Skip to content

Remove commons-io dependency #73

@adangel

Description

@adangel

Describe the bug
There seems to be a security (?) issue with commons-io 2.7 - see pmd/pmd#4691

After googling (VULNDB-239195 is behind a paywall) I found this:

https://issues.apache.org/jira/browse/FLINK-22747

VULNDB-239195
"Vendor Specific News/Changelog Entry
https://commons.apache.org/proper/commons-io/changes-report.html#a2.8.0
Vendor Specific Solution URL
apache/commons-io@0de91c0
Vendor Specific Solution URL
apache/commons-io@97ae01c
Bug Tracker
https://issues.apache.org/jira/browse/IO-675"

In PMD, we already removed commons-io some time ago. I think, we should do the same in pmd-designer.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions