-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

All,

On 3/9/17 6:57 PM, Claude Brisson (JIRA) wrote:
> 
> [
> https://issues.apache.org/jira/browse/VELTOOLS-171?page=com.atlassian.
jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=1590
4098#comment-15904098
> ]
> 
> Claude Brisson commented on VELTOOLS-171: 
> -----------------------------------------
> 
> I think it would be quite trivial to fix the 2.0. If someone
> submits a patch, it shouldn't be too hard for us (still ant, not
> yet maven, FYI Michael) to publish a 2.1. I agree, this discussion
> should better happen on the dev list.

I'm (still) a user of Struts 1 and likely to be a user of Struts 2 in
the future, and I need continued support for Struts in Velocity via
VelocityTools. Struts 1 support reached maturity in the past, so
there's little work to do, there. I'm not familiar enough (yet) with
Struts 2 to do a competent job supporting Struts 2 in Velocity-Tools.

As for the recent Struts-related vulnerability, Velocity-Tools uses
Struts only as a compile-time dependency (or should, anyway). It is
not critically-important that Velocity upgrade its compile-time
dependency to a recent version of Struts because the use of
Velocity-Tools does not mandate S2 or preclude an S2 upgrade by the
containing application.

- -chris
-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - http://gpgtools.org
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCAAGBQJYyE3/AAoJEBzwKT+lPKRYuhsP/1vCG3xi5oRyaRyxvQpJiH3F
Zz6rx4i4qEDG4ZsEf1D/gGsImtgZmYGkzXv3tKjo5fJzmzZrstagxz7GivTxlJUY
Apxx76qsmhALSDW9hHtWnPTaxgDl2rNcNiczDH7ZhdZHgQ4Z33nRyJv3Jry9qBfG
C1aYIPB0nBnI4/qurg1H8fD0jV3B5Kj5SGc1DNTxZRabUVxhAQ1BIgdsABt0GQHY
c++dD6TeOAHmtoLeur+60PMzXNDjRZntohQAGG+dQTj1ujSBS2NsI3bsHaDDjC9H
yUK8/KgRLrewb3t0I15KqIo9gZsUv0nxwA6nvxx2JP5bFhLmbRLXnEqb/Y9h6V5v
yvLX+2ALteF+O+HkG+gWTZFzbQUMyrfNhdA7C1Hy5Vk7t98to1TLB4qsxxxFDDai
SDW7sUSc3EJrlKNyYgnGWqUDJZv/QVMQKcY4DdEPmvAvUAZB3zY9UR/q9F04Zckb
DBkeaXEAkdL1NCR96MvrqNo7tzEIc9V4lupvud79vXwQgZ60CeXEovXKXCW92RXk
+Eyc2QhV4nDgstJ3y6lqjVV8LpOIz6eJ8LJE8+Be5ogrAWi66cB9ki86Q1viGkF1
o7PcSEWQPMrXg6w3+eRXYttQd/N713fcx1cSIRujYoy1Rv9j8Y3/irVZGDphA8Ef
P/mS469OmlPr3j2hnoKb
=oNSg
-----END PGP SIGNATURE-----

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@velocity.apache.org
For additional commands, e-mail: dev-h...@velocity.apache.org

Reply via email to