Skip to content

[MSHARED-848] Code Improvement in ReaderFactory to get rid of commons-io dependency #289

Description

@jira-importer

Karl Heinz Marbaise opened MSHARED-848 and commented

Currently the dependency to:

<dependency>
  <groupId>commons-io</groupId>
  <artifactId>commons-io</artifactId>
  <version>2.6</version>
</dependency>

is only needed within the class ReaderFactory which imports org.apache.commons.io.input.XmlStreamReader.

The question: Can that be replaced with something different? In consequence we could get rid of the dependency on commons-io.


Affects: maven-shared-utils-3.3.3

Issue Links:

Remote Links:

0 votes, 5 watchers

Activity

  1. jira-importer commented on Feb 23, 2020

    @jira-importer
    Author

    Elliotte Rusty Harold commented

    This would require reimplementing org.apache.commons.io.input.XmlStreamReader or removing newXmlReader from this class. Just maybe we could do the latter if we first deprecated this and suggested clients depend on org.apache.commons.io.input.XmlStreamReader directly.

  2. jira-importer commented on Jul 25, 2020

    @jira-importer
    Author

    Hervé Boutemy commented

    Elliotte Rusty Harold with the merged PR, do you consider this issue done or not?
    then please update this issue accordingly: close or change fix version

  3. jira-importer commented on Jul 25, 2020

    @jira-importer
    Author

    Elliotte Rusty Harold commented

    not done yet. It's multireleaase if not won't fix.

  4. jira-importer commented on Aug 3, 2022

    @jira-importer
    Author

    Richard O'Sullivan commented

    Apache Commons IO before 2.7 is vulnerable to https://nvd.nist.gov/vuln/detail/CVE-2021-29425, Improper Limitation of a Pathname to a Restricted Directory". The NIST NVD Severity Score is 4.8, MEDIUM. Since the latest Long-Term Support (LTS) version of Java is now V17, the update to commons-io 2.7 or higher or removal of same should be reconsidered.

  5. jira-importer commented on Dec 4, 2022

    @jira-importer
    Author

    Elliotte Rusty Harold commented

    commons-io has been upgraded to 2.11 so the CVE is no longer an issue. The underlying issue remains.

  6. jira-importer commented on Jun 24, 2023

    @jira-importer
    Author

    Elliotte Rusty Harold commented

    Method is deprecated. Will evntually remove it instead.

  7. added
    enhancementNew feature or request
    priority:minorMinor loss of function, or other problem where easy workaround is present
    on Jul 3, 2025
  8. removed
    priority:minorMinor loss of function, or other problem where easy workaround is present
    on Sep 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions