Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.maint.java > #8406

Transition from libcommons-httpclient-java to libhttpclient-java

Path csiph.com!eternal-september.org!feeder.eternal-september.org!aioe.org!bofh.it!news.nic.it!robomod
From Markus Koschany <apo@gambaru.de>
Newsgroups linux.debian.maint.java
Subject Transition from libcommons-httpclient-java to libhttpclient-java
Date Wed, 30 Sep 2015 20:20:01 +0200
Message-ID <qeu8V-4ns-13@gated-at.bofh.it> (permalink)
X-Original-To "debian-java@lists.debian.org" <debian-java@lists.debian.org>
X-Mailbox-Line From debian-java-request@lists.debian.org Wed Sep 30 18:19:56 2015
Old-Return-Path <apo@gambaru.de>
X-Amavis-Spam-Status No, score=-9.7 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, GMAIL=1, LDO_WHITELIST=-5, MEDS2=2, PGPSIGNATURE=-5, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham autolearn_force=no
X-Policyd-Weight using cached result; rate: -6.1
User-Agent Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Icedove/31.7.0
MIME-Version 1.0
Content-Type multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="diafcwI8hJRFwjrOamT9LM8jKvKk4IPmN"
X-Sa-Exim-Scanned No (on richard.fcube.de); SAEximRunCond expanded to false
X-Mailing-List <debian-java@lists.debian.org> archive/latest/18720
List-ID <debian-java.lists.debian.org>
List-URL <https://lists.debian.org/debian-java/>
List-Archive https://lists.debian.org/msgid-search/560C27B9.1060009@gambaru.de
Approved robomod@news.nic.it
Lines 195
Organization linux.* mail to news gateway
Sender robomod@news.nic.it
X-Original-Date Wed, 30 Sep 2015 20:19:37 +0200
X-Original-Message-ID <560C27B9.1060009@gambaru.de>
Xref csiph.com linux.debian.maint.java:8406

Show key headers only | View raw


[Multipart message — attachments visible in raw view] - view raw

Hi,

I think we should file bug reports and start replacing
libcommons-httpclient-java with libhttpclient-java.

Reasoning:

commons-httpclient is obsolete and has been EOL since 2011. It is no
longer supported and was/is affected by multiple security issues. [1]

I suggest to file bug reports with severity "Important" and to raise the
severity to serious when the list of rdeps is small. The goal is to
remove libcommons-httpclient-java during the Stretch release cycle.

Most of the 34 reverse-dependencies [2] are maintained by us. Complete
dd-list is attached.

There are more packages which should be removed (libservlet2.5-java
comes to mind). More ideas?

My proposed bug report template:

Tags: sid stretch
User: pkg-java-maintainers@lists.alioth.debian.org
Usertags: oldlibs commons-httpclient


Hi,

#PACKAGE# depends on libcommons-httpclient-java, which is obsolete and
has reached EOL status since 2011. It is no longer supported upstream
and was affected by multiple security issues in the recent past.
#PACKAGE# should be ported to the new libhttpclient-java version, so
that we can remove the old, unmaintained one.

Please try to do this before the Stretch release as we are going to try
to remove libcommons-httpclient-java this cycle.

We will bump this issue to serious when the list of rdeps is small and
we are getting ready to remove libcommons-httpclient-java completely.

If you have any questions don't hesitate to ask.

On behalf of the Debian Java Maintainers

Markus



[1] https://bugs.debian.org/781063
[2]

not-yet-commons-ssl
ivy
ant-contrib
netbeans
wsdl2c
activemq
commons-vfs
libspring-java
jenkins-json
libxmlrpc3-java
jftp
wagon
jajuk
spring-build
wagon2
libexml-java
jenkins
axis
jackrabbit
eclipse
mule
maven-docck-plugin
biomaj
triplea
openid4java
lucene-solr
libjboss-common-java
jets3t
jenkins-htmlunit
libreoffice
libowasp-antisamy-java
jakarta-jmeter
jabsorb
jspwiki

Back to linux.debian.maint.java | Previous | NextNext in thread | Find similar


Thread

Transition from libcommons-httpclient-java to libhttpclient-java Markus Koschany <apo@gambaru.de> - 2015-09-30 20:20 +0200
  Re: Transition from libcommons-httpclient-java to libhttpclient-java Emmanuel Bourg <ebourg@apache.org> - 2015-09-30 22:00 +0200
    Re: Transition from libcommons-httpclient-java to libhttpclient-java Markus Koschany <apo@gambaru.de> - 2015-10-01 09:10 +0200
      Re: Transition from libcommons-httpclient-java to libhttpclient-java Markus Koschany <apo@gambaru.de> - 2015-10-05 19:00 +0200

csiph-web