Re: [security] finding known issues for commons projects

2023-08-29 Thread Gary Gregory
Hi Mike, All the security pages you refer to are manually authored. What it means is that someone took the time to create these pages for those components at some point in the past. It does not mean the pages are complete, up to date, or that components that have CVEs actually have pages. This is

[security] finding known issues for commons projects

2023-08-28 Thread Mike Drob
Hello commons-dev! I found the very lovely https://commons.apache.org/security.html page and I very much appreciate the links out to individual project's security pages. However, it looks like a little under half (9/21) have security pages linked. Does this mean that the other 12 projects have