Re: Proposal to bring GEODE-8456 (shiro upgrade) to support branches

2020-09-01 Thread Raymond Ingles
+1 On 8/31/20, 7:19 PM, "Owen Nichols" wrote: Recently shiro-1.5.3.jar is getting flagged for ‘high’ security vulnerability CVE-2020-13933. Analysis shows that Geode does not use Shiro in a manner that would expose this vulnerability. The risk of bringing GEODE-8456 is low

Re: Proposal to bring GEODE-8456 (shiro upgrade) to support branches

2020-09-01 Thread Owen Nichols
Sarah Abbey wrote: > > > +1 > > > > From: Ju@N > > Sent: Tuesday, September 1, 2020 4:10 AM > > To: dev@geode.apache.org > > Subject: Re: Proposal to bring GEODE-8456 (shiro upgrade) to support

Re: Proposal to bring GEODE-8456 (shiro upgrade) to support branches

2020-09-01 Thread Dave Barnes
> > Sent: Tuesday, September 1, 2020 4:10 AM > > To: dev@geode.apache.org > > Subject: Re: Proposal to bring GEODE-8456 (shiro upgrade) to support > > branches > > > > +1 > > > > On Tue, 1 Sep 2020 at 01:11, Donal Evans wrote: > > > > &

Re: Proposal to bring GEODE-8456 (shiro upgrade) to support branches

2020-09-01 Thread Alexander Murmann
+1 On Tue, Sep 1, 2020 at 6:19 AM Sarah Abbey wrote: > +1 > > From: Ju@N > Sent: Tuesday, September 1, 2020 4:10 AM > To: dev@geode.apache.org > Subject: Re: Proposal to bring GEODE-8456 (shiro upgrade) to support > branches > > +1 &

Re: Proposal to bring GEODE-8456 (shiro upgrade) to support branches

2020-09-01 Thread Sarah Abbey
+1 From: Ju@N Sent: Tuesday, September 1, 2020 4:10 AM To: dev@geode.apache.org Subject: Re: Proposal to bring GEODE-8456 (shiro upgrade) to support branches +1 On Tue, 1 Sep 2020 at 01:11, Donal Evans wrote: > +1 > > We still have outstandin

Re: Proposal to bring GEODE-8456 (shiro upgrade) to support branches

2020-09-01 Thread Ju@N
+1 On Tue, 1 Sep 2020 at 01:11, Donal Evans wrote: > +1 > > We still have outstanding release blockers for 1.13, so getting this fix > in now just prevents extra work in the future without slowing us down now. > > From: Owen Nichols > Sent: Monday, August 31,

Re: Proposal to bring GEODE-8456 (shiro upgrade) to support branches

2020-08-31 Thread Donal Evans
+1 We still have outstanding release blockers for 1.13, so getting this fix in now just prevents extra work in the future without slowing us down now. From: Owen Nichols Sent: Monday, August 31, 2020 4:19 PM To: dev@geode.apache.org Subject: Proposal to bring