Benjamin/Denis, I've reached out to the people directly and communicated the issues raised in this thread. I've also provided a link this thread. I'll report back as soon as I hear.
+1 on doing something, _anything_ about BIRT. Some of their
vulnerabilities are just nasty. Then there's the perception that bugs just go into /dev/null... https://bugs.eclipse.org/bugs/show_bug.cgi?id=546816
Denis
On 2019-05-10 8:41 p.m., Benjamin Cabé
wrote:
Hi,
Not sure if this belongs to the AC but I do
think to some extent it does. I've been on the security@
mailing list for a number of years and I can't remember one
single time where the BIRT project team has engaged w.r.t to
the security vulnerabilities that are regularly reported.
How do we feel about shipping a simrel with
numerous known vulnerabilities?
_______________________________________________
eclipse.org-architecture-council mailing list
eclipse.org-architecture-council@xxxxxxxxxxx
https://www.eclipse.org/mailman/listinfo/eclipse.org-architecture-council
IMPORTANT: Membership in this list is generated by processes internal to the Eclipse Foundation. To be permanently removed from this list, you must contact emo@xxxxxxxxxxx to request removal.
_______________________________________________ eclipse.org-architecture-council mailing list eclipse.org-architecture-council@xxxxxxxxxxxhttps://www.eclipse.org/mailman/listinfo/eclipse.org-architecture-council IMPORTANT: Membership in this list is generated by processes internal to the Eclipse Foundation. To be permanently removed from this list, you must contact emo@xxxxxxxxxxx to request removal.
|