[GitHub] [commons-configuration] mohammadmaulana commented on pull request #221: Bump commons-text from 1.9 to 1.10.0

2022-10-31 Thread GitBox
mohammadmaulana commented on PR #221: URL: https://github.com/apache/commons-configuration/pull/221#issuecomment-1296830575 hi @garydgregory, please help to confirm, when the next version will be released? since this is fix for this critical vulnerability issue https://nvd.nist.gov/vuln

[GitHub] [commons-jexl] henrib commented on pull request #134: Simplify grammar and lexical state management

2022-10-31 Thread GitBox
henrib commented on PR #134: URL: https://github.com/apache/commons-jexl/pull/134#issuecomment-1296857430 Nice ! I've a tiny modification wrt keywords list and 'dot id' handling. I'm fighting with git though... Created a branch, trying to merge back in your PR, will find a way momentarily.

[GitHub] [commons-jexl] henrib merged pull request #134: Simplify grammar and lexical state management

2022-10-31 Thread GitBox
henrib merged PR #134: URL: https://github.com/apache/commons-jexl/pull/134 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@commons.a

[GitHub] [commons-jexl] henrib merged pull request #125: Bump asm from 9.3 to 9.4

2022-10-31 Thread GitBox
henrib merged PR #125: URL: https://github.com/apache/commons-jexl/pull/125 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@commons.a

[GitHub] [commons-jexl] henrib merged pull request #128: Bump spotbugs-maven-plugin from 4.7.2.0 to 4.7.2.1

2022-10-31 Thread GitBox
henrib merged PR #128: URL: https://github.com/apache/commons-jexl/pull/128 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@commons.a

[GitHub] [commons-jexl] henrib merged pull request #133: Bump actions/upload-artifact from 3.1.0 to 3.1.1

2022-10-31 Thread GitBox
henrib merged PR #133: URL: https://github.com/apache/commons-jexl/pull/133 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@commons.a

[jira] [Updated] (JEXL-382) Simplify grammar and lexical state management

2022-10-31 Thread Henri Biestro (Jira)
[ https://issues.apache.org/jira/browse/JEXL-382?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Henri Biestro updated JEXL-382: --- Affects Version/s: 3.2.1 > Simplify grammar and lexical state management >

[jira] [Updated] (JEXL-382) Simplify grammar and lexical state management

2022-10-31 Thread Henri Biestro (Jira)
[ https://issues.apache.org/jira/browse/JEXL-382?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Henri Biestro updated JEXL-382: --- Assignee: Henri Biestro > Simplify grammar and lexical state management > -

[jira] [Updated] (JEXL-382) Simplify grammar and lexical state management

2022-10-31 Thread Henri Biestro (Jira)
[ https://issues.apache.org/jira/browse/JEXL-382?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Henri Biestro updated JEXL-382: --- Fix Version/s: 3.3 > Simplify grammar and lexical state management > --

[jira] [Resolved] (JEXL-382) Simplify grammar and lexical state management

2022-10-31 Thread Henri Biestro (Jira)
[ https://issues.apache.org/jira/browse/JEXL-382?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Henri Biestro resolved JEXL-382. Resolution: Fixed Nice one Dmitri! Commit [81e2be9|https://github.com/apache/commons-jexl/commit/81e

[GitHub] [commons-configuration] garydgregory commented on pull request #221: Bump commons-text from 1.9 to 1.10.0

2022-10-31 Thread GitBox
garydgregory commented on PR #221: URL: https://github.com/apache/commons-configuration/pull/221#issuecomment-1296938828 @mohammadmaulana Apache Commons Text 1.10.0 is already released, you can use it from you applications. There is no schedule as of yet for the next release of Commons

[jira] [Updated] (JEXL-381) Change default JEXL configuration to a more security-friendly behaviour

2022-10-31 Thread Henri Biestro (Jira)
[ https://issues.apache.org/jira/browse/JEXL-381?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Henri Biestro updated JEXL-381: --- Description: WHAT: JEXL's default builder allows accessing and calling any public method, field or co

[jira] [Updated] (JEXL-381) Change default JEXL configuration to a more security-friendly behaviour

2022-10-31 Thread Henri Biestro (Jira)
[ https://issues.apache.org/jira/browse/JEXL-381?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Henri Biestro updated JEXL-381: --- Description: WHAT: JEXL's default builder allows accessing and calling any public method, field or co

[jira] [Updated] (JEXL-381) Change default JEXL configuration to a more security-friendly behaviour

2022-10-31 Thread Henri Biestro (Jira)
[ https://issues.apache.org/jira/browse/JEXL-381?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Henri Biestro updated JEXL-381: --- Description: WHAT: JEXL's default builder allows accessing and calling any public method, field or co

