[jira] [Commented] (TOMEE-2276) Update TomEE with Johnzon 1.0.2

2018-12-18 Thread Daniel Cunha (JIRA)


[ 
https://issues.apache.org/jira/browse/TOMEE-2276?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16724412#comment-16724412
 ] 

Daniel Cunha commented on TOMEE-2276:
-

I've sent a PR for the branch 7.0.x and 7.1.x :)

[https://github.com/apache/tomee/pull/292]

https://github.com/apache/tomee/pull/291

> Update TomEE with Johnzon 1.0.2
> ---
>
> Key: TOMEE-2276
> URL: https://issues.apache.org/jira/browse/TOMEE-2276
> Project: TomEE
>  Issue Type: Improvement
>Affects Versions: 7.0.6, 7.1.1
>Reporter: Bruno Baptista
>Priority: Minor
>  Labels: pull-request-available
>
> The maintainance branch for johnzon contains important changes, namely:
> **JOHNZON-193 ensure objectbuilder is reusable.
> See: [https://github.com/apache/johnzon/commits/maintenance_1.0.x]
> We should expect for a 1.0.2 release of Johnzon.



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)


[jira] [Commented] (TOMEE-2276) Update TomEE with Johnzon 1.0.2

2018-12-18 Thread ASF GitHub Bot (JIRA)


[ 
https://issues.apache.org/jira/browse/TOMEE-2276?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16724410#comment-16724410
 ] 

ASF GitHub Bot commented on TOMEE-2276:
---

GitHub user danielsoro opened a pull request:

https://github.com/apache/tomee/pull/292

TOMEE-2276 - Update TomEE with Johnzon 1.0.2



You can merge this pull request into a Git repository by running:

$ git pull https://github.com/danielsoro/tomee patch-1

Alternatively you can review and apply these changes as the patch at:

https://github.com/apache/tomee/pull/292.patch

To close this pull request, make a commit to your master/trunk branch
with (at least) the following in the commit message:

This closes #292


commit 14cf776d67168235e4c1d343d5875072c0b37a11
Author: Daniel Cunha 
Date:   2018-12-18T19:38:30Z

TOMEE-2276 - Update TomEE with Johnzon 1.0.2




> Update TomEE with Johnzon 1.0.2
> ---
>
> Key: TOMEE-2276
> URL: https://issues.apache.org/jira/browse/TOMEE-2276
> Project: TomEE
>  Issue Type: Improvement
>Affects Versions: 7.0.6, 7.1.1
>Reporter: Bruno Baptista
>Priority: Minor
>  Labels: pull-request-available
>
> The maintainance branch for johnzon contains important changes, namely:
> **JOHNZON-193 ensure objectbuilder is reusable.
> See: [https://github.com/apache/johnzon/commits/maintenance_1.0.x]
> We should expect for a 1.0.2 release of Johnzon.



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)


[jira] [Commented] (TOMEE-2276) Update TomEE with Johnzon 1.0.2

2018-12-18 Thread ASF GitHub Bot (JIRA)


[ 
https://issues.apache.org/jira/browse/TOMEE-2276?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16724408#comment-16724408
 ] 

ASF GitHub Bot commented on TOMEE-2276:
---

GitHub user danielsoro opened a pull request:

https://github.com/apache/tomee/pull/291

TOMEE-2276 - Update TomEE with Johnzon 1.0.2



You can merge this pull request into a Git repository by running:

$ git pull https://github.com/danielsoro/tomee johnzon-update-tomee-7.0.x

Alternatively you can review and apply these changes as the patch at:

https://github.com/apache/tomee/pull/291.patch

To close this pull request, make a commit to your master/trunk branch
with (at least) the following in the commit message:

This closes #291


commit d0e894ed9de53f892d0f30c5fb2b28aaaf5bfdff
Author: Daniel Cunha (soro) 
Date:   2018-12-18T19:34:29Z

Update Johnzon for 1.0.2




> Update TomEE with Johnzon 1.0.2
> ---
>
> Key: TOMEE-2276
> URL: https://issues.apache.org/jira/browse/TOMEE-2276
> Project: TomEE
>  Issue Type: Improvement
>Affects Versions: 7.0.6, 7.1.1
>Reporter: Bruno Baptista
>Priority: Minor
>  Labels: pull-request-available
>
> The maintainance branch for johnzon contains important changes, namely:
> **JOHNZON-193 ensure objectbuilder is reusable.
> See: [https://github.com/apache/johnzon/commits/maintenance_1.0.x]
> We should expect for a 1.0.2 release of Johnzon.



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)


[jira] [Updated] (TOMEE-2276) Update TomEE with Johnzon 1.0.2

2018-12-18 Thread ASF GitHub Bot (JIRA)


 [ 
https://issues.apache.org/jira/browse/TOMEE-2276?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

ASF GitHub Bot updated TOMEE-2276:
--
Labels: pull-request-available  (was: )

> Update TomEE with Johnzon 1.0.2
> ---
>
> Key: TOMEE-2276
> URL: https://issues.apache.org/jira/browse/TOMEE-2276
> Project: TomEE
>  Issue Type: Improvement
>Affects Versions: 7.0.6, 7.1.1
>Reporter: Bruno Baptista
>Priority: Minor
>  Labels: pull-request-available
>
> The maintainance branch for johnzon contains important changes, namely:
> **JOHNZON-193 ensure objectbuilder is reusable.
> See: [https://github.com/apache/johnzon/commits/maintenance_1.0.x]
> We should expect for a 1.0.2 release of Johnzon.



