aws-sdk-java icon indicating copy to clipboard operation
aws-sdk-java copied to clipboard

Update joda-time version in pom.xml

Open tabladrum opened this issue 3 years ago • 11 comments

Issue #, if available:

Description of changes: Updated joda-time version in pom.xml. 2.8.1 is too old.

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

tabladrum avatar Oct 11 '22 16:10 tabladrum

@debora-ito can this be merged?

tabladrum avatar Nov 22 '22 12:11 tabladrum

Hi @tabladrum apologies for the long silence.

Is there any security alerts on the current joda-time version, or are you suggesting we upgrade because it's old?

debora-ito avatar Nov 23 '22 02:11 debora-ito

Thanks @debora-ito for the response. There is no security alert. But 2.8.1 is way too old (2015).

tabladrum avatar Nov 23 '22 03:11 tabladrum

Hi @debora-ito, I'm on Topo's team. For a little more context, our internal process looks at the age of a component, and the older a dependency is, the harder it is for our devs to justify its use. Bumping a few versions would help a number of people out. Thanks for the consideration!

brianwarner avatar Nov 28 '22 16:11 brianwarner

Maybe is related to: https://github.com/aws/aws-sdk-java/pull/2586

yamelsenih avatar Dec 09 '22 16:12 yamelsenih

Happy new year @debora-ito - any feedback on this PR?

tabladrum avatar Jan 04 '23 19:01 tabladrum

Happy New Year!

I brought this up to the team and they are interested in upgrading the joda-time version, but based on some past experiences with joda-time we need to work on writing additional integration tests to make sure nothing will break. The task is in the backlog, pending prioritization.

@tabladrum any particular reason to upgrade to version 2.11.2 when there's newer versions available?

debora-ito avatar Jan 04 '23 23:01 debora-ito

2.12.0...2.12.2 came out after I submitted this PR. Will be good to take the latest.

tabladrum avatar Jan 05 '23 02:01 tabladrum

@debora-ito Updated joda-time to 2.12.1

tabladrum avatar Jan 05 '23 12:01 tabladrum

Also let me know if I can hep anyway in creating the additional test cases.

tabladrum avatar Jan 06 '23 13:01 tabladrum

Pinging again :-) @debora-ito

tabladrum avatar Mar 17 '23 15:03 tabladrum

@tabladrum @brianwarner @cmxconsulting

The joda-time version was upgraded as part of SDK 1.12.704 release. https://github.com/aws/aws-sdk-java/blob/4066cae126e509d6da49001afce1baee6a7b2459/pom.xml#L431

debora-ito avatar Apr 19 '24 18:04 debora-ito