You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@guacamole.apache.org by "Nick Couchman (JIRA)" <ji...@apache.org> on 2019/02/15 13:27:00 UTC

[jira] [Commented] (GUACAMOLE-734) Your project glyptodon/guacamole-client is using buggy third-party libraries [WARNING]

    [ https://issues.apache.org/jira/browse/GUACAMOLE-734?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16769308#comment-16769308 ] 

Nick Couchman commented on GUACAMOLE-734:
-----------------------------------------

[~calvinhkf]: Please provide a few more details on this.  In particular:
* You indicate the glyptodon/guacamole-client repository, which, while it contains a current version of the Guacamole code, is not the same as the apache/guacamole-client repository
* You do not indicate what version of the code this applies to.  Please provide a version.
* You have a "Require JDK 1.6 to run Logback", but it's unclear what that means.  The Guacamole project already requires JDK 1.8 for compile and JRE 1.8 for runtime.  The issue you referenced indicates removal of 1.5 support - Guacamole does not, and has not for quite some time, supported compile or run with JDK 1.5.

> Your project glyptodon/guacamole-client is using buggy third-party libraries [WARNING]
> --------------------------------------------------------------------------------------
>
>                 Key: GUACAMOLE-734
>                 URL: https://issues.apache.org/jira/browse/GUACAMOLE-734
>             Project: Guacamole
>          Issue Type: Bug
>            Reporter: Kaifeng Huang
>            Priority: Minor
>
> Hi, there!
>     We are a research team working on third-party library analysis. We have found that some widely-used third-party libraries in your project have major/critical bugs, which will degrade the quality of your project. We highly recommend you to update those libraries to new versions.
>     We have attached the buggy third-party libraries and corresponding jira issue links below for you to have more detailed information.
> 	1. ch.qos.logback logback-classic
> 	version: 1.1.2
> 	Jira issues:
> 	ConfigurationDelegate.groovy should check AppenderAttachable not AsyncAppender
> 	affectsVersions:1.1.2
> 	https://jira.qos.ch/projects/LOGBACK/issues/LOGBACK-1008?filter=allopenissues
> 	NullPointerException from RollingFileAppender
> 	affectsVersions:1.1.2
> 	https://jira.qos.ch/projects/LOGBACK/issues/LOGBACK-1054?filter=allopenissues
> 	DatePatternToRegexTest fails on non English locale
> 	affectsVersions:1.1.2
> 	https://jira.qos.ch/projects/LOGBACK/issues/LOGBACK-969?filter=allopenissues
> 	Require JDK 1.6 to run logback
> 	affectsVersions:1.1.2
> 	https://jira.qos.ch/projects/LOGBACK/issues/LOGBACK-972?filter=allopenissues
> Sincerely~
> FDU Software Engineering Lab
> Feb 15th,2019



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)