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)


[jira] [Updated] (TOMEE-2276) Update TomEE with Johnzon 1.0.2

2018-12-18 Thread Daniel Cunha (JIRA)


 [ 
https://issues.apache.org/jira/browse/TOMEE-2276?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Daniel Cunha updated TOMEE-2276:

Affects Version/s: 7.1.1

> Update TomEE with Johnzon 1.0.2
> ---
>
> Key: TOMEE-2276
> URL: https://issues.apache.org/jira/browse/TOMEE-2276
> Project: TomEE
>  Issue Type: Improvement
>Affects Versions: 7.0.6, 7.1.1
>Reporter: Bruno Baptista
>Priority: Minor
>
> The maintainance branch for johnzon contains important changes, namely:
> **JOHNZON-193 ensure objectbuilder is reusable.
> See: [https://github.com/apache/johnzon/commits/maintenance_1.0.x]
> We should expect for a 1.0.2 release of Johnzon.



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)


[jira] [Updated] (TOMEE-2276) Update TomEE with Johnzon 1.0.2

2018-12-18 Thread Daniel Cunha (JIRA)


 [ 
https://issues.apache.org/jira/browse/TOMEE-2276?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Daniel Cunha updated TOMEE-2276:

Summary: Update TomEE with Johnzon 1.0.2  (was: Update TomEE 7.0.6 with 
Johnzon 1.0.2)

> Update TomEE with Johnzon 1.0.2
> ---
>
> Key: TOMEE-2276
> URL: https://issues.apache.org/jira/browse/TOMEE-2276
> Project: TomEE
>  Issue Type: Improvement
>Affects Versions: 7.0.6, 7.1.1
>Reporter: Bruno Baptista
>Priority: Minor
>
> The maintainance branch for johnzon contains important changes, namely:
> **JOHNZON-193 ensure objectbuilder is reusable.
> See: [https://github.com/apache/johnzon/commits/maintenance_1.0.x]
> We should expect for a 1.0.2 release of Johnzon.



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)


[jira] [Commented] (TOMEE-2385) Add README.adoc to moviefun-rest/

2018-12-18 Thread ASF GitHub Bot (JIRA)


[ 
https://issues.apache.org/jira/browse/TOMEE-2385?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16724359#comment-16724359
 ] 

ASF GitHub Bot commented on TOMEE-2385:
---

GitHub user joedayz opened a pull request:

https://github.com/apache/tomee/pull/290

TOMEE-2385 Adding README.md for moviefun-rest example

I added documentation for only backend code. 

You can merge this pull request into a Git repository by running:

$ git pull https://github.com/joedayz/tomee master

Alternatively you can review and apply these changes as the patch at:

https://github.com/apache/tomee/pull/290.patch

To close this pull request, make a commit to your master/trunk branch
with (at least) the following in the commit message:

This closes #290


commit d9bb41ec7bcd7db243869be9384629abeb19d24d
Author: Jose Diaz 
Date:   2018-12-18T18:38:50Z

TOMEE-2385 Adding README.md




> Add README.adoc to moviefun-rest/
> -
>
> Key: TOMEE-2385
> URL: https://issues.apache.org/jira/browse/TOMEE-2385
> Project: TomEE
>  Issue Type: Sub-task
>Reporter: David Blevins
>Assignee: Jose Diaz
>Priority: Major
>  Labels: pull-request-available
>




--
This message was sent by Atlassian JIRA
(v7.6.3#76005)


[jira] [Updated] (TOMEE-2385) Add README.adoc to moviefun-rest/

2018-12-18 Thread ASF GitHub Bot (JIRA)


 [ 
https://issues.apache.org/jira/browse/TOMEE-2385?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

ASF GitHub Bot updated TOMEE-2385:
--
Labels: pull-request-available  (was: )

> Add README.adoc to moviefun-rest/
> -
>
> Key: TOMEE-2385
> URL: https://issues.apache.org/jira/browse/TOMEE-2385
> Project: TomEE
>  Issue Type: Sub-task
>Reporter: David Blevins
>Assignee: Jose Diaz
>Priority: Major
>  Labels: pull-request-available
>




--
This message was sent by Atlassian JIRA
(v7.6.3#76005)


[jira] [Work started] (TOMEE-2385) Add README.adoc to moviefun-rest/

2018-12-18 Thread Jose Diaz (JIRA)


 [ 
https://issues.apache.org/jira/browse/TOMEE-2385?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Work on TOMEE-2385 started by Jose Diaz.

> Add README.adoc to moviefun-rest/
> -
>
> Key: TOMEE-2385
> URL: https://issues.apache.org/jira/browse/TOMEE-2385
> Project: TomEE
>  Issue Type: Sub-task
>Reporter: David Blevins
>Assignee: Jose Diaz
>Priority: Major
>




--
This message was sent by Atlassian JIRA
(v7.6.3#76005)


tomee git commit: TOMEE-2275 Update OWB to 1.7.6

2018-12-18 Thread jlmonteiro
Repository: tomee
Updated Branches:
  refs/heads/tomee-7.0.x 8f8394f4e -> 20697d444


TOMEE-2275 Update OWB to 1.7.6


Project: http://git-wip-us.apache.org/repos/asf/tomee/repo
Commit: http://git-wip-us.apache.org/repos/asf/tomee/commit/20697d44
Tree: http://git-wip-us.apache.org/repos/asf/tomee/tree/20697d44
Diff: http://git-wip-us.apache.org/repos/asf/tomee/diff/20697d44

Branch: refs/heads/tomee-7.0.x
Commit: 20697d4442773511f6dfbcd5fe8155b322f9a8e1
Parents: 8f8394f
Author: Jean-Louis Monteiro 
Authored: Tue Dec 18 17:35:17 2018 +0100
Committer: Jean-Louis Monteiro 
Committed: Tue Dec 18 17:35:17 2018 +0100

