You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@groovy.apache.org by Jochen Theodorou <bl...@gmx.org> on 2017/11/27 12:21:10 UTC

updating xstream

Hi,

is there anything speaking agains updating xstream to 1.4.10? I am 
mostly thinking of 
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3674 and 
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7957 here.

bye Jochen

Re: updating xstream

Posted by Jochen Theodorou <bl...@gmx.org>.
ok, thanks. it seems I looked at 2.4.12 then only ;) sorry for not 
checking the dependency on master

Am 28.11.2017 um 05:56 schrieb Paul King:
> For reference:
> https://issues.apache.org/jira/browse/GROOVY-8291
> 
> On Tue, Nov 28, 2017 at 2:16 PM, Daniel Sun <realbluesun@hotmail.com 
> <ma...@hotmail.com>> wrote:
> 
>     Hi Jochen,
> 
>           The version of XStream has already been 1.4.10  ;-)
> 
>     https://github.com/apache/groovy/blob/master/build.gradle#L187
>     <https://github.com/apache/groovy/blob/master/build.gradle#L187>
> 
>     Cheers,
>     Daniel.Sun
> 
> 
> 
>     --
>     Sent from:
>     http://groovy.329449.n5.nabble.com/Groovy-Dev-f372993.html
>     <http://groovy.329449.n5.nabble.com/Groovy-Dev-f372993.html>
> 
> 

Re: updating xstream

Posted by Paul King <pa...@asert.com.au>.
For reference:
https://issues.apache.org/jira/browse/GROOVY-8291

On Tue, Nov 28, 2017 at 2:16 PM, Daniel Sun <re...@hotmail.com> wrote:

> Hi Jochen,
>
>      The version of XStream has already been 1.4.10  ;-)
>
> https://github.com/apache/groovy/blob/master/build.gradle#L187
>
> Cheers,
> Daniel.Sun
>
>
>
> --
> Sent from: http://groovy.329449.n5.nabble.com/Groovy-Dev-f372993.html
>

Re: updating xstream

Posted by Daniel Sun <re...@hotmail.com>.
Hi Jochen,

     The version of XStream has already been 1.4.10  ;-)

https://github.com/apache/groovy/blob/master/build.gradle#L187

Cheers,
Daniel.Sun



--
Sent from: http://groovy.329449.n5.nabble.com/Groovy-Dev-f372993.html