Re: [cross-project-issues-dev] Log4j 1.x vulnerability

2022-01-25 Thread Dirk Fauth via cross-project-issues-dev
@Christian Good to hear that you are moving to Import-Package! The fragment in the current configuration can actually not be simply fixed with a drop-in replacement as your version bounds are too strict. With that configuration it won't be ever possible to exchange to a newer bugfix version. I woul

Re: [cross-project-issues-dev] Log4j 1.x vulnerability

2022-02-08 Thread Dirk Fauth via cross-project-issues-dev
Hi, I got in contact with the reload4j team. They changed the Bundle-SymbolicName to org.apache.log4j and fixed several OSGi meta data related issues in the meanwhile. Today they published 1.2.19 which should work as a drop-in replacement in Eclipse based applications where Require-Bundle was used

Re: [cross-project-issues-dev] Log4j 1.x vulnerability

2022-02-08 Thread Dirk Fauth via cross-project-issues-dev
problem being fixed in > 1.2.19 a fact and even if its a fact if it would be a fact that matters... > > Regards, > Ed > > On 08.02.2022 15:48, Dirk Fauth via cross-project-issues-dev wrote: > > Hi, > > I got in contact with the reload4j team. They changed the >

Re: [cross-project-issues-dev] Log4j 1.x vulnerability

2022-02-16 Thread Dirk Fauth via cross-project-issues-dev
dle org.apache.log4j to Orbit > https://git.eclipse.org/r/c/orbit/orbit-recipes/+/190574 > feel free to change this if someone finds out how to use EBR to only sign > the upstream artefact. > -Matthias > > On Tue, Feb 8, 2022 at 4:04 PM Dirk Fauth via cross-project-issues-dev < >

Re: [cross-project-issues-dev] Eclipse Platform to prefer use of dependencies from Maven Central rather than Orbit

2022-04-05 Thread Dirk Fauth via cross-project-issues-dev
I really like the idea. But what about jar signatures? When I brought up the topic for reload4j I was told that the jars need to be signed in order to be included. Is this taken care of? Aleksandar Kurtakov schrieb am Di., 5. Apr. 2022, 13:48: > Hey everyone, > With PGP signing support, latest T

Re: [cross-project-issues-dev] Eclipse Platform to prefer use of dependencies from Maven Central rather than Orbit

2022-04-05 Thread Dirk Fauth via cross-project-issues-dev
@Aleks Maybe jetty is already signed correctly? How will be the process for unsigned content? Christoph Läubrich schrieb am Di., 5. Apr. 2022, 13:54: > > When Maven Central is not OSGi artifact Orbit will be preferred. > > I can only encourage everyone to open a ticket for such project and he

Re: [cross-project-issues-dev] Eclipse Platform to prefer use of dependencies from Maven Central rather than Orbit

2022-04-05 Thread Dirk Fauth via cross-project-issues-dev
-wg/eclipseide.org/-/issues/11 > > On 05.04.2022 13:57, Dirk Fauth via cross-project-issues-dev wrote: > > @Aleks > Maybe jetty is already signed correctly? How will be the process for > unsigned content? > > > Christoph Läubrich schrieb am Di., 5. Apr. 2022, > 13:54:

Re: [cross-project-issues-dev] Eclipse Platform to prefer use of dependencies from Maven Central rather than Orbit

2022-04-05 Thread Dirk Fauth via cross-project-issues-dev
Well, with the Generic Editor available I recently dropped all tpd files. Now I edit the target files via Generic Editor and also have code completion. That is now similar comfortable. But I think Oomph does not yet support the new Maven location. Michael Keppler schrieb am Di., 5. Apr. 2022, 20

Re: [cross-project-issues-dev] PlatformRel vs SimRel vs Orbit Abolishment frustration / Xtext leaving SimRel (again) ?!?

2022-04-06 Thread Dirk Fauth via cross-project-issues-dev
I totally understand the statements and even share the frustration in other places. For example I really liked Gerrit and the contribution process, and now I am kind of forced to move to the GitHub process. Still need to figure out how and when I will be able to do so. For the oomph thing, IIRC on