you believe there is a vulnerability, it should be reported through the proper channels: https://openjdk.org/groups/vulnerability/report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

oca Needs verification of OCA signatory status

Development

Successfully merging this pull request may close these issues.

2 participants