Details
-
Wish
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
None
-
None
-
None
Description
We've gotten requests over the years to get rid of xerces. Should we do that in 3.x/main?
The one nice thing about including it is that it offers some consistency across java versions and platforms. This can help with securing the parsers (against xxe, etc). This can also make debugging easier.
However, as people have pointed out, the xerces project appears to be in security-fix-only mode.
WDYT?
Attachments
Issue Links
- links to