Re: Security Vulnerability Detected in GWT Library

2019-05-13 Thread Hrishikesh Joshi
Are there any plans to update this in GWT 2.9.0 ? Are there any technical limitations which are holding GWT from updating this. If there are no technical limitations and only issue is contribution to opensource, then I would like to know that. On Thursday, 2 May 2019 14:00:39 UTC+5:30,

Re: Security Vulnerability Detected in GWT Library

2019-05-02 Thread t . broyer
On Wednesday, May 1, 2019 at 8:58:03 PM UTC+2, foal wrote: > > Easly to update in upcoming releases than explain each other that it isn't > critical :) > > BTW GWT-RPC user protobuf? > The protobuf in gwt-servlet is an internal dependency for sourcemaps and streamhtmlparser (used in

Re: Security Vulnerability Detected in GWT Library

2019-05-01 Thread foal
Easly to update in upcoming releases than explain each other that it isn't critical :) BTW GWT-RPC user protobuf? Thought about replacing REST with Protobuf but did not find ready to use solution (Java <-> GWT with APT generators). Stas. On Wednesday, April 10, 2019 at 10:28:23 AM UTC+2,

Re: Security Vulnerability Detected in GWT Library

2019-04-10 Thread luca . masini
gwt-dev is only used during maven build or at least for the code server running on my workstation, this is not necessary. May be gwt-servlet for old legacy apps thet still use GWT-RPC, but most now use REST service and REST clients. Anyway thanks for your suggestions. Have a nice day Il

Security Vulnerability Detected in GWT Library

2019-04-10 Thread Hrishikesh Joshi
GWT 2.8.2: All All --- # Description Security Vulnerability Detected in gwt-dev.jar & gwt-servlet.jar are reported by Dependency checker tool https://jeremylong.github.io/DependencyCheck/ Below are the details - 1. Gwt-dev.jar - 1.1 Vulnerable version of jetty