OSSIndex / vulns

Report missing advisories and corrections on OSS Index
17 stars 12 forks source link

commons-io version 20030203.000550 08-Nov-2005, non-standard version number of a very old package, looking like an update all the time #257

Open hg42 opened 2 years ago

hg42 commented 2 years ago

I'm sorry, not sure if you would call this a bug, but I do. I don't see any way to submit such a request, but I think it is important enough to be reported.

All kinds of software (correctly from my POV) interprets that non-standard version number as higher than everything else, so it is always suggested as an update. I guess, no one will ever use such an old library, and if so, this is probably not the one to be chosen, as you don't even know which version it really is. So, I request to remove that old version from the repository or if it should be kept, please change the version to something reasonable.

(I also found a RELEASE113 version which is better, because it isn't interpreted as a version number)

Thanks for the effort, Harald