Run2 druid patching checklist
A checklist for ensuring thorough patching of Apache Druid security vulnerabilities.From its SKILL.md
npx -y skills add cxcscmu/SkillLearnBench --skill run2_druid-patching-checklistAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
SKILL.md
1.1 KB, 207 tokens by cl100k_base, as published. Nobody here has run it
Druid Patching Checklist
When applying security patches to Druid, ensure you cover all affected areas:
- Grep for Patterns: Search for all instances of the vulnerable pattern (e.g.,
@JacksonInject JavaScriptConfig). - Apply Consistent Fixes: Use the same robust fix across all occurrences.
- Import Management:
- Ensure all required classes (like
OptBoolean) are imported. - Be careful not to accidentally remove existing imports (like
com.google.common.base.Function).
- Ensure all required classes (like
- Parameter Name Accuracy: Verify the parameter names in the
@JsonCreatorconstructors. Some usefnwhile others usefunction. - Verify Project Structure: Ensure patches are applied to the correct modules (core, processing, server, indexing-service).
- Build Verification: Run a full build of the affected modules to catch compilation errors.
- Patch Generation: Generate a clean
git diffand save it to thepatches/directory.
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.