cryptacular dependency
Brent Putman
putmanb at georgetown.edu
Fri Mar 6 19:59:47 EST 2020
On 3/2/20 7:16 AM, Andrew Vinall wrote:
>
> I understand Version 4 of Shibboleth will include this update.
Yes, it will ship with 1.2.4. Baring any catastrophic and unforseen
circumstances, OpenSAML 4.0.0 will ship early next week.
> However, could the 3.x branch be updated to include the backported fix
> in cryptacular 1.1.4? Note it is built with JDK7 like its previous
> version.
Given that we've been focused on getting 4.x out the door, we don't at
the moment have any concrete plans for an updated 3.4.x release. We'll
discuss internally.
In the immediate future, from what I see of the changes it's probably
OK to just update your effective dependency to 1.1.4 with a local Maven
override (if using Maven), or just pulling down the updated jar. The
VT authors of that library are on this list and I'll let them comment
on whether they would forsee any problems with that as a short-term
workaround.
I'm sure you can guess that the longer-term answer is going to be
"Update to 4.0".
--Brent
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20200306/e6f0599a/attachment.html>
More information about the dev
mailing list