[jira] [Updated] (JEXL-381) Change default JEXL configuration to a more security-friendly behaviour

2022-10-31 Thread Henri Biestro (Jira)
[ https://issues.apache.org/jira/browse/JEXL-381?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Henri Biestro updated JEXL-381: --- Description: WHAT: JEXL's default builder allows accessing and calling any public method, field or co

[jira] [Commented] (JEXL-381) Change default JEXL configuration to a more security-friendly behaviour

2022-10-31 Thread Gary D. Gregory (Jira)
[ https://issues.apache.org/jira/browse/JEXL-381?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17626628#comment-17626628 ] Gary D. Gregory commented on JEXL-381: -- I'm not sure "permeability" is the best word t

[jira] [Comment Edited] (JEXL-381) Change default JEXL configuration to a more security-friendly behaviour

2022-10-31 Thread Gary D. Gregory (Jira)
[ https://issues.apache.org/jira/browse/JEXL-381?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17626628#comment-17626628 ] Gary D. Gregory edited comment on JEXL-381 at 10/31/22 2:51 PM: -

[jira] [Comment Edited] (JEXL-381) Change default JEXL configuration to a more security-friendly behaviour

2022-10-31 Thread Gary D. Gregory (Jira)
[ https://issues.apache.org/jira/browse/JEXL-381?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17626628#comment-17626628 ] Gary D. Gregory edited comment on JEXL-381 at 10/31/22 2:53 PM: -

[GitHub] [commons-text] garydgregory commented on a diff in pull request #375: Use java8 Stream.

2022-10-31 Thread GitBox
garydgregory commented on code in PR #375: URL: https://github.com/apache/commons-text/pull/375#discussion_r1009545056 ## src/main/java/org/apache/commons/text/AlphabetConverter.java: ## @@ -104,11 +104,7 @@ private static Integer[] convertCharsToIntegers(final Character[] char

[GitHub] [commons-text] garydgregory commented on a diff in pull request #375: Use java8 Stream.

2022-10-31 Thread GitBox
garydgregory commented on code in PR #375: URL: https://github.com/apache/commons-text/pull/375#discussion_r1009545056 ## src/main/java/org/apache/commons/text/AlphabetConverter.java: ## @@ -104,11 +104,7 @@ private static Integer[] convertCharsToIntegers(final Character[] char

[GitHub] [commons-text] garydgregory commented on a diff in pull request #375: Use java8 Stream.

2022-10-31 Thread GitBox
garydgregory commented on code in PR #375: URL: https://github.com/apache/commons-text/pull/375#discussion_r1009552877 ## src/main/java/org/apache/commons/text/similarity/IntersectionSimilarity.java: ## @@ -125,12 +125,7 @@ int uniqueElementSize() { * @return The intersect

[GitHub] [commons-text] garydgregory commented on a diff in pull request #375: Use java8 Stream.

2022-10-31 Thread GitBox
garydgregory commented on code in PR #375: URL: https://github.com/apache/commons-text/pull/375#discussion_r1009555138 ## src/main/java/org/apache/commons/text/similarity/IntersectionSimilarity.java: ## @@ -125,12 +125,7 @@ int uniqueElementSize() { * @return The intersect

[jira] [Commented] (NUMBERS-29) Move combinatorics utilities from "Commons Math"

2022-10-31 Thread Alex Herbert (Jira)
[ https://issues.apache.org/jira/browse/NUMBERS-29?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17626651#comment-17626651 ] Alex Herbert commented on NUMBERS-29: - I have spent some time looking at stirlingS2.

[jira] [Updated] (NUMBERS-30) Move "array" utilities from "Commons Math"

2022-10-31 Thread Alex Herbert (Jira)
[ https://issues.apache.org/jira/browse/NUMBERS-30?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Alex Herbert updated NUMBERS-30: Component/s: arrays > Move "array" utilities from "Commons Math" >

[jira] [Updated] (NUMBERS-29) Move combinatorics utilities from "Commons Math"

2022-10-31 Thread Alex Herbert (Jira)
[ https://issues.apache.org/jira/browse/NUMBERS-29?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Alex Herbert updated NUMBERS-29: Component/s: combinatorics > Move combinatorics utilities from "Commons Math" > ---

[GitHub] [commons-text] arturobernalg commented on a diff in pull request #375: Use java8 Stream.

