Skip to content

[MDEP-775] Update velocity-tools from 2.0 to a newer version that doesn't depend on struts 1.3.8 #1278

Description

@jira-importer

Gazy Mahomar opened MDEP-775 and commented

The Dependency plugin depends on org.apache.velocity:velocity-tools:2.0, which in turn depends on org.apache.struts:struts-core 1.3.8. As mentioned in MDEP-626, struts-core:1.3.8 has several CVEs against it. For those of us with overzealous IT departments in corporate environments, this presents a problem, as the struts-core:1.3.8 jar constantly triggers vulnerability checks. 

Would it be possible to update velocity-tools to a newer version without struts?


No further details from MDEP-775

Metadata

Metadata

Assignees

No one assigned

    Labels

    dependenciesPull requests that update a dependency filepriority:majorMajor loss of function

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions