Uploaded image for project: 'jBPM'
  1. jBPM
  2. JBPM-10173

Kie-Server usage of wildfly-elytron in different deployments

XMLWordPrintable

    • Icon: Enhancement Enhancement
    • Resolution: Done
    • Icon: Major Major
    • 7.74.0.Final
    • None
    • None
    • None
    • False
    • None
    • False
    • NEW
    • NEW
    • ---
    • ---

      Wildfly-elytron is shaded dependency which wrongly is packaged also with all dependencies it shades.
      This brings the conflicts when any dependency is not compatible or is vulnerable and it requires to be upgraded.
      It was fixed in Wildfly/EAP deployment to have provided scope in Kie Server components, but we would need to fix also server deployments where Elytron is not internal module provided by server container.
      Like https://github.com/kiegroup/droolsjbpm-integration/blob/main/kie-server-parent/kie-server-wars/kie-server/src/main/assembly/assembly-servlet-container.xml or https://github.com/kiegroup/droolsjbpm-integration/blob/main/kie-server-parent/kie-server-wars/kie-server/src/main/assembly/assembly-ee7-container.xml
      where it would need to use individual elytron modules instead of aggregated one.

              alampare Andrea Lamparelli
              mnovotny@redhat.com Marek Novotny
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: