Skip to content
Snippets Groups Projects
This project is mirrored from https://github.com/metabase/metabase. Pull mirroring updated .
  1. Nov 09, 2022
  2. Nov 08, 2022
  3. Nov 07, 2022
    • alexandermkinn's avatar
      Fix typo (#25372) · cc589cf0
      alexandermkinn authored
      
      Co-authored-by: default avatarJeff Bruemmer <jeff.bruemmer@gmail.com>
      Unverified
      cc589cf0
    • Bryan Maass's avatar
      Use all text scorers in the final result to increase scoring signal (#26026) · 1c6e8109
      Bryan Maass authored
      * Uses all text scorers in the final result
      
      - instead of just the maximum one
      - add tests
      
      * add prefix scorer test + fix text-score-with
      
      * linter fixes
      
      * pass in number of results to find
      
      * refactor test function
      
      * fix linter by removing unused namespace: metabase.util
      
      * limit arity of serialize to 3
      
      * make oss-score and ee-score different things
      
      - They were defined to be exactly the same, but should be different!
      - Update some tests that broke when a test function was fixed
      
      * remove extra let
      
      * move rseq back out of sorted-take
      
      * improve test feedback
      
      * force weight of text based scorers always weigh 10
      
      * handle 0 score/weights when normalizing scores
      
      * add nil check
      
      * fix more subtle test differences
      
      * more test fiddling
      
      - still test that :offset and :limit respect limits
      
      * reuse bit->boolean from api collection
      
      * clean up some tests
      
      - filter -> remove
      - replace some magic numbers
      - revert to testing entire maps instead of names of sorted items
      
      * add test, docstring, and weight
      
      * sort ns requires
      
      * responding to most of the review comments
      
      * start our zero-score sum check with 0
      
      * do not tokenize / normalize nil raw-search-string
      
      * force equality in basic search test
      
      * modify test to work in dev and test environments
      
      * use display_name in results when appropriate
      
      - This was looking for the _first_ column that had a non-zero score, but
      actually we need to consider all relevant columns.
      - Uses them to figure out if there is a display name, and if there is,
      to use it.
      - Coppied over the logic about showing :context from the prior approach
      Unverified
      1c6e8109
    • Nick Fitzpatrick's avatar
      Adding Tests for hasColumnSettings, Fixing currency bug (#26171) · deeaed9c
      Nick Fitzpatrick authored
      * Adding Tests for hasColumnSettings
      
      * Updating Comment
      Unverified
      deeaed9c
    • Jeff Bruemmer's avatar
      docs - add week function (#26152) · 25dbd2e9
      Jeff Bruemmer authored
      
      * add week function
      
      * Update docs/questions/query-builder/expressions-list.md
      
      Co-authored-by: default avatarNatalie <nat@metabase.com>
      
      * update copy
      
      * formatting
      
      Co-authored-by: default avatarNatalie <nat@metabase.com>
      Unverified
      25dbd2e9
    • Alexander Polyankin's avatar
    • Alexander Polyankin's avatar
    • dpsutton's avatar
      Bump woodstox : CVE-2022-40151 (#26269) · 84df58aa
      dpsutton authored
      First seen in trivy report:
      https://github.com/metabase/metabase/pull/26161/checks?check_run_id=9326286850
      
      CVE:
      https://avd.aquasec.com/nvd/cve-2022-40151
      
      xstream: Xstream to serialise XML data was vulnerable to Denial of
      Service attacks High
      Package: com.fasterxml.woodstox:woodstox-core
      Installed Version: 6.2.6
      Vulnerability CVE-2022-40151
      Severity: HIGH
      Fixed Version: 5.4.0, 6.4.0
      
      Bumping deps and comparing `clj -X:deps tree` shows the change only adds
      the new dep top level and no new deps are brought in by the change.
      
      ```
      ❯ diff --unified deps deps-updated
      --- deps	2022-11-07 08:43:21.000000000 -0600
      +++ deps-updated	2022-11-07 08:49:56.000000000 -0600
      @@ -9,6 +9,8 @@
         X org.slf4j/slf4j-api 1.7.25 :use-top
         X org.apache.logging.log4j/log4j-api 2.18.0 :use-top
         X org.apache.logging.log4j/log4j-core 2.18.0 :use-top
      +com.fasterxml.woodstox/woodstox-core 6.4.0
      +  . org.codehaus.woodstox/stax2-api 4.2.1
       joda-time/joda-time 2.10.13
       commons-codec/commons-codec 1.15
       weavejester/dependency 0.2.1
      @@ -285,8 +287,7 @@
         . org.apache.santuario/xmlsec 2.3.0
           X org.slf4j/slf4j-api 1.7.32 :use-top
           X commons-codec/commons-codec 1.15 :use-top
      -    . com.fasterxml.woodstox/woodstox-core 6.2.6
      -      . org.codehaus.woodstox/stax2-api 4.2.1
      +    X com.fasterxml.woodstox/woodstox-core 6.2.6 :use-top
           . jakarta.xml.bind/jakarta.xml.bind-api 2.3.3
             . jakarta.activation/jakarta.activation-api 1.2.2
         . org.opensaml/opensaml-xmlsec-api 3.4.6
      ```
      Unverified
      84df58aa
    • Natalie's avatar
      replace quotation marks (#26252) · 21d45497
      Natalie authored
      Unverified
      21d45497
    • Braden Shepherdson's avatar
      Serdes v2: Search for dependencies both on the filesystem and the appdb (#26217) · 1e4fb63b
      Braden Shepherdson authored
      This allows smaller selective exports that (for example) don't need to
      include the data model if you know the other side has it.
      Unverified
      1e4fb63b
  4. Nov 05, 2022
  5. Nov 04, 2022
  6. Nov 03, 2022
  7. Nov 02, 2022
  8. Nov 01, 2022
Loading