rodwiddowson opened a new issue, #1374:
URL: https://github.com/apache/maven-assembly-plugin/issues/1374

   ### New feature, improvement proposal
   
   I have been doing an analysis of our dependencies and I discovered that 
maven-assembly-plugin version 3.8.0 indirectly imports 
io.airlift:aircompressor.  The indirection comes via plexus-archiver.
   
   aircompressor  is a dead project (superseded by aircompressor3), and if you 
believe mavenrepository.com has about 8 CVEs against it, [1]
   
   I poked a bit further and it looks like plexus-archiver started using this 
package in 4.10.0 and moved over to using commons-compress instead in 4.11.0 
(commit ffa5935449bc).
   
   It would be really cool if you could move your dependency forward to at 
least 4.11.0
   
   For our use I am currently pinning maven-assembly-plugin in our pom to use  
plexus-archiver 4.14.0 [2] and it seems to work OK.  I have also checked out 
your code, changed the pom, and done a “mvn test” on that project.  
   
   Of course I have no insight into your use.  I also don’t know whether 
plexus-archiver uses semantic versioning so what I am doing may be unsafe.
   
   I’d be happy to test a version for you if that makes this easier.  Or put 
together a PR (but that seems heavyweight for a one-line change)
   
   Rod
   
   [1] https://mvnrepository.com/artifact/io.airlift/aircompressor/0.27
   [2] 
https://codeberg.org/Shibboleth/java-parent-project/commit/bd0a3fd4bab069a4ff76c655ffb4e47cf60e76cf
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to