Team,

My name is Aleksandr and I am writing you as a backend developer of SAP.
Recently we have started using "commons-fileupload:1.4" in our production code. 
And looking at the latest version (1.4) date I want to ask you why there are no 
new releases even though there are fresh commits? My main motivation for the 
question is a security concern. There can be the case that new vulnerability is 
found in transitive dependencies of "commons-fileupload" and it will mean that 
due to security policies of our company we will/may need to stop using the 
library. Thanks a lot in advance for the answer.

Best regards
Aleksandr

Reply via email to