struts-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Lukasz Lenart <lukaszlen...@apache.org>
Subject Re: CVE-2014-0114
Date Mon, 25 Jun 2018 07:17:05 GMT
niedz., 24 cze 2018 o 12:02 Greg Huber <gregh3269@gmail.com> napisał(a):
> Sorry, a bit more info, I am replacing/removing commons-validator 1.6 which
> brings beanutils 1.9.3, now checking the jars, it now reverts back to
> 1.8.0,  This is the  hierarchy reported using eclipse :
>
> struts2-tiles-plugin 2.5.16
>   tiles-core 3.0.7
>     commons-digester 2.0
>       commons-beanutils 1.8.0

Yeah... and Tiles were announced/considered to be moved to attic. It's
a real pain to maintain third parties' dependencies. Maybe we should
take it over and at least keep them up2date in matter of dependencies?
I thought about creating an organisation called "Attic" at GitHub and
maintain those attic projects ;-)


Regards
-- 
Łukasz
+ 48 606 323 122 http://www.lenart.org.pl/

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@struts.apache.org
For additional commands, e-mail: dev-help@struts.apache.org


Mime
View raw message