--
 pom.xml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
--


http://git-wip-us.apache.org/repos/asf/tomee/blob/20697d44/pom.xml
--
diff --git a/pom.xml b/pom.xml
index b0407b4..f03b935 100644
--- a/pom.xml
+++ b/pom.xml
@@ -101,7 +101,7 @@
 7.0-1
 
 2.4.3
-1.7.5
+1.7.6
 2.1
 1.0.1
 



[jira] [Updated] (TOMEE-2275) Update OWB version after resolution of OWB-1270

2018-12-18 Thread Jean-Louis MONTEIRO (JIRA)


 [ 
https://issues.apache.org/jira/browse/TOMEE-2275?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Jean-Louis MONTEIRO updated TOMEE-2275:
---
Issue Type: Dependency upgrade  (was: Improvement)

> Update OWB version after resolution of OWB-1270
> ---
>
> Key: TOMEE-2275
> URL: https://issues.apache.org/jira/browse/TOMEE-2275
> Project: TomEE
>  Issue Type: Dependency upgrade
>  Components: TomEE Core Server
>Affects Versions: 7.0.5
>Reporter: Bruno Baptista
>Assignee: Jean-Louis MONTEIRO
>Priority: Major
>  Labels: jdk11
> Fix For: 7.0.6, 7.1.1
>
>
> https://issues.apache.org/jira/browse/OWB-1270 backports "extracting unsafe 
> proxy code in an Unsafe class" that is important for JDK11 support.
> We should expect for an OWB version 1.7.6



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)


tomee git commit: TOMEE-2275 Update OWB to 1.7.6

2018-12-18 Thread jlmonteiro
Repository: tomee
Updated Branches:
  refs/heads/tomee-7.1.x 192bf4dc3 -> 096084e59


TOMEE-2275 Update OWB to 1.7.6


Project: http://git-wip-us.apache.org/repos/asf/tomee/repo
Commit: http://git-wip-us.apache.org/repos/asf/tomee/commit/096084e5
Tree: http://git-wip-us.apache.org/repos/asf/tomee/tree/096084e5
Diff: http://git-wip-us.apache.org/repos/asf/tomee/diff/096084e5

Branch: refs/heads/tomee-7.1.x
Commit: 096084e5981dfa122d032eb95d46e1381b343891
Parents: 192bf4d
Author: Jean-Louis Monteiro 
Authored: Tue Dec 18 17:34:20 2018 +0100
Committer: Jean-Louis Monteiro 
Committed: Tue Dec 18 17:34:20 2018 +0100

--
 pom.xml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
--


http://git-wip-us.apache.org/repos/asf/tomee/blob/096084e5/pom.xml
--
diff --git a/pom.xml b/pom.xml
index f5e789d..0b674ce 100644
--- a/pom.xml
+++ b/pom.xml
@@ -101,7 +101,7 @@
 7.0-1
 
 2.4.3
-1.7.5
+1.7.6
 2.1
 1.0
 1.0.1



[jira] [Assigned] (TOMEE-2275) Update OWB version after resolution of OWB-1270

2018-12-18 Thread Jean-Louis MONTEIRO (JIRA)


 [ 
https://issues.apache.org/jira/browse/TOMEE-2275?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Jean-Louis MONTEIRO reassigned TOMEE-2275:
--

Assignee: Jean-Louis MONTEIRO

> Update OWB version after resolution of OWB-1270
> ---
>
> Key: TOMEE-2275
> URL: https://issues.apache.org/jira/browse/TOMEE-2275
> Project: TomEE
>  Issue Type: Improvement
>  Components: TomEE Core Server
>Affects Versions: 7.0.5
>Reporter: Bruno Baptista
>Assignee: Jean-Louis MONTEIRO
>Priority: Major
>  Labels: jdk11
> Fix For: 7.0.6, 7.1.1
>
>
> https://issues.apache.org/jira/browse/OWB-1270 backports "extracting unsafe 
> proxy code in an Unsafe class" that is important for JDK11 support.
> We should expect for an OWB version 1.7.6



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)


[jira] [Updated] (TOMEE-2275) Update OWB version after resolution of OWB-1270

2018-12-18 Thread Jean-Louis MONTEIRO (JIRA)


 [ 
https://issues.apache.org/jira/browse/TOMEE-2275?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Jean-Louis MONTEIRO updated TOMEE-2275:
---
Fix Version/s: 7.1.1

> Update OWB version after resolution of OWB-1270
> ---
>
> Key: TOMEE-2275
> URL: https://issues.apache.org/jira/browse/TOMEE-2275
> Project: TomEE
>  Issue Type: Improvement
>  Components: TomEE Core Server
>Affects Versions: 7.0.5
>Reporter: Bruno Baptista
>Assignee: Jean-Louis MONTEIRO
>Priority: Major
>  Labels: jdk11
> Fix For: 7.0.6, 7.1.1
>
>
> https://issues.apache.org/jira/browse/OWB-1270 backports "extracting unsafe 
> proxy code in an Unsafe class" that is important for JDK11 support.
> We should expect for an OWB version 1.7.6



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)


[jira] [Commented] (TOMEE-2345) Add `` to all annotations outside codeblocks

2018-12-18 Thread ASF GitHub Bot (JIRA)


[ 
https://issues.apache.org/jira/browse/TOMEE-2345?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16724216#comment-16724216
 ] 

ASF GitHub Bot commented on TOMEE-2345:
---

Github user asfgit closed the pull request at:

https://github.com/apache/tomee/pull/282


> Add `` to all annotations outside codeblocks
> 
>
> Key: TOMEE-2345
> URL: https://issues.apache.org/jira/browse/TOMEE-2345
> Project: TomEE
>  Issue Type: Sub-task
>  Components: Website
>Reporter: David Blevins
>Assignee: Carlos Chacin
>Priority: Major
>  Labels: pull-request-available
>
> We have hacked some code to make improvements on the docs site wide:
>  
> [https://github.com/apache/tomee-site-generator/blob/master/src/main/java/org/apache/tomee/website/AsciidocAdjustHeadingLevels.java]
> [https://github.com/apache/tomee-site-generator/blob/master/src/main/java/org/apache/tomee/website/GuessAsciidocCodeblockLanguage.java]
>  
> It would be awesome to have one that can put `` around mentions of 
> annotations outside of codeblocks.



