Re: [PROPOSAL] freeze trunk for new features in favor of a release 24.x branch preparation / future roadmap

2024-05-08 Thread Jacques Le Roux
Ah, last but not least: I think we should at least wait for Freemarker 2.3.33 that we successfully tested on demo. The vote should be soon, hence the release. Le 08/05/2024 à 20:47, Jacques Le Roux a écrit : Thanks to clarify Michael, Inline when needed... Le 08/05/2024 à 13:59, Michael

Re: [PROPOSAL] freeze trunk for new features in favor of a release 24.x branch preparation / future roadmap

2024-05-08 Thread Jacques Le Roux
Thanks to clarify Michael, Inline when needed... Le 08/05/2024 à 13:59, Michael Brohl a écrit : Hi everyone, my main point for having a roadmap and (if necessary) freezing trunk (for a short time) before creating a release branch in the future was to avoid the situation we have now: 1. we

Re: [PROPOSAL] freeze trunk for new features in favor of a release 24.x branch preparation / future roadmap

2024-05-08 Thread Jacques Le Roux
Thanks for confirming Le 08/05/2024 à 15:45, Pranay Pandey a écrit : Hi Jacques, Yeah, I wanted to say that. As long as we are sure of test coverage, all the critical paths are working. Best regards, Pranay Pandey On Tue, 7 May 2024 at 22:11, Jacques Le Roux wrote: Ha sorry Pranay, I

CVE-2024-32113: Apache OFBiz: Path traversal leading to RCE

2024-05-08 Thread Jacques Le Roux
Severity: important Affected versions: - Apache OFBiz before 18.12.13 Description: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version

Re: [PROPOSAL] freeze trunk for new features in favor of a release 24.x branch preparation / future roadmap

2024-05-08 Thread Pranay Pandey
Hi Jacques, Yeah, I wanted to say that. As long as we are sure of test coverage, all the critical paths are working. Best regards, Pranay Pandey On Tue, 7 May 2024 at 22:11, Jacques Le Roux wrote: > Ha sorry Pranay, > > I did not get your point, I guess you were discussing before frezzing

Re: [PROPOSAL] freeze trunk for new features in favor of a release 24.x branch preparation / future roadmap

2024-05-08 Thread Pranay Pandey
Hi Michael, Yeah, that makes a lot of sense to have a structure in place for sure. Best regards, Pranay Pandey On Wed, 8 May 2024 at 17:30, Michael Brohl wrote: > Hi everyone, > > my main point for having a roadmap and (if necessary) freezing trunk > (for a short time) before creating a

Re: [PROPOSAL] freeze trunk for new features in favor of a release 24.x branch preparation / future roadmap

2024-05-08 Thread Michael Brohl
Hi everyone, my main point for having a roadmap and (if necessary) freezing trunk (for a short time) before creating a release branch in the future was to avoid the situation we have now: 1. we agreed to create a new release branch some time ago 2. there were some open tasks which blocked

Re: [VOTE] [RESULT] Apache OFBiz 18.12.13

2024-05-08 Thread Jacques Le Roux
OK, thanks Jacopo Le 08/05/2024 à 13:50, Jacopo Cappellato a écrit : Yes, it is normal because that is the dev distribution folder: as soon as the release becomes official the files are moved to the official distribution folder: https://downloads.apache.org/ofbiz/ Jacopo On Tue, May 7, 2024

Re: [VOTE] [RESULT] Apache OFBiz 18.12.13

2024-05-08 Thread Jacopo Cappellato
Yes, it is normal because that is the dev distribution folder: as soon as the release becomes official the files are moved to the official distribution folder: https://downloads.apache.org/ofbiz/ Jacopo On Tue, May 7, 2024 at 4:07 PM Jacques Le Roux wrote: > > Hi Jacopo, > > I see only KEYS > >