Ehcache extension adds 22 critical vulnerabilities to docker image

Yeah, the EH cache extension needs a serious upgrade to the next major version, it’s a question of resources.

For Lucee 7, we will actually unbundle it (which doesn’t help with that CVE problem) Jira as it’s huge and counts for 20mb of the 90mb far jar! (which is the multiplied on disk when deployed)

The reason the non snapshot versions suddenly appeared is that as part of our release process, i.e. 6.2.0.321, any bundled snapshots are published as stable

1 Like