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)


[3/4] tomee git commit: This closes #282. Thanks cchacin.

2018-12-18 Thread jlmonteiro
This closes #282. Thanks cchacin.


Project: http://git-wip-us.apache.org/repos/asf/tomee/repo
Commit: http://git-wip-us.apache.org/repos/asf/tomee/commit/890898ef
Tree: http://git-wip-us.apache.org/repos/asf/tomee/tree/890898ef
Diff: http://git-wip-us.apache.org/repos/asf/tomee/diff/890898ef

Branch: refs/heads/master
Commit: 890898ef30c622cca3014ff83886cdcccfb20241
Parents: 1820408 62db64b
Author: Jean-Louis Monteiro 
Authored: Tue Dec 18 16:37:10 2018 +0100
Committer: Jean-Louis Monteiro 
Committed: Tue Dec 18 16:37:10 2018 +0100

--
 docs/app-clients-and-jndi.adoc  |  4 +-
 docs/application-composer/getting-started.adoc  |  2 +-
 ...application-discovery-via-the-classpath.adoc |  2 +-
 docs/application-resources.adoc |  4 +-
 docs/basics---getting-things.adoc   |  2 +-
 docs/basics---transactions.adoc |  2 +-
 docs/configuring-datasources.adoc   |  4 +-
 docs/constructor-injection.adoc |  2 +-
 docs/datasource-config.adoc |  2 +-
 docs/developer/json/index.adoc  |  4 +-
 .../testing/applicationcomposer/index.adoc  | 26 ++--
 docs/developer/testing/arquillian/index.adoc|  2 +-
 docs/documentation.adoc |  2 +-
 docs/documentation.old.adoc |  2 +-
 docs/ejb-local-ref.adoc |  2 +-
 docs/ejb-ref.adoc   |  2 +-
 docs/ejb-refs.adoc  |  4 +-
 docs/embedded-and-remotable.adoc| 10 ++---
 docs/generating-ejb-3-annotations.adoc  |  4 +-
 docs/hello-world.adoc   |  2 +-
 docs/jndi-names.adoc|  4 +-
 docs/jpa-concepts.adoc  |  4 +-
 docs/local-client-injection.adoc| 20 -
 docs/lookup-of-other-ejbs-example.adoc  |  8 ++--
 docs/new-in-openejb-3.0.adoc|  6 +--
 docs/persistence-context.adoc   |  2 +-
 docs/persistence-unit-ref.adoc  |  6 +--
 docs/resource-injection.adoc|  6 +--
 docs/resource-ref-for-datasource.adoc   |  2 +-
 docs/security-annotations.adoc  |  8 ++--
 docs/singleton-beans.adoc   | 44 ++--
 docs/spring-and-openejb-3.0.adoc|  4 +-
 docs/spring-ejb-and-jpa.adoc| 10 ++---
 docs/tomcat-object-factory.adoc |  2 +-
 docs/tomee-and-security.adoc|  2 +-
 docs/transaction-annotations.adoc   |  6 +--
 36 files changed, 109 insertions(+), 109 deletions(-)
--




[4/4] tomee git commit: Merge branch 'master' of https://git-wip-us.apache.org/repos/asf/tomee

2018-12-18 Thread jlmonteiro
Merge branch 'master' of https://git-wip-us.apache.org/repos/asf/tomee


Project: http://git-wip-us.apache.org/repos/asf/tomee/repo
Commit: http://git-wip-us.apache.org/repos/asf/tomee/commit/ce2998f7
Tree: http://git-wip-us.apache.org/repos/asf/tomee/tree/ce2998f7
Diff: http://git-wip-us.apache.org/repos/asf/tomee/diff/ce2998f7

Branch: refs/heads/master
Commit: ce2998f7839c6c9b4b7bd46a460b5674bdd02e61
Parents: 890898e 9f8a299
Author: Jean-Louis Monteiro 
Authored: Tue Dec 18 17:27:34 2018 +0100
Committer: Jean-Louis Monteiro 
Committed: Tue Dec 18 17:27:34 2018 +0100

--
 examples/pom.xml | 3 ---
 1 file changed, 3 deletions(-)
--




[1/4] tomee git commit: TOMEE-2345 Add to all annotations outside codeblocks

2018-12-18 Thread jlmonteiro
Repository: tomee
Updated Branches:
  refs/heads/master 9f8a299bd -> ce2998f78


TOMEE-2345 Add  to all annotations outside codeblocks


Project: http://git-wip-us.apache.org/repos/asf/tomee/repo
Commit: http://git-wip-us.apache.org/repos/asf/tomee/commit/62db64ba
Tree: http://git-wip-us.apache.org/repos/asf/tomee/tree/62db64ba
Diff: http://git-wip-us.apache.org/repos/asf/tomee/diff/62db64ba

Branch: refs/heads/master
Commit: 62db64ba35c8cd51c3a96f5ec00c66c1f7e839dd
Parents: 64ed418
Author: Carlos Chacin 
Authored: Sun Dec 16 15:08:12 2018 -0800
Committer: Carlos Chacin 
Committed: Sun Dec 16 15:08:12 2018 -0800

