apache / apache/maven-site

Document and discourage min and max suffixes in version strings

Open
#1,489 0 comments 0 reactions 0 assignees View on GitHub
bug
Dominant language
Java
Stars
123
Forks
301
Avg merge
16h 59m
Merged PRs (30d)
32

Description

### Bug description

This is a security vulnerability like other forms of version ranges

### Maven site URL where bug exists

https://maven.apache.org/pom.html#Version_Order_Specification

Contributor guide

No contributing guide indexed for this repository

Research direction

Start at the Maven site Version Order Specification page linked in the issue and review how version ranges are documented. Add guidance that min and max suffixes should be discouraged because of the stated security concern; done means the page clearly documents this restriction.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
documentation, security
Issue type
Documentation
Difficulty
2/5
Estimated time
Half a day
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.