Question Regarding Recent Security Announcement

2018-11-04 Thread David Dillard
Hi, An email was recently sent to the Apache Announcements list suggesting that users update to Apache Struts 2.3.36 in order to update to Apache Commons

RE: [EXTERNAL] Re: Question Regarding Recent Security Announcement

2018-11-05 Thread David Dillard
stion Regarding Recent Security Announcement niedz., 4 lis 2018 o 18:40 David Dillard napisaƂ(a): > 1. Per the Maven repository, Struts 2.3.36 recommends Fileupload 1.3.2 be > used<https://mvnrepository.com/artifact/org.apache.struts/struts2-core/2.3.36>, > not 1.3.3, so I

RE: [EXTERNAL] Re: Struts 2.5.x support above Java 8

2018-11-11 Thread David Dillard
> We do plan support JDK 9 and JDK 11 as from Struts 2.6 (in development), > maybe we will be able to port those changes into 2.5.x branch but we will see. Really no point in supporting JDK 9 or 10 as they are now EOL. JDK 11 support would be great. ---

RE: [EXTERNAL] Re: Struts 2.5.x support above Java 8

2018-11-12 Thread David Dillard
: Struts Users Mailing List Subject: Re: [EXTERNAL] Re: Struts 2.5.x support above Java 8 Determining support is fraught, because people run on all sorts of JVMs, including EOLed versions :/ On Sun, Nov 11, 2018 at 10:01 AM David Dillard wrote: > > We do plan support JDK 9 and JDK 11 as from

RE: Struts 2.5 upgrade clarification

2018-12-27 Thread David Dillard
Independent of Struts requirements, you should upgrade as Java 6 is no longer receiving updates (not even under a support contract). https://www.oracle.com/technetwork/java/java-se-support-roadmap.html https://www.oracle.com/support/lifetime-support/ -Original Message- From: Gopal, Siv

RE: [EXTERNAL] struts2.5.22 + tiles3.0.8 + commons-beanutils to version 1.9.4

2019-12-09 Thread David Dillard
FYI, BeanUtils 1.9.4 only had one change and that was made to address a vulnerability. See https://commons.apache.org/proper/commons-beanutils/changes-report.html#a1.9.4 If I were you I'd check to see if that vulnerability is an issue for you in the context of Tiles. If it is maybe you can fi

RE: Status of 2.5.23?

2020-08-15 Thread David Dillard
Released about six weeks ago: https://github.com/apache/struts/releases/tag/STRUTS_2_5_23 -Original Message- From: Tellis, Wyatt Sent: Saturday, August 15, 2020 12:00 PM To: 'user@struts.apache.org' Subject: [EXTERNAL] Status of 2.5.23? Hi, What's the status of 2.5.23? The migratio