-
-
Notifications
You must be signed in to change notification settings - Fork 72
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Expected release date for 2.5.2? #236
Comments
Let us first thank @hezhangjian for taking over this project. But then, yes, please push out the release. Thank you! |
Latest update here #233 (comment) |
Given this is a CVE that is probably affecting many projects,is there a chance to expedite this release |
+1 for expediting the 2.5.2 release |
Thanks for taking up the torch, @hezhangjian |
Some remarks on the CVE:
So I'm afraid technically "connect2id" (9.x, 10.x) and Spring Security would also be affected by this CVE - although the probability that it can be exploited seems low 🙈 @hezhangjian : Maybe we could elaborate on this in the release notes, too. |
As so often in software supply chain security, fixing the actual vulnerability and quieting the monitoring tools that reported it ain't the same thing. So, if you use Spring Security:
|
@ccudennec-otto |
extract from sonatype response:
|
Thank you for the quick turnaround |
Any update on when a new version can be released . |
looking forward to this release :p |
Access to the sonatype recover. release pulished at 5:30 am local time 😫 |
It is correct that 2.5.2 is supposed to be the only version specified in https://repo.maven.apache.org/maven2/net/minidev/json-smart/maven-metadata.xml This is breaking some upstream dependencies, namely
transitive via
|
I am also experiencing this
|
closed by released, versions can be discussed in #240 |
Project landing page states 2.5.2 was released on 2/7/2025, but I don't see a tag for the release, no release in the project, or in maven.
When can we expect a release for this?
The text was updated successfully, but these errors were encountered: