[ 
https://issues.apache.org/jira/browse/TOMEE-4677?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18109856#comment-18109856
 ] 

Richard Zowalla commented on TOMEE-4677:
----------------------------------------

Hi all,

we are usually aware of such updates (including the assosciated CVEs) - 
dependabot runs against our code base and dependency upgrades are typically 
picked up before a release anyway.

As is usual for ASF projects, there is no explicit roadmap or fixed date for 
10.3.0. A release happens when a volunteer finds the time to prepare and drive 
one.

Please also keep in mind that maintainer capacity is currently largely bound by 
unsolicited, automated LLM-based scanning of the foundation's code bases. 
Triaging those reports consumes time that is then no longer available for 
development or release work.

Gruß
Richard

> Upgrade tomcat to 10.1.59
> -------------------------
>
>                 Key: TOMEE-4677
>                 URL: https://issues.apache.org/jira/browse/TOMEE-4677
>             Project: TomEE
>          Issue Type: Dependency upgrade
>          Components: TomEE Core Server
>    Affects Versions: 10.2.0
>            Reporter: RAJU THANNEERU
>            Priority: Major
>             Fix For: 10.3.0
>
>          Time Spent: 20m
>  Remaining Estimate: 0h
>
> |[CVE-2026-66299|https://nvd.nist.gov/vuln/detail/CVE-2026-66299]|7.5|high|fixed
>  in 11.0.25, 10.1.58, 9.0.121|2026-08-06 09:29:28 +0000 
> UTC|[tomcat-util_10.1.57|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:605259df88676786462dc8161fa3b454c4079a314fc27b916b9a2e604863155c_tomcat-util_10.1.57]|this
>  image|/usr/local/tomee/lib/tomcat-util.jar|



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to