Sylwester Lachiewicz
Sylwester Lachiewicz
@dependabot recreate
reported also by user #244
@dependabot rebase
@dependabot recreate
same story https://github.com/apache/maven/issues/8631 where I reverted with https://github.com/apache/maven/commit/763f76cf833cddd6630add035c541ac54bbe381d due same reason history here: https://github.com/apache/maven/issues/8684
can we use this? https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing/privately-reporting-a-security-vulnerability
good idea - lets try for m-jar-p 4.x (ie for Maven 4 only & Java 17). Maven 3.x will not be affected
My plugin-tool branch could be dropped
latest ci runs on `Current runner version: '2.328.0'` safe to merge
Maybe we can use jakarta instead of javax? If it's not a big deal now?