--
 docs/app-clients-and-jndi.adoc  |  4 +-
 docs/application-composer/getting-started.adoc  |  2 +-
 ...application-discovery-via-the-classpath.adoc |  2 +-
 docs/application-resources.adoc |  4 +-
 docs/basics---getting-things.adoc   |  2 +-
 docs/basics---transactions.adoc |  2 +-
 docs/configuring-datasources.adoc   |  4 +-
 docs/constructor-injection.adoc |  2 +-
 docs/datasource-config.adoc |  2 +-
 docs/developer/json/index.adoc  |  4 +-
 .../testing/applicationcomposer/index.adoc  | 26 ++--
 docs/developer/testing/arquillian/index.adoc|  2 +-
 docs/documentation.adoc |  2 +-
 docs/documentation.old.adoc |  2 +-
 docs/ejb-local-ref.adoc |  2 +-
 docs/ejb-ref.adoc   |  2 +-
 docs/ejb-refs.adoc  |  4 +-
 docs/embedded-and-remotable.adoc| 10 ++---
 docs/generating-ejb-3-annotations.adoc  |  4 +-
 docs/hello-world.adoc   |  2 +-
 docs/jndi-names.adoc|  4 +-
 docs/jpa-concepts.adoc  |  4 +-
 docs/local-client-injection.adoc| 20 -
 docs/lookup-of-other-ejbs-example.adoc  |  8 ++--
 docs/new-in-openejb-3.0.adoc|  6 +--
 docs/persistence-context.adoc   |  2 +-
 docs/persistence-unit-ref.adoc  |  6 +--
 docs/resource-injection.adoc|  6 +--
 docs/resource-ref-for-datasource.adoc   |  2 +-
 docs/security-annotations.adoc  |  8 ++--
 docs/singleton-beans.adoc   | 44 ++--
 docs/spring-and-openejb-3.0.adoc|  4 +-
 docs/spring-ejb-and-jpa.adoc| 10 ++---
 docs/tomcat-object-factory.adoc |  2 +-
 docs/tomee-and-security.adoc|  2 +-
 docs/transaction-annotations.adoc   |  6 +--
 36 files changed, 109 insertions(+), 109 deletions(-)
--


http://git-wip-us.apache.org/repos/asf/tomee/blob/62db64ba/docs/app-clients-and-jndi.adoc
--
diff --git a/docs/app-clients-and-jndi.adoc b/docs/app-clients-and-jndi.adoc
index d8548fd..d9d61a9 100644
--- a/docs/app-clients-and-jndi.adoc
+++ b/docs/app-clients-and-jndi.adoc
@@ -18,8 +18,8 @@ Internally, we bind each EJB proxy under essentially a 
hardcoded and
 predictable format and then again using the user supplied format.  So
 there are at minimum two JNDI trees with every EJB proxy.  It used to be
 two at least.  Now we have quite a few because of Java EE 6 global JNDI
-and the support we added for @LocalClient and allowing the same
-interface to be used as both @Local and @Remote.
+and the support we added for `@LocalClient` and allowing the same
+interface to be used as both `@Local` and `@Remote`.
 
 Basically we have:
 

http://git-wip-us.apache.org/repos/asf/tomee/blob/62db64ba/docs/application-composer/getting-started.adoc
--
diff --git a/docs/application-composer/getting-started.adoc 
b/docs/application-composer/getting-started.adoc
index 2a7e3da..337a6c6 100644
--- a/docs/application-composer/getting-started.adoc
+++ b/docs/application-composer/getting-started.adoc
@@ -161,7 +161,7 @@ the ApplicationComposer:
 @RunWith(ApplicationComposer.class) public class MyTest \{ // ... }
 * using `ApplicationComposerRule` rule:
 +
-public class MyTest \{ @Rule // or @ClassRule if you want the
+public class MyTest \{ `@Rule` // or `@ClassRule` if you want the
 container/application lifecycle be bound to the class and not test
 methods public final ApplicationComposerRule rule = new
 ApplicationComposerRule(this); }

http://git-wip-us.apache.org/repos/asf/tomee/blob/62db64ba/docs/application-discovery-via-the-classpath.adoc
--
diff --git a/docs/application-discovery-via-the-classpath.adoc 

[2/4] tomee git commit: Add debug information

2018-12-18 Thread jlmonteiro
Add debug information


Project: http://git-wip-us.apache.org/repos/asf/tomee/repo
Commit: http://git-wip-us.apache.org/repos/asf/tomee/commit/18204086
Tree: http://git-wip-us.apache.org/repos/asf/tomee/tree/18204086
Diff: http://git-wip-us.apache.org/repos/asf/tomee/diff/18204086

Branch: refs/heads/master
Commit: 18204086c730d5504beccd76e501f4917ffa1a80
Parents: 9155773
Author: Jean-Louis Monteiro 
Authored: Tue Dec 18 16:18:03 2018 +0100
Committer: Jean-Louis Monteiro 
Committed: Tue Dec 18 16:18:03 2018 +0100

--
 .../resource/AutoConnectionTrackerTest.java | 43 
 1 file changed, 36 insertions(+), 7 deletions(-)
--


http://git-wip-us.apache.org/repos/asf/tomee/blob/18204086/container/openejb-core/src/test/java/org/apache/openejb/resource/AutoConnectionTrackerTest.java
--
diff --git 
a/container/openejb-core/src/test/java/org/apache/openejb/resource/AutoConnectionTrackerTest.java
 
b/container/openejb-core/src/test/java/org/apache/openejb/resource/AutoConnectionTrackerTest.java
index 6fb9859..e8f9598 100644
--- 
a/container/openejb-core/src/test/java/org/apache/openejb/resource/AutoConnectionTrackerTest.java
+++ 
b/container/openejb-core/src/test/java/org/apache/openejb/resource/AutoConnectionTrackerTest.java
@@ -17,6 +17,7 @@
  */
 package org.apache.openejb.resource;
 
