Branch: refs/heads/master
  Home:   https://github.com/jenkinsci/email-ext-plugin
  Commit: 985892a861802c5ad0accd3d8e93abfcc4e1f48d
      
https://github.com/jenkinsci/email-ext-plugin/commit/985892a861802c5ad0accd3d8e93abfcc4e1f48d
  Author: Kohsuke Kawaguchi <k...@kohsuke.org>
  Date:   2014-11-04 (Tue, 04 Nov 2014)

  Changed paths:
    M pom.xml

  Log Message:
  -----------
  [JENKINS-25348]

Avoid having multiple copies of groovy-sandbox.jar in the Jenkins JVM,
which compromises the security.

I think it makes sense for the script-security plugin to own this
library, so instead let's depend on that plugin to provide a canonical
copy.

There's still a separate fix that needs to happen in script-security
plugin and its client plugins, but in the mean time this fix plugs the
hole as email-ext-plugin is the only other plugin in the jenkinsci org
that brings its own copy of groovy-sandbox


-- 
You received this message because you are subscribed to the Google Groups 
"Jenkins Commits" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to jenkinsci-commits+unsubscr...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to