+1

--
Kind Regards,
Ashish Vijaywargiya
Vice President of Operations
*HotWax Systems*
*Enterprise open source experts*
http://www.hotwaxsystems.com



On Sun, Aug 30, 2026 at 7:57 PM Mridul Pathak <[email protected]>
wrote:

> Hi all,
>
> commons-imaging has been pinned to 1.0-alpha3 in OFBiz because its API
> changed in 1.0.0-alpha4, a version we never migrated past; the library
> itself has stayed alpha-only since 2019 and is currently at 1.0.0-alpha6
> with no GA in sight.
>
> I audited actual usage and found it's concentrated in one file,
> SecuredUpload.java, for magic-byte format validation and a TIFF
> decode/encode fallback -- the JDK's built-in ImageIO already handles
> PNG/GIF/JPEG natively. Both needs can be covered by dependencies we either
> already have or that are a clean, narrow addition: metadata-extractor
> (already a project dependency) for format sniffing via its
> FileTypeDetector, and com.twelvemonkeys.imageio:imageio-tiff (pure-Java,
> BSD-3, actively maintained SPI plugin) to give ImageIO native TIFF support,
> letting us delete the manual Commons Imaging fallback code entirely.
>
> I've filed OFBIZ-13507 and put up patches for both trunk and release24.09:
> - trunk: https://github.com/apache/ofbiz-framework/pull/1819
> - release24.09 (backport):
> https://github.com/apache/ofbiz-framework/pull/1821
>
> It's a net reduction in both dependencies and code (one dependency removed,
> one narrow one added, about 70 fewer lines on trunk), and also drops the
> now-unreachable commons-imaging Dependabot ignore rule added in #1810.
>
> Feedback welcome before I look at merging.
>
> Thanks,
> Mridul Pathak
>

Reply via email to