Skip to content

cloudstack uses an org.json:json jar version that is not OSS friendly #8696

@pjfanning

Description

@pjfanning

<cs.json.version>20090211</cs.json.version>

Please use a version from 2023/2024. There are security fixes (CVEs).

The main issue is the license. It was only made properly public domain in late 2022. Prior to that, it had a nonsensical license - that restricted its use for evil. Please read https://www.apache.org/legal/resolved.html (section about JSON license).

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions