agentsclimarketplace

Run2 druid patching checklist

Skill cxcscmu/SkillLearnBench/skills/b2-self-feedback-gemini-3-flash-preview/fix-security-bug/run2_druid-patching-checklist

A checklist for ensuring thorough patching of Apache Druid security vulnerabilities.From its SKILL.md

Install
npx -y skills add cxcscmu/SkillLearnBench --skill run2_druid-patching-checklist

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

SKILL.md

1.1 KB, 207 tokens by cl100k_base, as published. Nobody here has run it

Druid Patching Checklist

When applying security patches to Druid, ensure you cover all affected areas:

  1. Grep for Patterns: Search for all instances of the vulnerable pattern (e.g., @JacksonInject JavaScriptConfig).
  2. Apply Consistent Fixes: Use the same robust fix across all occurrences.
  3. Import Management:
    • Ensure all required classes (like OptBoolean) are imported.
    • Be careful not to accidentally remove existing imports (like com.google.common.base.Function).
  4. Parameter Name Accuracy: Verify the parameter names in the @JsonCreator constructors. Some use fn while others use function.
  5. Verify Project Structure: Ensure patches are applied to the correct modules (core, processing, server, indexing-service).
  6. Build Verification: Run a full build of the affected modules to catch compilation errors.
  7. Patch Generation: Generate a clean git diff and save it to the patches/ directory.

What ships with it

Read from the repository

Just SKILL.md. No reference files, no scripts.

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.