Skip to content

Dependencies: commons-configuration and commons-lang #748

Answered by kwwall
RockefellerA asked this question in Q&A
Discussion options

You must be logged in to vote

@RockefellerA wrote:

Hello, I'm using ESAPI and am also using whitesource/Mend, which is flagging two dependencies ESAPI has: commons-configuration and commons-lang. These have new versions, commons-configuration2 and commons-lang3.

I've done a little research and it looks like the owasp Java Encoder is compatible with commons-lang3, but I wasn't sure if the main ESAPI project is fully compatible. I couldn't find any information on whether commons-configuration2 was compatible.

I can't comment on the OWASP Java Encoder Project. You'd have to ask them.

Are these planned to be updated in the future, or are there some workarounds you'd suggest? Thank you for your time!

To add to what @je…

Replies: 3 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@RockefellerA
Comment options

Answer selected by RockefellerA
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants