2013/12/3 foo bar <linut...@gmail.com>: > Hi, > > Thanks for that response, very helpful. > It's just sometimes our code may need to use a later version of a library > that struts also uses, based on this, I think we will need to do a risk > benefit analysis on such occasion.
It should be possible to simple drop in dependencies of the same branch, i.e. commons-beanutils-1.8.0 -> commons-beanutils-1.8.3 > Just curious though, according to this pom file > http://repo1.maven.org/maven2/org/apache/struts/struts2-core/2.3.15.3/struts2-core-2.3.15.3.pom > It doesn't specify which versions of libraries to use. > For example ognl, wouldn't it use ognl-3.0.8 (the latest in > http://mvnrepository.com/artifact/ognl/ognl), which is different from the > bundled/included ognl-3.0.6 ? http://central.maven.org/maven2/org/apache/struts/struts2-parent/2.3.15.3/struts2-parent-2.3.15.3.pom Regards -- Ćukasz + 48 606 323 122 http://www.lenart.org.pl/ --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@struts.apache.org For additional commands, e-mail: dev-h...@struts.apache.org