Am 2021-06-25 um 00:26 schrieb Falko Modler:
Hi,

I'd like to suggest an update of maven-shared-utils to at least 3.3.3
due to security issue https://issues.apache.org/jira/browse/MSHARED-297.
Quarkus is using parts of Maven that bring in maven-shared-utils 3.2.1
and we received complaints by users:
https://github.com/quarkusio/quarkus/issues/18050
In the short term, we'll most likely override that version in Quarkus,
but the clean solution would be in Maven itself.

MNG-7177.

Also, I'm not sure about the status of
https://github.com/apache/maven/pull/413 which fixes a relatively
widespread concurrency issue in context of aggregating plugin goals.

I will need to take a look at this again.

@Robert, you and Guillaume have approved the PR, so do you think we can add this to alpha 1?

M

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@maven.apache.org
For additional commands, e-mail: dev-h...@maven.apache.org

Reply via email to