[jira] [Commented] (XERCESC-2188) Use-after-free on external DTD scan

2020-03-09 Thread Sylvain Beucler (Jira)
[ https://issues.apache.org/jira/browse/XERCESC-2188?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17055415#comment-17055415 ] Sylvain Beucler commented on XERCESC-2188: -- FWIW I spotted one embedding at

[jira] [Commented] (XERCESC-2188) Use-after-free on external DTD scan

2020-03-09 Thread Scott Cantor (Jira)
[ https://issues.apache.org/jira/browse/XERCESC-2188?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17055409#comment-17055409 ] Scott Cantor commented on XERCESC-2188: --- Also, we'd need to ensure no actual public classes don't

[jira] [Commented] (XERCESC-2188) Use-after-free on external DTD scan

2020-03-09 Thread Scott Cantor (Jira)
[ https://issues.apache.org/jira/browse/XERCESC-2188?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17055407#comment-17055407 ] Scott Cantor commented on XERCESC-2188: --- Yes, that's kind of the issue, what we can assume about

[jira] [Commented] (XERCESC-2188) Use-after-free on external DTD scan

2020-03-09 Thread Sylvain Beucler (Jira)
[ https://issues.apache.org/jira/browse/XERCESC-2188?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17055399#comment-17055399 ] Sylvain Beucler commented on XERCESC-2188: -- Hi, I'm no expert either and I'm merely

Re: Branching for 3.3 work?

2020-03-09 Thread Cantor, Scott
On 3/9/20, 12:01 PM, "Boris Kolpackov" wrote: > Sounds good to me. I, personally, think we don't even need a vote > for this. Maybe if you don't hear any opposing views, just make the > change? That's what I was planning on. There's no hurry on the doc update, but I'll branch probably

Re: Branching for 3.3 work?

2020-03-09 Thread Boris Kolpackov
Cantor, Scott writes: > On 3/6/20, 9:56 AM, "Boris Kolpackov" wrote: > > > I am not aware though from the names internal/ and dom/impl/ should be > > off-limits while everything else is probably fair game. > > I'm happy if we decide we just say that since it addresses this > particular case,

Re: Apache CLA for small contributions

2020-03-09 Thread Cantor, Scott
On 3/6/20, 10:26 PM, "Roger Leigh" wrote: > I wanted to check with you what the policy was regarding the requirement for > an Apache CLA for code contributions. > Does this apply for the case of simple and obvious one-liners and other > fairly trivial fixes as opposed to more > substantial