4 ms·
Groovy was a security nightmare. The groovy sandbox simply doesn't do enough to protect a server. Our scripting language "Painless" is faster and more secure t
by timv 9y ago
Groovy was a security nightmare. The groovy sandbox simply doesn't do enough to protect a server.
Our scripting language "Painless" is faster and more secure than we could achieve with groovy, so in Elasticsearch 5.0 we made Painless the default and deprecated groovy.
In 6.0, groovy is gone.
We didn't do it to be minimalist, but we couldn't in good conscience continue to ship an insecure scripting language when we had an alternative.
Disclosure: I work at Elastic on security.