Skip to content

use commons-collections v3.2.2 to avoid v3.2.1 vulnerability#77

Merged
ldko merged 1 commit into
iipc:masterfrom
ndushay:patched-commons-coll
Aug 9, 2017
Merged

use commons-collections v3.2.2 to avoid v3.2.1 vulnerability#77
ldko merged 1 commit into
iipc:masterfrom
ndushay:patched-commons-coll

Conversation

@ndushay

@ndushay ndushay commented Aug 8, 2017

Copy link
Copy Markdown
Contributor

resolves #76

Dunno if it would make sense to up the version of it.unimi.dsi instead, or if that would fix the vulnerability ... but do know that this should address the problems with minimal, if any, side effects.

@ldko

ldko commented Aug 9, 2017

Copy link
Copy Markdown
Member

Regarding possibly upping the version of it.unimi.dsi, I think even the most recent version is still using a version of commons-collections under 3.2.2

@ldko ldko merged commit 4101f7e into iipc:master Aug 9, 2017
@ldko

ldko commented Aug 9, 2017

Copy link
Copy Markdown
Member

Thanks @ndushay

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

upgrade to commons-collections.jar 3.2.2

2 participants