Note that BeanUtils 2 is a major update with a package name change, meaning it is not a drop in replacement.
The one main remaining issue to discuss IIRC is whether the BU API should make public Commons Collections interface and classes, as opposed to more generic JRE Collections. Gary On Wed, Jun 5, 2019 at 8:10 AM Melloware <melloware...@gmail.com> wrote: > Rob, > > I 100% agree since CVE-2014-0114 has been fixed in BeanUtils I think we > need a release. > > However the 1.X branch seems dormant it seems for the last 3 years > everything has been working on is BeanUtils2 which is where all the > fixes have been made? > > Mello > > > --------------------------------------------------------------------- > To unsubscribe, e-mail: dev-unsubscr...@commons.apache.org > For additional commands, e-mail: dev-h...@commons.apache.org > >