[ 
https://issues.apache.org/jira/browse/UNOMI-821?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17821072#comment-17821072
 ] 

Serge Huber commented on UNOMI-821:
-----------------------------------

Thanks for reporting this, we will update this library as you suggested. We 
also noticed it's used in :
 * shell-dev-commands
 * shell-commands

So we will update it everywhere it's used. 

Regards,

  Serge... 

> Unomi uses a non OSS version of org.json:json jar
> -------------------------------------------------
>
>                 Key: UNOMI-821
>                 URL: https://issues.apache.org/jira/browse/UNOMI-821
>             Project: Apache Unomi
>          Issue Type: Bug
>            Reporter: PJ Fanning
>            Priority: Major
>
> See 
> https://github.com/apache/unomi/blob/110286ad74ecaec927f3b61c54140d852dfbd4fe/extensions/unomi-mailchimp/services/pom.xml#L60
> Please read https://www.apache.org/legal/resolved.html (JSON license section).
> Newer version of this jar (2023/2024) have a Public Domain license so are ok. 
> These releases have CVE fixes too.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to