+import junit.framework.AssertionFailedError;
 import junit.framework.TestCase;
 import org.apache.geronimo.connector.outbound.AbstractConnectionManager;
 import org.apache.geronimo.connector.outbound.ConnectionTrackingInterceptor;
@@ -167,8 +168,8 @@ public class AutoConnectionTrackerTest extends TestCase {
 
 System.gc();
 cf.getConnection().close();
-assertEquals(0, logCapture.find("Transaction complete, but 
connection still has handles associated").size());
-assertEquals(0, logCapture.find("Detected abandoned 
connection").size());
+assertLogs(logCapture, 0, "Transaction complete, but connection 
still has handles associated");
+assertLogs(logCapture, 0, "Detected abandoned connection");
 assertTrue(getConnectionCount((FakeConnectionFactoryImpl) cf) > 0);
 }
 {
@@ -186,8 +187,8 @@ public class AutoConnectionTrackerTest extends TestCase {
 
 System.gc();
 cf.getConnection().close();
-assertEquals(0, logCapture.find("Transaction complete, but 
connection still has handles associated").size());
-assertEquals(0, logCapture.find("Detected abandoned 
connection").size());
+assertLogs(logCapture, 0, "Transaction complete, but connection 
still has handles associated");
+assertLogs(logCapture, 0, "Detected abandoned connection");
 assertTrue(getConnectionCount((FakeConnectionFactoryImpl) cf) > 0);
 }
 {
@@ -197,8 +198,8 @@ public class AutoConnectionTrackerTest extends TestCase {
 
 final AutoConnectionTracker tracker = 
getAutoConnectionTracker((FakeConnectionFactoryImpl) cf);
 tracker.setEnvironment(null, null);
-assertEquals(1, logCapture.find("Transaction complete, but 
connection still has handles associated").size());
-assertEquals(1, logCapture.find("Detected abandoned 
connection").size());
+assertLogs(logCapture, 1, "Transaction complete, but connection 
still has handles associated");
+assertLogs(logCapture, 1, "Detected abandoned connection");
 }
 {
 logCapture.clear();
@@ -207,10 +208,38 @@ public class AutoConnectionTrackerTest extends TestCase {
 
 final AutoConnectionTracker tracker = 
getAutoConnectionTracker((FakeConnectionFactoryImpl) cf);
 tracker.setEnvironment(null, null);
-assertEquals(1, logCapture.find("Detected abandoned 
connection").size());
+assertLogs(logCapture, 1, "Detected abandoned connection");
 }
 }
 
+// this is a very quick and dirty hack for debugging purpose
+private void assertLogs(final LogCaptureHandler logCapture, final int 
times, final String message) {
+final int iteration = 5;
+final int waitSeconds = 2;
+
+AssertionFailedError failure = null;
+
+for (int i = 0 ; i < iteration ; i++) {
+try {
+assertEquals(message, times, logCapture.find(message).size());
+return;
+
+} catch (final AssertionFailedError e) {
+if (failure == null) { // keep the first issue
+failure = e;
+}
+
+try {
+Thread.sleep(waitSeconds * 1000);
+} catch (final InterruptedException e1) {
+// no-op
+}
+}

[jira] [Commented] (TOMEE-2368) example-mvc-resteasy

2018-12-18 Thread ASF GitHub Bot (JIRA)


[ 
https://issues.apache.org/jira/browse/TOMEE-2368?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16724158#comment-16724158
 ] 

ASF GitHub Bot commented on TOMEE-2368:
---

Github user jeanouii commented on the issue:

https://github.com/apache/tomee/pull/278
  
@radcortez can you merge this one?


> example-mvc-resteasy
> 
>
> Key: TOMEE-2368
> URL: https://issues.apache.org/jira/browse/TOMEE-2368
> Project: TomEE
>  Issue Type: Documentation
>  Components: Examples and Documentation
>Reporter: Daniel Dias dos Santos
>Priority: Minor
>  Labels: pull-request-available
> Fix For: 8.0.0-M2
>
> Attachments: mvc-resteasy.png
>
>
> I made a simple hello world example with MVC 1.0 using RestEasy.



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)


[jira] [Commented] (TOMEE-2363) Introduce OWASP dependency checking in the Maven build process

2018-12-18 Thread ASF GitHub Bot (JIRA)


[ 
https://issues.apache.org/jira/browse/TOMEE-2363?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16724156#comment-16724156
 ] 

ASF GitHub Bot commented on TOMEE-2363:
---

Github user jeanouii commented on the issue:

https://github.com/apache/tomee/pull/276
  
Sounds perfect @rzo1 .
@radcortez I am ready to merge. Did you get a chance to also review and 
test?



> Introduce OWASP dependency checking in the Maven build process
> --
>
> Key: TOMEE-2363
> URL: https://issues.apache.org/jira/browse/TOMEE-2363
> Project: TomEE
>  Issue Type: Improvement
>  Components: TomEE Build
>Affects Versions: 7.0.5, 7.1.0, 8.0.0-M1
>Reporter: Richard Zowalla
>Priority: Minor
>  Labels: pull-request-available
> Fix For: 7.0.6, 7.1.1, 8.0.0-M2
>
>
> As discussed on the mailing list
>  
> {quote}Hey, 
>  
> any objectives against automatic checking of known, publicly disclosed 
> dependency vulnerabilities in the Maven build process (e.g. via a profile). 
>  
> I was thinking about introducing OWASP dependency checking (see 
> [https://www.owasp.org/index.php/OWASP_Dependency_Check]) in the TomEE 
> project, so we are aware of security risks introduced by (transient) 
> dependencies. 
>  
> Any thoughs on this? 
>  
> Best, 
>  
> Richard 
> {quote}



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)


[jira] [Commented] (TOMEE-2368) example-mvc-resteasy

2018-12-18 Thread Daniel Dias dos Santos (JIRA)


[ 
https://issues.apache.org/jira/browse/TOMEE-2368?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16724097#comment-16724097
 ] 

Daniel Dias dos Santos commented on TOMEE-2368:
---

cool.


