Skip to main content

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [List Home]
Re: [cross-project-issues-dev] [Bug 547338] Update to guava 24.1.1+ (fix CVE-2018-10237)

Hi,

To conform with the usual procedure, I'll open the CQ for m2e to use Guava 27.1: https://dev.eclipse.org/ipzilla/show_bug.cgi?id=19607 (that CQ can then be reused by Orbit if some feel in the mood of packaging it)
But note that a fixed recent version of Guava (25.1) was already approved for m2e, but not packaged into Orbit as it's in the "embedded Maven": https://dev.eclipse.org/ipzilla/show_bug.cgi?id=19607 , so this one could be already reused by Orbit to package as bundle and then distributed to all downstream projects. But since packaging is an effort, I suggest we do it against Guava 27.1.
Preparing the contribution to Orbit for 27.1 and submitting it to Gerrit can be started immediately, and merge will happen later upon Orbit CQ approval.

Back to the top