Gazy Mahomar opened MDEP-775 and commented
The Dependency plugin depends on org.apache.velocity:velocity-tools:2.0, which in turn depends on org.apache.struts:struts-core 1.3.8. As mentioned in MDEP-626, struts-core:1.3.8 has several CVEs against it. For those of us with overzealous IT departments in corporate environments, this presents a problem, as the struts-core:1.3.8 jar constantly triggers vulnerability checks.
Would it be possible to update velocity-tools to a newer version without struts?
No further details from MDEP-775
Gazy Mahomar opened MDEP-775 and commented
The Dependency plugin depends on
org.apache.velocity:velocity-tools:2.0, which in turn depends onorg.apache.struts:struts-core 1.3.8. As mentioned in MDEP-626,struts-core:1.3.8has several CVEs against it. For those of us with overzealous IT departments in corporate environments, this presents a problem, as thestruts-core:1.3.8jar constantly triggers vulnerability checks.Would it be possible to update
velocity-toolsto a newer version without struts?No further details from MDEP-775