[VOTE] Release Apache Commons IO 2.20.0 based on RC1

2025-07-14 Thread Gary Gregory
We have fixed a few bugs and added enhancements since Apache Commons IO 2.19.0 was released, so I would like to release Apache Commons IO 2.20.0. Apache Commons IO 2.20.0 RC1 is available for review here: https://dist.apache.org/repos/dist/dev/commons/io/2.20.0-RC1 (svn revision 78176) The Gi

Wrong version for https://nvd.nist.gov/vuln/detail/CVE-2025-48976#match-16814623

2025-07-14 Thread Gary Gregory
Hi NIST, Gary Gregory here from the Apache Commons project, reporting that https://nvd.nist.gov/vuln/detail/CVE-2025-48976#match-16814623 lists version 2.0.0-M4 as vulnerable when it fixes the issue. Our ticket: https://issues.apache.org/jira/browse/FILEUPLOAD-361 TY, Gary -