[batchee] future?

2022-11-17 Thread Romain Manni-Bucau
Hi all, We discussed some time ago to drop batchee as an active subproject, wonder where we are now on this? Do we freeze it and document we don't maintain it anymore? Romain Manni-Bucau @rmannibucau | Blog | Old Blog

[GitHub] [geronimo-batchee] rmannibucau commented on pull request #12: [SECURITY] Fix Zip Slip Vulnerability

2022-11-17 Thread GitBox
rmannibucau commented on PR #12: URL: https://github.com/apache/geronimo-batchee/pull/12#issuecomment-1319639612 Well there is no discussion yet - and to be honest "anywhere" does not mean "downloaded from a random source" but literally "put by an user there". So BatchEE does not take into

[GitHub] [geronimo-batchee] JLLeitschuh commented on pull request #12: [SECURITY] Fix Zip Slip Vulnerability

2022-11-17 Thread GitBox
JLLeitschuh commented on PR #12: URL: https://github.com/apache/geronimo-batchee/pull/12#issuecomment-1319372016 If the zip archive could come from anywhere, then it would be appropriate to issue a CVE here. Is there a discussion inside the ASF about this, or does one need to be kicked