Re: [VOTE] Release Commons Collections 3.2.2 Based on RC1

2015-11-11 Thread Gary Gregory
On Nov 11, 2015 1:56 AM, "Thomas Neidhart" wrote: > > On 11/10/2015 11:41 PM, Gary Gregory wrote: > > On Tue, Nov 10, 2015 at 2:22 PM, Thomas Neidhart < thomas.neidh...@gmail.com> > > wrote: > > > >> On 11/10/2015 10:52 PM, Gary Gregory wrote: > >>> Hi all: > >>> > >>> -1 > >>> > >>> Sorry, the RA

[CANCEL][VOTE] Release Commons Collections 3.2.2 Based on RC1

2015-11-11 Thread Thomas Neidhart
On 11/09/2015 11:37 PM, Thomas Neidhart wrote: > Hi all, > > in order to provide a work-around for the known remote code exploit via > java de-serialization of malicious InvokerTransformer instances, I would > like to start a vote to release Commons Collections 3.2.2 based on RC1. > > I would kin

Re: [VOTE] Release Commons Collections 3.2.2 Based on RC1

2015-11-11 Thread Stefan Bodewig
On 2015-11-09, Thomas Neidhart wrote: > in order to provide a work-around for the known remote code exploit via > java de-serialization of malicious InvokerTransformer instances, I would > like to start a vote to release Commons Collections 3.2.2 based on RC1. +1 Stefan

Re: [VOTE] Release Commons Collections 3.2.2 Based on RC1

2015-11-11 Thread sebb
I agree that the CSS file does not have an AL header, however it is only one line so it is at best doubtful that it needs one. There is little or no evidence of originality / creative expression in that one line. The daemon css file on the other hand is longer than the AL header, so needs the head

Re: [VOTE] Release Commons Collections 3.2.2 Based on RC1

2015-11-11 Thread Thomas Neidhart
On 11/10/2015 11:41 PM, Gary Gregory wrote: > On Tue, Nov 10, 2015 at 2:22 PM, Thomas Neidhart > wrote: > >> On 11/10/2015 10:52 PM, Gary Gregory wrote: >>> Hi all: >>> >>> -1 >>> >>> Sorry, the RAT failure needs to be handled one way or another: exclude >> the >>> files or add headers: >>> >>> U

Re: [VOTE] Release Commons Collections 3.2.2 Based on RC1

2015-11-10 Thread Gary Gregory
On Tue, Nov 10, 2015 at 2:22 PM, Thomas Neidhart wrote: > On 11/10/2015 10:52 PM, Gary Gregory wrote: > > Hi all: > > > > -1 > > > > Sorry, the RAT failure needs to be handled one way or another: exclude > the > > files or add headers: > > > > Unapproved licenses: > > > > data/test/NullComparat

Re: [VOTE] Release Commons Collections 3.2.2 Based on RC1

2015-11-10 Thread Thomas Neidhart
On 11/10/2015 10:52 PM, Gary Gregory wrote: > Hi all: > > -1 > > Sorry, the RAT failure needs to be handled one way or another: exclude the > files or add headers: > > Unapproved licenses: > > data/test/NullComparator.version2.obj1 > data/test/NullComparator.version2.obj2 > xdocs/style/pr

Re: [VOTE] Release Commons Collections 3.2.2 Based on RC1

2015-11-10 Thread Gary Gregory
Hi all: -1 Sorry, the RAT failure needs to be handled one way or another: exclude the files or add headers: Unapproved licenses: data/test/NullComparator.version2.obj1 data/test/NullComparator.version2.obj2 xdocs/style/project.css I imagine the obj files can be excluded but the CSS file

Re: [VOTE] Release Commons Collections 3.2.2 Based on RC1

2015-11-10 Thread Thomas Neidhart
On 11/10/2015 09:59 PM, Luc Maisonobe wrote: > Le 09/11/2015 23:37, Thomas Neidhart a écrit : >> Hi all, >> >> in order to provide a work-around for the known remote code exploit via >> java de-serialization of malicious InvokerTransformer instances, I would >> like to start a vote to release Commo

Re: [VOTE] Release Commons Collections 3.2.2 Based on RC1

2015-11-10 Thread Luc Maisonobe
Le 09/11/2015 23:37, Thomas Neidhart a écrit : > Hi all, > > in order to provide a work-around for the known remote code exploit via > java de-serialization of malicious InvokerTransformer instances, I would > like to start a vote to release Commons Collections 3.2.2 based on RC1. > > I would kin

[VOTE] Release Commons Collections 3.2.2 Based on RC1

2015-11-09 Thread Thomas Neidhart
Hi all, in order to provide a work-around for the known remote code exploit via java de-serialization of malicious InvokerTransformer instances, I would like to start a vote to release Commons Collections 3.2.2 based on RC1. I would kindly ask people to review the RC especially wrt the following