notsoserial on jcenter repo?

Previous Topic Next Topic
 
classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view
|

notsoserial on jcenter repo?

Jacques Le Roux
Administrator
Hi Eirik,

I contact you on behalf of the Apache OFBiz® Project Management Committee.

We have decided to use notsoserial to provide security for our users
https://cwiki.apache.org/confluence/display/OFBIZ/The+infamous+Java+serialization+vulnerability

We recently moved from Ant to Gradle. After this discussion http://markmail.org/message/ppxjeagqrwx6tkj3 (you don't need to read it, just as the cross
reference for us ;)) we thought to ask you if you would mind pushing notsoserial to jcenter repo?

The reason is it's better for us to have you taking care of that rather than having to create a fork and update on your changes. I guess it would help
other projects as well. I know some other Top Level Apache projects are also relying on notsoserial.

I hope it's not too much to ask. I saw that you seems to be in vacation https://twitter.com/eirbjo we are not in a hurry (the cinnamon roll seems
quite weird to me :))

Best regards

Jacques