Project

General

Profile

Actions

Task #2507

closed

Library struts-core-1.3.8.jar is no longer supported

Added by Tomáš Doischer over 3 years ago. Updated over 3 years ago.

Status:
Closed
Priority:
Low
Assignee:
Radek Tomiška
Category:
Continuous development
Target version:
Start date:
10/05/2020
Due date:
% Done:

100%

Estimated time:
Owner:

Description

A client's scanner found that the library Apache Struts in version 1.3.8 is no longer supported. They are not allowed to have unsupported software on their servers.

Is it possible to upgrade the library (and potentially others which are not supported) in future releases? This is not urgent but it could cause issues for other clients as well.

Actions #1

Updated by Radek Tomiška over 3 years ago

Note: Transient depencency from Velocity (velocity tools 2.0) - velocity (+tool) can be upgraded (or removed, if tool library is not used).

Actions #2

Updated by Radek Tomiška over 3 years ago

  • Status changed from New to Needs feedback
  • Target version set to 10.7.0
  • % Done changed from 0 to 90

I upgraded velocity tools to version 3.0. I checked upgrade guide and I didn't find compatibility issues (except struct are not used anymore
http://velocity.apache.org/tools/devel/upgrading.html#upgrading-to-30 what we need).

Commit:
https://github.com/bcvsolutions/CzechIdMng/commit/589891a71e9db3d23f3f9f91745a010b960b6485

Could you provide me a feedback, please?

Note: Velocity tools are not used in product templates at all, but it can be used in project templates, so I was afraid to remove it to preserve backward compatibility.

Actions #3

Updated by Vít Švanda over 3 years ago

  • Status changed from Needs feedback to Resolved
  • Assignee changed from Vít Švanda to Radek Tomiška
  • % Done changed from 90 to 100

I did review and I see new library in my enviroment.

Actions #4

Updated by Radek Tomiška over 3 years ago

  • Status changed from Resolved to Closed
Actions

Also available in: Atom PDF