Re: Security issue in groovy<2.5.0
Felix Natter <fnatter@gmx.net> writes:
> Emmanuel Bourg <ebourg@apache.org> writes:
>
> hi Emmanuel,
>
>> Le 26/08/2017 à 18:14, Felix Natter a écrit :
>>
>>> The problem is that it may take weeks/months for groovy 2.5 to be
>>> released, and weeks/months until it's packaged for Debian.
>>
>> How big is the fix for Groovy? Do you know which commits should be
>> backported?
>
> It's a single (but nontrivial) commit:
> https://github.com/apache/groovy/commit/0305a38a0cc8f4190a1486c460ebc6f712ad1a07
>
> The groovy people decided not to backport to groovy 2.4.x, so I am not
> sure whether we shall do it?
OTOH, this is for Debian unstable/testing...
Cheers and Best Regards,
--
Felix Natter
Reply to: