Skip to content

Patch release v2.2.3 for recent security fixes #617

@JanWesterkamp-iJUG

Description

@JanWesterkamp-iJUG

Thank you for taking your time to talk with us!

What is this issue about?

  • Bug report
  • Feature request
  • Question

Description
Is it possible to cut a patch release (like v2.2.3), that contains the already merged recent security fixes from dependencies?

Especially the following should be covered:

Other patch level updates (and optionally feature enhancements, but no breaking changes) might be included too.

It looks like the plugin is heading for a major release, but we are using it for the generation of specification documents in Jakarta EE and MicroProfile a lot and need to fix it with patch level releases there - so a new major version will break Semantic Versioning then, especially when there are break changes included, that affect us.

Details can be found in these vulnerability reports:

Meanwhile, I created a workaround PR for the asciidoc-asciidoctor-maven-examples:

I can refactor that back, when a patched plugin version is released.

Environment information

  • asciidoctor-maven-plugin version: >2.2.2
  • asciidoctorj version: 2.5.7
  • Maven, Java and OS version: ___

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions