Skip to content

[JENKINS-65161] Remove commons-digester from Core #11961

@jenkins-infra-bot

Description

@jenkins-infra-bot

Currently commons-digester 2.1 is triggering some security alerts on scanner. 

Digester is not used in core but exposed to some plugins which use it.

With the help of https://github.com/jenkins-infra/usage-in-plugins    we found the class 

A draft PR has been opened here #5320  for discussion.

I would personally remove it from core and make some PRs on plugins using it (except very old plugins not anymore maintained)

 

 


Originally reported by olamy, imported from: Remove commons-digester from Core
  • assignee: olamy
  • status: In Progress
  • priority: Major
  • component(s): core
  • resolution: Unresolved
  • votes: 0
  • watchers: 3
  • imported: 2025-11-24
Raw content of original issue

Currently commons-digester 2.1 is triggering some security alerts on scanner. 

Digester is not used in core but exposed to some plugins which use it.

With the help of https://github.com/jenkins-infra/usage-in-plugins    we found the class 

A draft PR has been opened here #5320  for discussion.

I would personally remove it from core and make some PRs on plugins using it (except very old plugins not anymore maintained)

 

 

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions