Skip to content

Update scala-xml to 2.0.0#562

Closed
scala-steward wants to merge 1 commit into
apache:masterfrom
scala-steward:update/scala-xml-2.0.0
Closed

Update scala-xml to 2.0.0#562
scala-steward wants to merge 1 commit into
apache:masterfrom
scala-steward:update/scala-xml-2.0.0

Conversation

@scala-steward
Copy link
Copy Markdown
Contributor

Updates org.scala-lang.modules:scala-xml from 1.3.0 to 2.0.0.
GitHub Release Notes - Changelog - Version Diff

I'll automatically update this PR to resolve conflicts as long as you don't change it yourself.

If you'd like to skip this version, you can just close this PR. If you have any feedback, just mention me in the comments below.

Configure Scala Steward for your repository with a .scala-steward.conf file.

Have a fantastic day writing Scala!

Ignore future updates

Add this to your .scala-steward.conf file to ignore future updates of this dependency:

updates.ignore = [ { groupId = "org.scala-lang.modules", artifactId = "scala-xml" } ]

labels: library-update, semver-major

@mbeckerle
Copy link
Copy Markdown
Contributor

We should delay this until after PR #560 gets reviewed and merged.

The release notes for this new version of scala xml say they have changed the default behavior to "secure" i.e., not allowing doctypes and entities, etc. That's part of what was done in PR 560, but PR 560 also adds tests to verify this, and centralizes loading for uniformity.

@mbeckerle
Copy link
Copy Markdown
Contributor

This will be done in a separate regular PR that is updating the XML Loading generally.

@mbeckerle mbeckerle closed this May 17, 2021
@scala-steward scala-steward deleted the update/scala-xml-2.0.0 branch May 18, 2021 18:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants