Remove commons-digester from Core

This issue is archived. You can view it, but you can't modify it. Learn more

XMLWordPrintable

      Currently commons-digester 2.1 is triggering some security alerts on scanner. 

      Digester is not used in core but exposed to some plugins which use it.

      With the help of https://github.com/jenkins-infra/usage-in-plugins    we found the class 

      A draft PR has been opened here https://github.com/jenkinsci/jenkins/pull/5320  for discussion.

      I would personally remove it from core and make some PRs on plugins using it (except very old plugins not anymore maintained)

       

       

            Assignee:
            Olivier Lamy
            Reporter:
            Olivier Lamy
            Archiver:
            Jenkins Service Account

              Created:
              Updated:
              Archived: