The proposed Apache Tomcat 8.5.45 release is now available for voting. The major changes compared to the 8.5.43 release are:
- Expand the HTTP/2 excessive overhead protection to cover various forms of abusive client behaviour and close the connection if any such behaviour is detected. - Security improvements to the Windows installer including a change in the default user from Local System to Local Service. - Improve handling of invalid requests so that 400 responses are returned to the client rather than 500 responses. Along with lots of other bug fixes and improvements. For full details, see the changelog: https://ci.apache.org/projects/tomcat/tomcat85/docs/changelog.html It can be obtained from: https://dist.apache.org/repos/dist/dev/tomcat/tomcat-8/v8.5.45/ The Maven staging repo is: https://repository.apache.org/content/repositories/orgapachetomcat-1228/ The tag is: https://github.com/apache/tomcat/tree/8.5.45 46d444a14cdac3e7e1f011a02cbdac9e5a80631c The proposed 8.5.45 release is: [ ] Broken - do not release [ ] Stable - go ahead and release as 8.5.45 --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org