# Clojure Deref (Nov 19, 2021)

DevFeed: [Clojure Deref (Nov 19, 2021)](<https://devfeed.tech/articles/clojure-deref-nov-19-2021-49535.md>)

Original publisher: [Read original article](<https://clojure.org/news/2021/11/19/deref>)

Published: 2021-11-19T00:00:00Z

Content type: news

Language: en

Sources: [Clojure News](<https://devfeed.tech/sources/clojure-news.md>)

Topics: [Clojure](<https://devfeed.tech/topics/clojure.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Software Testing](<https://devfeed.tech/topics/software-testing.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [async](<https://devfeed.tech/topics/async.md>), [Documentation](<https://devfeed.tech/topics/documentation.md>), [Git](<https://devfeed.tech/topics/git.md>), [Java](<https://devfeed.tech/topics/java.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [application-security-testing](<https://devfeed.tech/tags/application-security-testing.md>), [async](<https://devfeed.tech/tags/async.md>), [bug-fixes](<https://devfeed.tech/tags/bug-fixes.md>), [clojure](<https://devfeed.tech/tags/clojure.md>), [docs](<https://devfeed.tech/tags/docs.md>), [java](<https://devfeed.tech/tags/java.md>), [java-9](<https://devfeed.tech/tags/java-9.md>), [programming](<https://devfeed.tech/tags/programming.md>), [release](<https://devfeed.tech/tags/release.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [windows](<https://devfeed.tech/tags/windows.md>)

## AI overview

A November 2021 Clojure ecosystem roundup highlights the initial release of clj-holmes, a static application security testing tool for finding vulnerabilities in Clojure code. It also covers planned Clojure 1.11 and core.async updates, documentation work, Windows compilation improvements, Git integration, and related ecosystem news.

## Source excerpt

Welcome to the Clojure Deref! This is a weekly link/news roundup for the Clojure ecosystem. (@ClojureDeref RSS) Highlights I was glad to see an initial release of clj-holmes, a static application security testing tool to look for vulnerabilities in Clojure code. clj-holmes is an extensible framework and has some initial rules but is open to extension for more. I am pretty regularly asked for a tool in this area similar to Fortify or static scanners in other languages - lots of companies have regulatory requirements to proactively scan code in this way and this is a great start. Check it out if you're interested! In the core We have been moving a bunch of jiras (some new stuff, some bug fixes) through the pipeline and are hoping to get the next 1.11 alpha out early next week with all of that stuff. The 1.11 Targeted list shows everything that's currently open for 1.11. Everything with Approval=Ok there will be in the next alpha plus probably a few more that make it through. (And of course, none of the others are guaranteed to end up in 1.11, that's just what we have in flight at the moment). Likely this will also include a spec release to pick up CLJ-2606 which relates to the trailing map support added in 1.11.0-alpha1. I've spent a fair amount of time on core.async this week, initially focused on ASYNC-204 which is being screened right now, but also I've cleaned up some "won't fix" stuff and fixed some other minor things. Planning to release core.async early next week with those updates. In the process of all that I recalled that I was working on a set of docs for core.async and was shocked to discover it had been two years since I had last touched it. I dusted that off and am almost done with those, better 8 years late than never right? At the end of last week I made several enhancements to the compile-clj task - this will now automatically use the @classpath-file feature on Windows when needed and available (feature was added in Java 9), and you can pass several a