Proposal: Experimental VEX File for Apache Commons Projects

2025-07-20 Thread Piotr P. Karwasz
Hi all, As you know, we released CVE-2025-48924 for Commons Lang a few days ago. Due to the widespread use of the library, the CVE has already triggered some user responses: for example, in [1], users reported being forced to upgrade Commons Lang and remove deprecated method usage due to inter

[VOTE] Release Apache Commons Text 1.14.0 based on RC1

2025-07-20 Thread Gary Gregory
We have fixed a few bugs and added enhancements since Apache Commons Text 1.13.1 was released, so I would like to release Apache Commons Text 1.14.0. Apache Commons Text 1.14.0 RC1 is available for review here: https://dist.apache.org/repos/dist/dev/commons/text/1.14.0-RC1 (svn revision 78270)