Hi everyone,

Here are the PRs targeted for the RC3 release:
https://github.com/apache/roller/pulls?q=is%3Apr+state%3Aopen+label%3A6.1.6

Feedback and reviews are welcome. I hope to review these and have RC3 ready
in the next few days.

Thanks,
Dave


On Wed, Sep 09, 2026 03:46 PM, Matt Raible <[email protected]> wrote:

> -1 (but a soft one, and happy to flip to +1 once this is fixed)
>
> Thanks for rolling RC2, Dave! The good news is the artifacts and the
> actual changes are in great shape. The bad news is I hit one regression
> that breaks the entry editor, and I don't think we should ship it.
>
> I did a full walk through a fresh install on Derby: created the first
> user, created a weblog, set the front page, published an entry, uploaded
> media, imported an OPML blogroll, and posted comments. The security work
> all holds up in the running app. SVG uploads come back as an octet-stream
> attachment with nosniff instead of rendering, a bad comment URL shows as
> plain text in moderation rather than a live link, XML-RPC rejects vendor
> extension types, the salt filters handle the multipart bookmark import
> without a false Security Violation, and the front-page setup flow no longer
> locks anonymous visitors out of the site root. Enclosures round-trip into
> both feeds and the feeds stay well-formed.
>
> The problem:
>
> jQuery UI 404s on every authoring page, which kills the date picker and
> the tag autocomplete in the entry editor and drops the jQuery UI styling.
> The #180 dependency bump moved jquery-ui to 1.14.2+1 and wrote that literal
> version, plus sign and all, into the resource URLs in head.jsp:
>
>     /webjars/jquery-ui/1.14.2+1/jquery-ui.min.js  -> 404
>     /webjars/jquery-ui/1.14.2+1/jquery-ui.css     -> 404
>
> The plus in the path never resolves, whether it's sent raw or as %2B, so
> both files come back 404 and the console fills up with "$(...).datepicker
> is not a function" and "$(...).autocomplete is not a function". It's baked
> into the shipped roller.war, and it's a regression from 6.1.5, which was on
> 1.14.1.
>
> The fix is one line. The webjar ships its resources under the plus-free
> path too, so pointing head.jsp at 1.14.2 instead of 1.14.2+1 returns 200
> and brings the editor back. Nothing else needs to change.
>
> Everything else I found was cosmetic (the new CSP meta tag logs a harmless
> "frame-ancestors is ignored in a meta element" warning, which we can clean
> up later by moving it to a header). Publishing, rendering, media, and
> comments are otherwise solid.
>
> Cheers,
>
> Matt
>
>
> > On Sep 7, 2026, at 15:31, Dave <[email protected]> wrote:
> >
> > Hello Roller community,
> >
> > This is a vote to release Apache Roller 6.1.6, release candidate 2. RC2
> > supersedes RC1 -- please disregard the RC1 vote. On top of RC1, it pulls
> in
> > the dependency updates and JDK 25 test matrix from #180 and a small
> > authoring-template consistency change on the comment management page.
> >
> > Roller 6.1.6 is a maintenance release: it retires three obsolete
> features,
> > hardens media and enclosure handling, updates dependencies, and fixes the
> > source distribution so that it builds.
> >
> > Release notes:
> > https://github.com/apache/roller/blob/roller-6.1.6-rc2/CHANGES.md
> >
> > Git tag roller-6.1.6-rc2 (commit 6b7e246b2):
> > https://github.com/apache/roller/tree/roller-6.1.6-rc2
> >
> > Artifacts staged at:
> > https://dist.apache.org/repos/dist/dev/roller/roller-6.1/v6.1.6/
> >
> > Signed with key 8FEC6F9CBA59703C, which is in:
> > https://downloads.apache.org/roller/KEYS
> >
> > To verify:
> > curl -O https://downloads.apache.org/roller/KEYS
> > gpg --import KEYS
> > gpg --verify apache-roller-6.1.6-rc2-source.tar.gz.asc
> > shasum -c apache-roller-6.1.6-rc2-source.tar.gz.sha512
> >
> > I have verified signatures and checksums, built the source archive on JDK
> > 11, and confirmed LICENSE and NOTICE in all four archives.
> >
> > The vote is open for at least 72 hours and passes with three binding +1
> > votes from Roller PMC members.
> >
> > [ ] +1 release this as Apache Roller 6.1.6
> > [ ] 0 no opinion
> > [ ] -1 do not release, because ...
> >
> > Dave
>
>

Reply via email to