-
Enhancement
-
Resolution: Done
-
Major
-
None
-
None
-
None
-
False
-
None
-
False
-
NEW
-
NEW
-
---
-
---
-
-
Wildfly-elytron is shaded dependency which wrongly is packaged also with all dependencies it shades.
This brings the conflicts when any dependency is not compatible or is vulnerable and it requires to be upgraded.
It was fixed in Wildfly/EAP deployment to have provided scope in Kie Server components, but we would need to fix also server deployments where Elytron is not internal module provided by server container.
Like https://github.com/kiegroup/droolsjbpm-integration/blob/main/kie-server-parent/kie-server-wars/kie-server/src/main/assembly/assembly-servlet-container.xml or https://github.com/kiegroup/droolsjbpm-integration/blob/main/kie-server-parent/kie-server-wars/kie-server/src/main/assembly/assembly-ee7-container.xml
where it would need to use individual elytron modules instead of aggregated one.
- is caused by
-
ELY-1971 wildlfy-elytron jar shaded jar incorrectly contains external dependencies
- Open