uschindler commented on code in PR #1653:
URL: https://github.com/apache/solr/pull/1653#discussion_r1222109675


##########
gradle/validation/forbidden-apis.gradle:
##########
@@ -49,11 +49,6 @@ allprojects { prj ->
           logger.debug("Signature file omitted (does not exist): ${sig}")
         }
       }
-      
-      // commons-io is special: forbiddenapis has a versioned bundledSignature.
-      bundledSignatures += resolvedMods
-        .findAll { id -> id.group == 'commons-io' && id.name == 'commons-io' }
-        .collect { id -> "${id.name}-unsafe-${id.version}" as String }

Review Comment:
   Hi, the new version is too new and not yet supported. Can you open an issue 
or PR for forbiddenapis?
   
   As workaround the easiest would be to use the 2.11 signatures file. I think 
that can be patched in the collect method here.
   
   I do not see the workaround in this PR... Where is it?



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscr...@solr.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org


---------------------------------------------------------------------
To unsubscribe, e-mail: issues-unsubscr...@solr.apache.org
For additional commands, e-mail: issues-h...@solr.apache.org

Reply via email to