Skip to content

Fix #260: Commons BeanUtils2#488

Closed
melloware wants to merge 3 commits intoJaspersoft:masterfrom
melloware:260
Closed

Fix #260: Commons BeanUtils2#488
melloware wants to merge 3 commits intoJaspersoft:masterfrom
melloware:260

Conversation

@melloware
Copy link

@melloware melloware commented Oct 18, 2024

Fix #260: Commons BeanUtils2

  • Removes the CVE on Commons Collections 3.2
  • Simplifies by removing this dependency from Hibernate it was being used for 1 single Constant which was deprecated and removed from BeanUtils2
  • Allows you to simply change the dependency to Apache Commons BeanUtils2 (if it ever comes out been waiting 5 years)

@melloware
Copy link
Author

After 6 long years Apache Commons BeanUtils2 finally has a release on Maven Central and this PR is updated

@teodord
Copy link
Collaborator

teodord commented Jan 7, 2025

I see the 2.0.0-M1 version being published, but there is no official announcement on the project website at Apache.org.
I assume M1 stands for "milestone 1". Not sure what this means. Is it final release or just an early preview?

@melloware
Copy link
Author

It was just released today its an M1 but its finally in central and so far in all my prod apps its working great. I definitely understand not want to use M1 but thought I would update this PR.

@melloware
Copy link
Author

melloware commented May 28, 2025

Bumped to Collections 4 4.5.0 official and BeanUtils 2.0.0-M2

@dadza
Copy link
Collaborator

dadza commented May 30, 2025

Upgraded to BeanUtils 2.0.0-M2 at 2401b3e

@dadza dadza closed this May 30, 2025
@melloware
Copy link
Author

@dadza weird your PR is almost identical to mine?

@melloware melloware deleted the 260 branch May 30, 2025 14:47
@dadza
Copy link
Collaborator

dadza commented Jun 2, 2025

My changes are almost identical to yours because they serve the same purpose and that's what was required to achieve the desired goal.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Remove use of commons collections 3 coming via beanutils

3 participants