I can do the equals to mvc-cxf .

I see how the he if comport.

thanks. :  )

> example-mvc-resteasy
> 
>
> Key: TOMEE-2368
> URL: https://issues.apache.org/jira/browse/TOMEE-2368
> Project: TomEE
>  Issue Type: Documentation
>  Components: Examples and Documentation
>Reporter: Daniel Dias dos Santos
>Priority: Minor
>  Labels: pull-request-available
> Fix For: 8.0.0-M2
>
> Attachments: mvc-resteasy.png
>
>
> I made a simple hello world example with MVC 1.0 using RestEasy.



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)


[jira] [Commented] (TOMEE-2368) example-mvc-resteasy

2018-12-18 Thread Jonathan Gallimore (JIRA)


[ 
https://issues.apache.org/jira/browse/TOMEE-2368?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16724088#comment-16724088
 ] 

Jonathan Gallimore commented on TOMEE-2368:
---

Ah ok. I do see the same thing. We could get this merged in. One thought I
had, was this could ultimately be the same as the CXF-based example, just
with the different dependencies and config. What do you think?

Jon

On Tue, Dec 18, 2018 at 1:00 PM Daniel Dias dos Santos (JIRA) <



> example-mvc-resteasy
> 
>
> Key: TOMEE-2368
> URL: https://issues.apache.org/jira/browse/TOMEE-2368
> Project: TomEE
>  Issue Type: Documentation
>  Components: Examples and Documentation
>Reporter: Daniel Dias dos Santos
>Priority: Minor
>  Labels: pull-request-available
> Fix For: 8.0.0-M2
>
> Attachments: mvc-resteasy.png
>
>
> I made a simple hello world example with MVC 1.0 using RestEasy.



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)


[jira] [Updated] (TOMEE-2368) example-mvc-resteasy

2018-12-18 Thread Daniel Dias dos Santos (JIRA)


 [ 
https://issues.apache.org/jira/browse/TOMEE-2368?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Daniel Dias dos Santos updated TOMEE-2368:
--
Attachment: mvc-resteasy.png

> example-mvc-resteasy
> 
>
> Key: TOMEE-2368
> URL: https://issues.apache.org/jira/browse/TOMEE-2368
> Project: TomEE
>  Issue Type: Documentation
>  Components: Examples and Documentation
>Reporter: Daniel Dias dos Santos
>Priority: Minor
>  Labels: pull-request-available
> Fix For: 8.0.0-M2
>
> Attachments: mvc-resteasy.png
>
>
> I made a simple hello world example with MVC 1.0 using RestEasy.



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)


[jira] [Commented] (TOMEE-2368) example-mvc-resteasy

2018-12-18 Thread Daniel Dias dos Santos (JIRA)


[ 
https://issues.apache.org/jira/browse/TOMEE-2368?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16724037#comment-16724037
 ] 

Daniel Dias dos Santos commented on TOMEE-2368:
---

Hello Jon,

for me the same thing appears, but I think this is not an execeçao, another 
warning of log servero.

in any case, the application stands if you access: 

 

http: // localhost: 8080 / mvc-resteasy

 

!mvc-resteasy.png!

> example-mvc-resteasy
> 
>
> Key: TOMEE-2368
> URL: https://issues.apache.org/jira/browse/TOMEE-2368
> Project: TomEE
>  Issue Type: Documentation
>  Components: Examples and Documentation
>Reporter: Daniel Dias dos Santos
>Priority: Minor
>  Labels: pull-request-available
> Fix For: 8.0.0-M2
>
> Attachments: mvc-resteasy.png
>
>
> I made a simple hello world example with MVC 1.0 using RestEasy.



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)


[jira] [Updated] (TOMEE-2242) Upgrade commons-lang3 dependency from old 3.5 to current 3.8 version

2018-12-18 Thread Martin Wiesner (JIRA)


 [ 
https://issues.apache.org/jira/browse/TOMEE-2242?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Martin Wiesner updated TOMEE-2242:
--
Summary: Upgrade commons-lang3 dependency from old 3.5 to current 3.8 
version  (was: Upgrade commons-lang3 dependency from old 3.5 to current 3.8 
version?)

> Upgrade commons-lang3 dependency from old 3.5 to current 3.8 version
> 
>
> Key: TOMEE-2242
> URL: https://issues.apache.org/jira/browse/TOMEE-2242
> Project: TomEE
>  Issue Type: Dependency upgrade
>Affects Versions: 7.0.5
>Reporter: Jonathan Gallimore
>Assignee: Jonathan Gallimore
>Priority: Major
> Fix For: 8.0.0-M1, 7.0.6, 7.1.1
>
>
> Struts 2.5.17 depends on new classes introduced in  commons-lang3-3.6 (class
> org.apache.commons.lang3.reflect.MethodUtils does not have a method 
> getAnnotation method which is expected by struts 2.5.17).
>  
> 1) Would it be possible to upgrade Apache TomEE+ 7.0.6 and higher (7.1/ 8.x 
> branches) dependency on commons-lang3 from 3.5 to latest (3.8) ?



