Skip to content
Snippets Groups Projects
This project is mirrored from https://github.com/metabase/metabase. Pull mirroring updated .
  1. Nov 10, 2022
  2. Nov 09, 2022
  3. Nov 08, 2022
  4. Nov 07, 2022
    • alexandermkinn's avatar
      Fix typo (#25372) · cc589cf0
      alexandermkinn authored
      
      Co-authored-by: default avatarJeff Bruemmer <jeff.bruemmer@gmail.com>
      Unverified
      cc589cf0
    • Bryan Maass's avatar
      Use all text scorers in the final result to increase scoring signal (#26026) · 1c6e8109
      Bryan Maass authored
      * Uses all text scorers in the final result
      
      - instead of just the maximum one
      - add tests
      
      * add prefix scorer test + fix text-score-with
      
      * linter fixes
      
      * pass in number of results to find
      
      * refactor test function
      
      * fix linter by removing unused namespace: metabase.util
      
      * limit arity of serialize to 3
      
      * make oss-score and ee-score different things
      
      - They were defined to be exactly the same, but should be different!
      - Update some tests that broke when a test function was fixed
      
      * remove extra let
      
      * move rseq back out of sorted-take
      
      * improve test feedback
      
      * force weight of text based scorers always weigh 10
      
      * handle 0 score/weights when normalizing scores
      
      * add nil check
      
      * fix more subtle test differences
      
      * more test fiddling
      
      - still test that :offset and :limit respect limits
      
      * reuse bit->boolean from api collection
      
      * clean up some tests
      
      - filter -> remove
      - replace some magic numbers
      - revert to testing entire maps instead of names of sorted items
      
      * add test, docstring, and weight
      
      * sort ns requires
      
      * responding to most of the review comments
      
      * start our zero-score sum check with 0
      
      * do not tokenize / normalize nil raw-search-string
      
      * force equality in basic search test
      
      * modify test to work in dev and test environments
      
      * use display_name in results when appropriate
      
      - This was looking for the _first_ column that had a non-zero score, but
      actually we need to consider all relevant columns.
      - Uses them to figure out if there is a display name, and if there is,
      to use it.
      - Coppied over the logic about showing :context from the prior approach
      Unverified
      1c6e8109
    • Nick Fitzpatrick's avatar
      Adding Tests for hasColumnSettings, Fixing currency bug (#26171) · deeaed9c
      Nick Fitzpatrick authored
      * Adding Tests for hasColumnSettings
      
      * Updating Comment
      Unverified
      deeaed9c
    • Jeff Bruemmer's avatar
      docs - add week function (#26152) · 25dbd2e9
      Jeff Bruemmer authored
      
      * add week function
      
      * Update docs/questions/query-builder/expressions-list.md
      
      Co-authored-by: default avatarNatalie <nat@metabase.com>
      
      * update copy
      
      * formatting
      
      Co-authored-by: default avatarNatalie <nat@metabase.com>
      Unverified
      25dbd2e9
    • Alexander Polyankin's avatar
    • Alexander Polyankin's avatar
    • dpsutton's avatar
      Bump woodstox : CVE-2022-40151 (#26269) · 84df58aa
      dpsutton authored
      First seen in trivy report:
      https://github.com/metabase/metabase/pull/26161/checks?check_run_id=9326286850
      
      CVE:
      https://avd.aquasec.com/nvd/cve-2022-40151
      
      xstream: Xstream to serialise XML data was vulnerable to Denial of
      Service attacks High
      Package: com.fasterxml.woodstox:woodstox-core
      Installed Version: 6.2.6
      Vulnerability CVE-2022-40151
      Severity: HIGH
      Fixed Version: 5.4.0, 6.4.0
      
      Bumping deps and comparing `clj -X:deps tree` shows the change only adds
      the new dep top level and no new deps are brought in by the change.
      
      ```
      ❯ diff --unified deps deps-updated
      --- deps	2022-11-07 08:43:21.000000000 -0600
      +++ deps-updated	2022-11-07 08:49:56.000000000 -0600
      @@ -9,6 +9,8 @@
         X org.slf4j/slf4j-api 1.7.25 :use-top
         X org.apache.logging.log4j/log4j-api 2.18.0 :use-top
         X org.apache.logging.log4j/log4j-core 2.18.0 :use-top
      +com.fasterxml.woodstox/woodstox-core 6.4.0
      +  . org.codehaus.woodstox/stax2-api 4.2.1
       joda-time/joda-time 2.10.13
       commons-codec/commons-codec 1.15
       weavejester/dependency 0.2.1
      @@ -285,8 +287,7 @@
         . org.apache.santuario/xmlsec 2.3.0
           X org.slf4j/slf4j-api 1.7.32 :use-top
           X commons-codec/commons-codec 1.15 :use-top
      -    . com.fasterxml.woodstox/woodstox-core 6.2.6
      -      . org.codehaus.woodstox/stax2-api 4.2.1
      +    X com.fasterxml.woodstox/woodstox-core 6.2.6 :use-top
           . jakarta.xml.bind/jakarta.xml.bind-api 2.3.3
             . jakarta.activation/jakarta.activation-api 1.2.2
         . org.opensaml/opensaml-xmlsec-api 3.4.6
      ```
      Unverified
      84df58aa
    • Natalie's avatar
      replace quotation marks (#26252) · 21d45497
      Natalie authored
      Unverified
      21d45497
    • Braden Shepherdson's avatar
      Serdes v2: Search for dependencies both on the filesystem and the appdb (#26217) · 1e4fb63b
      Braden Shepherdson authored
      This allows smaller selective exports that (for example) don't need to
      include the data model if you know the other side has it.
      Unverified
      1e4fb63b
Loading