Great job! +1
[ ] Leave at test build [ ] Alpha [ ] Beta [X] General Availability (GA) Johannes ################################################# web: http://www.jgeppert.com twitter: http://twitter.com/jogep > > Am 19.04.2013 10:46, schrieb Maurizio Cucchiara: > > The Struts 2.3.14.1 test build is now available. >> >> It includes the latest security patches which fix two possible >> vulnerabilities: >> * OGNL eval expressions has been disabled by default. >> >> For details and the rationale behind these changes, please consult the >> corresponding security bulletins: >> * >> https://cwiki.apache.org/**confluence/display/WW/S2-012<https://cwiki.apache.org/confluence/display/WW/S2-012> >> * >> https://cwiki.apache.org/**confluence/display/WW/S2-013<https://cwiki.apache.org/confluence/display/WW/S2-013> >> >> Please note that currently these bulletins and the release notes are >> only visible to logged-in users with the struts-committer role. This is >> a needed requirement to control disclosure until the actual release is >> announced. >> >> Release notes: >> * [https://cwiki.apache.org/**confluence/display/WW/Version+** >> Notes+2.3.14.1<https://cwiki.apache.org/confluence/display/WW/Version+Notes+2.3.14.1> >> ] >> >> Distribution: >> * >> [http://people.apache.org/**builds/struts/2.3.14.1/<http://people.apache.org/builds/struts/2.3.14.1/> >> ] >> >> Maven 2 staging repository: >> * >> [https://repository.apache.**org/content/groups/staging/<https://repository.apache.org/content/groups/staging/> >> ] >> >> Once you have had a chance to review the test build, please respond >> with a vote on its quality: >> >> [ ] Leave at test build >> [ ] Alpha >> [ ] Beta >> [ ] General Availability (GA) >> >> Everyone who has tested the build is invited to vote. Votes by PMC >> members are considered binding. A vote passes if there are at least >> three binding +1s and more +1s than -1s. >> >> This is a "fast-track" release vote. If we have a positive vote after >> 24 hours (at least three binding +1s and more +1s than -1s), the >> release may be submitted for mirroring and announced to the usual >> channels. >> >> The website download link will include the mirroring timestamp >> parameter [1], which limits the selection of mirrors to those that >> have been refreshed since the indicated time and date. (After 24 >> hours, we *must* remove the timestamp parameter from the website link, >> to avoid unnecessary server load.) In the case of a fast-track >> release, the email announcement will not link directly to >> <download.cgi>, but to <downloads.html>, so that we can control use of >> the timestamp parameter. >> >> [1] >> http://apache.org/dev/mirrors.**html#use<http://apache.org/dev/mirrors.html#use> >> >> >> >> Twitter >> :http://www.twitter.com/m_**cucchiara<http://www.twitter.com/m_cucchiara> >> G+ >> :https://plus.google.com/**107903711540963855921<https://plus.google.com/107903711540963855921> >> Linkedin >> :http://www.linkedin.com/in/**mauriziocucchiara<http://www.linkedin.com/in/mauriziocucchiara> >> VisualizeMe: http://vizualize.me/maurizio.** >> cucchiara?r=maurizio.cucchiara<http://vizualize.me/maurizio.cucchiara?r=maurizio.cucchiara> >> >> Maurizio Cucchiara >> >> ------------------------------**------------------------------**--------- >> To unsubscribe, e-mail: >> [email protected].**org<[email protected]> >> For additional commands, e-mail: [email protected] >> >> > ------------------------------**------------------------------**--------- > To unsubscribe, e-mail: > [email protected].**org<[email protected]> > For additional commands, e-mail: [email protected] > >