2022-10-31 Thread GitBox
arturobernalg commented on code in PR #375: URL: https://github.com/apache/commons-text/pull/375#discussion_r1009584981 ## src/main/java/org/apache/commons/text/similarity/IntersectionSimilarity.java: ## @@ -125,12 +125,7 @@ int uniqueElementSize() { * @return The intersec

[jira] [Commented] (NUMBERS-29) Move combinatorics utilities from "Commons Math"

2022-10-31 Thread Gilles Sadowski (Jira)
[ https://issues.apache.org/jira/browse/NUMBERS-29?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17626676#comment-17626676 ] Gilles Sadowski commented on NUMBERS-29: bq. I suggest adding to the combinatoric

[jira] [Commented] (NUMBERS-29) Move combinatorics utilities from "Commons Math"

2022-10-31 Thread Alex Herbert (Jira)
[ https://issues.apache.org/jira/browse/NUMBERS-29?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17626685#comment-17626685 ] Alex Herbert commented on NUMBERS-29: - {quote}Are you sure about the API (a new Stirl

[jira] [Commented] (JEXL-381) Change default JEXL configuration to a more security-friendly behaviour

2022-10-31 Thread Henri Biestro (Jira)
[ https://issues.apache.org/jira/browse/JEXL-381?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17626730#comment-17626730 ] Henri Biestro commented on JEXL-381: 'Permeability' was intended as 'how much' of the h

[jira] [Commented] (JEXL-381) Change default JEXL configuration to a more security-friendly behaviour

2022-10-31 Thread Dmitri Blinov (Jira)
[ https://issues.apache.org/jira/browse/JEXL-381?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17626731#comment-17626731 ] Dmitri Blinov commented on JEXL-381: IMO the idea to sandbox JEXL by default is not wit

[jira] [Comment Edited] (JEXL-381) Change default JEXL configuration to a more security-friendly behaviour

2022-10-31 Thread Henri Biestro (Jira)
[ https://issues.apache.org/jira/browse/JEXL-381?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17626730#comment-17626730 ] Henri Biestro edited comment on JEXL-381 at 10/31/22 6:06 PM: --

[jira] [Commented] (JEXL-381) Change default JEXL configuration to a more security-friendly behaviour

2022-10-31 Thread Henri Biestro (Jira)
[ https://issues.apache.org/jira/browse/JEXL-381?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17626740#comment-17626740 ] Henri Biestro commented on JEXL-381: Dmitri, I would hope that JexlPermissions (JEXL-35

[jira] [Comment Edited] (JEXL-381) Change default JEXL configuration to a more security-friendly behaviour

2022-10-31 Thread Henri Biestro (Jira)
[ https://issues.apache.org/jira/browse/JEXL-381?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17626740#comment-17626740 ] Henri Biestro edited comment on JEXL-381 at 10/31/22 6:11 PM: --

[jira] [Comment Edited] (JEXL-381) Change default JEXL configuration to a more security-friendly behaviour

2022-10-31 Thread Henri Biestro (Jira)
[ https://issues.apache.org/jira/browse/JEXL-381?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17626730#comment-17626730 ] Henri Biestro edited comment on JEXL-381 at 10/31/22 6:11 PM: --

[jira] [Comment Edited] (JEXL-381) Change default JEXL configuration to a more security-friendly behaviour

2022-10-31 Thread Henri Biestro (Jira)
[ https://issues.apache.org/jira/browse/JEXL-381?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17626740#comment-17626740 ] Henri Biestro edited comment on JEXL-381 at 10/31/22 6:13 PM: --

[jira] [Commented] (JEXL-381) Change default JEXL configuration to a more security-friendly behaviour

2022-10-31 Thread Dmitri Blinov (Jira)
[ https://issues.apache.org/jira/browse/JEXL-381?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17626766#comment-17626766 ] Dmitri Blinov commented on JEXL-381: [~henrib] I don't remember exact reason why I didn

[jira] [Comment Edited] (JEXL-381) Change default JEXL configuration to a more security-friendly behaviour

2022-10-31 Thread Dmitri Blinov (Jira)
[ https://issues.apache.org/jira/browse/JEXL-381?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17626766#comment-17626766 ] Dmitri Blinov edited comment on JEXL-381 at 10/31/22 7:07 PM: --

[GitHub] [commons-text] garydgregory commented on pull request #375: Use java8 Stream.

2022-10-31 Thread GitBox
garydgregory commented on PR #375: URL: https://github.com/apache/commons-text/pull/375#issuecomment-1297664799 The code does not compile @arturobernalg -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to

[GitHub] [commons-text] codecov-commenter commented on pull request #375: Use java8 Stream.

2022-10-31 Thread GitBox
codecov-commenter commented on PR #375: URL: https://github.com/apache/commons-text/pull/375#issuecomment-1297727621 # [Codecov](https://codecov.io/gh/apache/commons-text/pull/375?src=pr&el=h1&utm_medium=referral&utm_source=github&utm_content=comment&utm_campaign=pr+comments&utm_term=The+Apa