Hi,

I'd like to suggest an update of maven-shared-utils to at least 3.3.3
due to security issue https://issues.apache.org/jira/browse/MSHARED-297.
Quarkus is using parts of Maven that bring in maven-shared-utils 3.2.1
and we received complaints by users:
https://github.com/quarkusio/quarkus/issues/18050
In the short term, we'll most likely override that version in Quarkus,
but the clean solution would be in Maven itself.

Also, I'm not sure about the status of
https://github.com/apache/maven/pull/413 which fixes a relatively
widespread concurrency issue in context of aggregating plugin goals.

Cheers,

Falko

Am 23.06.2021 um 10:02 schrieb Michael Osipov:
Folks,

I'd like to proceed with 3.8.x since there are a few issues which
users would like to see addressed.
I went through the issues in 4.0.0-alpha-1 and would like to evaluate
the following to be back ported to 3.8.x branch:

https://issues.apache.org/jira/browse/MNG-5669
https://issues.apache.org/jira/browse/MNG-5868
https://issues.apache.org/jira/browse/MNG-6071
https://issues.apache.org/jira/browse/MNG-6160
https://issues.apache.org/jira/browse/MNG-6737
https://issues.apache.org/jira/browse/MNG-6767
https://issues.apache.org/jira/browse/MNG-6819
https://issues.apache.org/jira/browse/MNG-6824
https://issues.apache.org/jira/browse/MNG-6828
https://issues.apache.org/jira/browse/MNG-6842
https://issues.apache.org/jira/browse/MNG-6850
https://issues.apache.org/jira/browse/MNG-6921
https://issues.apache.org/jira/browse/MNG-6937
https://issues.apache.org/jira/browse/MNG-6964
https://issues.apache.org/jira/browse/MNG-6983
https://issues.apache.org/jira/browse/MNG-6991
https://issues.apache.org/jira/browse/MNG-7000
https://issues.apache.org/jira/browse/MNG-7034
https://issues.apache.org/jira/browse/MNG-7057

Almost all are bugfixes.
Do you see any other issues need to be back ported? Any objects for
those?

Michael

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@maven.apache.org
For additional commands, e-mail: dev-h...@maven.apache.org



---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@maven.apache.org
For additional commands, e-mail: dev-h...@maven.apache.org

Reply via email to