[ 
https://issues.apache.org/jira/browse/AMQ-7448?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Sourabh Sarvotham Parkala updated AMQ-7448:
-------------------------------------------
    Description: 
Please find the link below

[https://github.com/apache/activemq/blob/master/activemq-openwire-generator/pom.xml]
 
[#L49|https://github.com/apache/activemq/blob/05c43fe3473b4460c6d8d768ad3076a53be302d3/activemq-openwire-generator/pom.xml#L49]

 

I am wondering if we need this dependency. As the parent pom already has been 
updated to org.apache.ant:ant. I tested it out by removing the dependency. It 
does not throw any compilation issues.

 

Also, this ant:ant:1.6.2 dependency brings this vulnerability 
[https://nvd.nist.gov/vuln/detail/CVE-2012-2098].

  was:
Please find the link below

[https://github.com/apache/activemq/blob/master/activemq-openwire-generator/pom.xml]
 
[#L49|https://github.com/apache/activemq/blob/05c43fe3473b4460c6d8d768ad3076a53be302d3/activemq-openwire-generator/pom.xml#L49]

 

I am wondering if we need this dependency. As the parent pom already has been 
updated to org.apache.ant:ant. I tested it out by removing the dependency. It 
does not throw any compilation issues.

 

Also, this ant:ant:1.6.2 dependency brings about 
[https://nvd.nist.gov/vuln/detail/CVE-2012-2098].


> Remove deprecated dependency ant:ant:1.6.2
> ------------------------------------------
>
>                 Key: AMQ-7448
>                 URL: https://issues.apache.org/jira/browse/AMQ-7448
>             Project: ActiveMQ
>          Issue Type: Bug
>    Affects Versions: 5.15.12
>            Reporter: Sourabh Sarvotham Parkala
>            Priority: Minor
>
> Please find the link below
> [https://github.com/apache/activemq/blob/master/activemq-openwire-generator/pom.xml]
>  
> [#L49|https://github.com/apache/activemq/blob/05c43fe3473b4460c6d8d768ad3076a53be302d3/activemq-openwire-generator/pom.xml#L49]
>  
> I am wondering if we need this dependency. As the parent pom already has been 
> updated to org.apache.ant:ant. I tested it out by removing the dependency. It 
> does not throw any compilation issues.
>  
> Also, this ant:ant:1.6.2 dependency brings this vulnerability 
> [https://nvd.nist.gov/vuln/detail/CVE-2012-2098].



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

Reply via email to