Re: [Geoserver-users] Query regarding the reproduction steps of vulnerability CVE-2023-5786

2024-07-04 Thread Jody Garnett
The difficulty is if someone else has disclosed publicly eh? I wrote down some stuff here from GSIP-220 which we can revise over time: https://docs.geoserver.org/latest/en/developer/policies/security.html -- Jody Garnett On Wed, Jul 3, 2024 at 11:16 PM Ian Turton wrote: > I think if we have d

Re: [Geoserver-users] Experimental/External plugin page

2024-07-04 Thread Jody Garnett
I would love to have an actual module system like Jenkins that allowing plugins to be installed/uninstalled from within the app. I am not quite sure how they do it? -- Jody Garnett On Thu, Jul 4, 2024 at 12:49 AM Tom Chadwin wrote: > I think this is a valid thought - specifically a way in whi

Re: [Geoserver-users] Set aside time for a GeoServer update this Tuesday

2024-07-04 Thread Andrea Aime
On Wed, Jul 3, 2024 at 9:46 PM Jody Garnett wrote: > But my prime question was that I found a reference stating that for >> NCSC-2024-0274 there where fixes released for 2.25, 2.24, 2.23, 2.21. >> Version 2.22 was missing in this list and if there was a reason for that or >> that we could use the

Re: [Geoserver-users] Set aside time for a GeoServer update this Tuesday

2024-07-04 Thread Mark Prins
On 03-07-2024 20:44, Jody Garnett wrote: Aside: What is NCSC-2024-0274 number? Looks to be a country specific number for CVE-2024-36401 ... yes: https://advisories.ncsc.nl/advisory?id=NCSC-2024-0274 ___ Geoserver-users mailing list Please make su

Re: [Geoserver-users] Experimental/External plugin page

2024-07-04 Thread Tom Chadwin
I think this is a valid thought - specifically a way in which the developer of an extension can get it to users before stable publication. Back when I was doing a QGIS plugin, I was encouraged to release very early indeed with the "experimental" flag set. It was very difficult to get any feedback o