[
https://issues.jboss.org/browse/JBDS-3562?page=com.atlassian.jira.plugin....
]
Nick Boldt commented on JBDS-3562:
----------------------------------
"eclipse plugins aren't known to be vulnerable"
and
"Eclipse.org plugins need released too."
Seem to state opposite things. Why would
Eclipse.org plugins need [to be] released too if
they're not vulnerable?
Related: jpa & m2e both have open bugzillas/JIRAs about this problem, so I'm going
to assume your second statement was the correct one.
I would also bet that just because the jpa feature requires apache.commons.collections
3.2.0, we will likely be able to install 3.2.2 on top too, possibly even replacing /
deactivating the older version.
Prepare for 9.0.1 / 9.1.0
--------------------------
Key: JBDS-3562
URL:
https://issues.jboss.org/browse/JBDS-3562
Project: Developer Studio (JBoss Developer Studio)
Issue Type: Bug
Components: build
Affects Versions: 9.0.1.GA
Reporter: Nick Boldt
Assignee: Nick Boldt
Fix For: 9.0.1.GA
Tracker JIRA to house things to do to prepare for 9.0.1 / 9.1.0 branches & builds.
Because JBDS 9.0.0 includes the compromised version of
apache.commons.collections (JBDS-3560, JBDS-3561), we need to at some point respin it,
which
will include:
a) updated JBT/JBDS target platforms 4.50.1.* and 4.51.1.*
b) repin of JBDS update sites and installer jars
To that end, I've created the following new branches:
https://github.com/jbosstools/jbosstools-target-platforms/commits/4.50.1.x
https://github.com/jbosstools/jbosstools-target-platforms/commits/4.51.1.x
And I've bumped the version of the target platforms in the 4.50.x and
4.51.x branches to 4.50.2.Beta1-SNAPSHOT and 4.51.2.Beta1-SNAPSHOT,
respectively.
JBDS is now at version 9.1.0 in the 4.3.x branch and 9.0.1 in the
4.3.1.x branch.
https://github.com/jbdevstudio/jbdevstudio-product/commits/jbosstools-4.3...
(new, 9.0.1)
https://github.com/jbdevstudio/jbdevstudio-product/commits/jbosstools-4.3.x
(updated to 9.1.0)
So, now we just need to ensure that the correct BUILD_ALIAS (CR1 for
9.0.1, Beta1 for 9.1.0) and target platforms are used.
--
This message was sent by Atlassian JIRA
(v6.4.11#64026)