Re: Security vulnerability process for EOL versions

2017-09-14 Thread Lukasz Lenart
2017-09-14 12:05 GMT+02:00 Michael Smith : > A follow on question. > > When would we expect 2.3 to become EOL? No exact plans, probably we will switch to JDK7 as we have problems supporting 2.3.x on JDK6 (lack of tools) but this will be then 2.4.x still keeping focus on security

Re: Security vulnerability process for EOL versions

2017-09-14 Thread Michael Smith
A follow on question. When would we expect 2.3 to become EOL? Thx Mike On 14 September 2017 at 08:13, Lukasz Lenart wrote: > 2017-09-13 18:57 GMT+02:00 Lehmer, Jason : > > In cases where the Struts community is notified or discovers a

Re: Security vulnerability process for EOL versions

2017-09-14 Thread Lukasz Lenart
2017-09-13 18:57 GMT+02:00 Lehmer, Jason : > In cases where the Struts community is notified or discovers a security > vulnerability in a supported version, does the evaluation process include > identifying unsupported versions that may be impacted as well? I realize

Security vulnerability process for EOL versions

2017-09-13 Thread Lehmer, Jason
In cases where the Struts community is notified or discovers a security vulnerability in a supported version, does the evaluation process include identifying unsupported versions that may be impacted as well? I realize the recommendation will likely be to upgrade to a supported version but I