-
Notifications
You must be signed in to change notification settings - Fork 114
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
MP 6 Issues PR #298
MP 6 Issues PR #298
Conversation
@Emily-Jiang: I am preparing additonal fixes for the missing locale config (one position at least) and for the very outdated AsciiDoc configuration, using the proposed changes from the MicroProfile Parent as base (see eclipse/microprofile-parent#66). Do you think it should be part of this PR or a separate one? |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM! Thanks @JanWesterkamp-iJUG
@JanWesterkamp-iJUG I suggest not to add more fixes before the ballot. We can do the subsequent fixes in the next one as the next release is around the corner. Thoughts? |
@Emily-Jiang I examined the old versions and there are exisitng vulnerabilities, that got fixed, see references here: https://mvnrepository.com/artifact/org.asciidoctor/asciidoctor-maven-plugin/1.5.8 (4 CVEs) Even in 2.2.2 some of it's preconfigured dependencies are updated in the POM - I can check the impact for that too, if you want me to. So I strongly suggest we fix it, as we have a proven solution availabe yet, that solves three of four issues and it's a major update we can do only in a major update usually. |
@JanWesterkamp-iJUG I thought this further. Since you only need to update the maven plugin version, go ahead to do a new commit on this PR. |
@Emily-Jiang I will do that, will you merge this one first? |
@Emily-Jiang, as discussed earlier, here is my PR regarding quick fix findings - the ones I found during my review and the ones I found during fixing the first findings.
Details of the changes could get sorted out by following my commit messages.
I reverted the changes regarding the very outdated AsciiDoc plugin versions getting aligned to the MicroProfile Parent ones - then the logo vanishes. Fixing that requires additional work (see PR there: eclipse/microprofile-parent#66), as fixing some of the formatting without risk too.
In the future we shoud think about reusing the Parent here.