[ANNOUNCEMENT] HttpComponents Client 5.2.1 GA Released

2023-08-21 Thread Oleg Kalnichevski
The Apache HttpComponents project is pleased to announce 5.3-alpha1 release of HttpComponents HttpClient. This is the first release in the 5.3 release series that introduces support for the Bearer authentication scheme (RFC 6750) and deprecates NTLM and GSS based experimental authentication

[ANNOUNCEMENT] HttpComponents Client 5.3-alpha1 Released (corrected)

2023-08-21 Thread Oleg Kalnichevski
The Apache HttpComponents project is pleased to announce 5.3-alpha1 release of HttpComponents HttpClient. This is the first release in the 5.3 release series that introduces support for the Bearer authentication scheme (RFC 6750) and deprecates NTLM and GSS based experimental authentication

[ANNOUNCE] Apache Pekko (Incubating) gRPC 1.0.0 available

2023-08-21 Thread PJ Fanning
Hi everyone, The Apache Pekko (Incubating) Team is happy to announce the release of Apache Pekko (Incubating) gRPC 1.0.0. Apache Pekko (Incubating) is an open source toolkit and runtime simplifying the construction of concurrent and distributed applications on the JVM. It is a fork of Akka and

CVE-2022-46751: Apache Ivy: XML External Entity vulnerability in Apache Ivy

2023-08-21 Thread Stefan Bodewig
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Severity: moderate Affected versions: - - Apache Ivy 1.0.0 through 2.5.1 Description: Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache Ivy.This

[ANN] Apache Ivy 2.5.2 Released

2023-08-21 Thread Stefan Bodewig
The Apache Ant Team is pleased to announce the release of Apache Ivy 2.5.2. Apache Ivy is a dependency manager focusing on flexibility and simplicity with strong integration into the Apache Ant build tool. Ivy 2.5.2 is bugfix release and addresses an XML external entity injection vulnerability,