tinkerpop-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Robert Dale (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (TINKERPOP-2185) Use commons-configuration2 instead of commns-configuration
Date Thu, 04 Apr 2019 12:06:00 GMT

    [ https://issues.apache.org/jira/browse/TINKERPOP-2185?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16809777#comment-16809777
] 

Robert Dale commented on TINKERPOP-2185:
----------------------------------------

[~alexott] Neither one is listed as a vulnerability.  So I don't see any need to update to
the redhat version.

> Use commons-configuration2 instead of commns-configuration
> ----------------------------------------------------------
>
>                 Key: TINKERPOP-2185
>                 URL: https://issues.apache.org/jira/browse/TINKERPOP-2185
>             Project: TinkerPop
>          Issue Type: Bug
>          Components: structure
>    Affects Versions: 3.3.6, 3.4.1
>            Reporter: Alex Ott
>            Assignee: stephen mallette
>            Priority: Major
>
> Product called Whitesource reports vulnerabilities in the commons-configuration 1.10
that is dependency of the gremlin-core module. As result, some projects couldn't be allowed
to production because of the failing check.



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)

Mime
View raw message