[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Security issue in groovy<2.5.0



Emmanuel Bourg <ebourg@apache.org> writes:

hi Emmanuel,

> Le 26/08/2017 à 18:14, Felix Natter a écrit :
>
>> The problem is that it may take weeks/months for groovy 2.5 to be
>> released, and weeks/months until it's packaged for Debian.
>
> How big is the fix for Groovy? Do you know which commits should be
> backported?

It's a single (but nontrivial) commit:
https://github.com/apache/groovy/commit/0305a38a0cc8f4190a1486c460ebc6f712ad1a07

The groovy people decided not to backport to groovy 2.4.x, so I am not
sure whether we shall do it?

Thanks and Best Regards,
-- 
Felix Natter


Reply to: