jackrabbit
jackrabbit copied to clipboard
JCR-4608 Upgrade to commons-collections4
https://issues.apache.org/jira/browse/JCR-4608 commons-collections 3.2.2 suffers from https://advisory.checkmarx.net/advisory/vulnerability/Cx78f40514-81ff/ Although Jackrabbit itself does not seem to use SetUniqueList, it still exists on the classpath.
can you try to rebase this based on what's currently in trunk?
@rkovarik , @mduerig - please see https://issues.apache.org/jira/browse/JCR-4862 (which is the last non-trivial step in removing the old dependency)
(OBE)