Batik 1.15 fixes some security issues

2022-09-22 Thread PJ Fanning
Hi everyone, Apache Batik [1] is used by Apache POI to work with SVG pictures that can be embedded in Microsoft documents. It is an optional dependency of poi-ooxml and it appears that we only support it in the XSLF packages for pptx files. Batik 1.15 has just been released and contains a numbe

Re: Batik 1.15 fixes some security issues

2022-09-22 Thread Andreas Reichel
Thanks for the heads up! I wished Apache FOP (or central apache) would be so alert. Much appreciated! Cheers Andreas On Thu, 2022-09-22 at 15:49 +, PJ Fanning wrote: > Hi everyone, > > Apache Batik [1] is used by Apache POI to work with SVG pictures that > can be embedded in Microsoft docu

Re: Batik 1.15 fixes some security issues

2022-09-22 Thread Andreas Reichel
Question please: as far as I can see it, Batik still pulls JAXEN/XercesImpl -- has this been taken care of? On Thu, 2022-09-22 at 23:15 +0700, Andreas Reichel wrote: > Thanks for the heads up! > I wished Apache FOP (or central apache) would be so alert. > > Much appreciated! > Cheers > Andreas >