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)


[jira] [Resolved] (TOMEE-2241) Need to upgrade commons-lang3-3.5.jar to commons-lang3-3.8.jar to allows Struts users to fix CVE-2018-11776 in their app

2018-12-18 Thread Martin Wiesner (JIRA)


 [ 
https://issues.apache.org/jira/browse/TOMEE-2241?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Martin Wiesner resolved TOMEE-2241.
---
Resolution: Duplicate

Resolved as duplicate of TOMEE-2242.

> Need to upgrade commons-lang3-3.5.jar to commons-lang3-3.8.jar to allows 
> Struts users to fix CVE-2018-11776 in their app
> 
>
> Key: TOMEE-2241
> URL: https://issues.apache.org/jira/browse/TOMEE-2241
> Project: TomEE
>  Issue Type: Dependency upgrade
>  Components: TomEE Core Server
>Affects Versions: 7.0.5
>Reporter: Alexandre Vermeerbergen
>Priority: Major
>  Labels: commons-lang,
> Fix For: 7.0.6
>
>   Original Estimate: 1h
>  Remaining Estimate: 1h
>
> We are running our web apps with TomEE+ 7.0.5 and we are trying to
>  upgrade our Apache struts based app to latest version (Struts 2.5.17) 
> because of CVE-2018-11776.
> Fixing this CVE-2018-11776 security issue involves upgrading web apps Struts 
> dependency to Struts 2.5.17 (see 
> [https://struts.apache.org/announce.html#a20180822-0)].
>  
>  However it turns out that Struts 2.5.17 depends on new classes
>  introduced in  commons-lang3-3.6 (class
>  org.apache.commons.lang3.reflect.MethodUtils does not have a method
>  getAnnotation method which is expected by struts 2.5.17), and Apache TomEE 
> 7.0.5 comes with commons-lang3-3.5.jar
> commons-lang3-3.5.jar is very old, we should upgrade TomEE core's dependency 
> to latest commons-lang3. Currently this is commons-lang3-3.8.jar



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)


[jira] [Commented] (TOMEE-2368) example-mvc-resteasy

2018-12-18 Thread Jonathan Gallimore (JIRA)


[ 
https://issues.apache.org/jira/browse/TOMEE-2368?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16723961#comment-16723961
 ] 

Jonathan Gallimore commented on TOMEE-2368:
---

[http://tomee-openejb.979440.n4.nabble.com/Re-jira-Commented-TOMEE-2368-example-mvc-resteasy-td4686657.html]

 

I'm getting an exception when running via mvn tomee:run:

 

EASY002155: Provider class 
org.jboss.resteasy.plugins.providers.sse.SseEventProvider is already 
registered.  2nd registration is being ignored.

18-Dec-2018 11:01:21.798 SEVERE [main] 
org.apache.openejb.observer.ObserverManager$MethodInvocation.invoke error 
invoking org.apache.tomee.webservices.TomeeJaxRsService@5d740a0f

 java.lang.IllegalArgumentException: class 
org.jboss.resteasy.plugins.providers.FormUrlEncodedProvider is not a SERVER 
provider

 at 
org.apache.openejb.server.cxf.rs.CxfRsHttpListener.isNotServerProvider(CxfRsHttpListener.java:491)

 at 
org.apache.openejb.server.cxf.rs.CxfRsHttpListener.providers(CxfRsHttpListener.java:434)

 at 
org.apache.openejb.server.cxf.rs.CxfRsHttpListener.configureFactory(CxfRsHttpListener.java:1012)

 at 
org.apache.openejb.server.cxf.rs.CxfRsHttpListener.deployApplication(CxfRsHttpListener.java:579)

 at 
org.apache.openejb.server.rest.RESTService.deployApplication(RESTService.java:485)

 at 
org.apache.openejb.server.rest.RESTService.afterApplicationCreated(RESTService.java:250)

 at 
org.apache.tomee.webservices.TomeeJaxRsService.afterApplicationCreated(TomeeJaxRsService.java:53)

 at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)

 at 
sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)

 at 
sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)

 at java.lang.reflect.Method.invoke(Method.java:498)

 at 
org.apache.openejb.observer.ObserverManager$MethodInvocation.invoke(ObserverManager.java:406)

 at org.apache.openejb.observer.ObserverManager.doFire(ObserverManager.java:111)

 at 
org.apache.openejb.observer.ObserverManager.fireEvent(ObserverManager.java:100)

 at org.apache.openejb.loader.SystemInstance.fireEvent(SystemInstance.java:134)

 at 
org.apache.tomee.catalina.TomcatWebAppBuilder.afterStart(TomcatWebAppBuilder.java:1784)

 at 
org.apache.tomee.catalina.GlobalListenerSupport.lifecycleEvent(GlobalListenerSupport.java:117)

 at 
org.apache.catalina.util.LifecycleBase.fireLifecycleEvent(LifecycleBase.java:123)

 at 
org.apache.catalina.util.LifecycleBase.setStateInternal(LifecycleBase.java:424)

 at org.apache.catalina.util.LifecycleBase.start(LifecycleBase.java:193)

 at 
org.apache.catalina.core.ContainerBase.addChildInternal(ContainerBase.java:743)

 at org.apache.catalina.core.ContainerBase.addChild(ContainerBase.java:719)

 at org.apache.catalina.core.StandardHost.addChild(StandardHost.java:703)

 at org.apache.catalina.startup.HostConfig.deployWAR(HostConfig.java:986)

 at org.apache.catalina.startup.HostConfig$DeployWar.run(HostConfig.java:1858)

 at java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:511)

 at java.util.concurrent.FutureTask.run(FutureTask.java:266)

 at 
org.apache.tomcat.util.threads.InlineExecutorService.execute(InlineExecutorService.java:75)

 at 
java.util.concurrent.AbstractExecutorService.submit(AbstractExecutorService.java:112)

 at org.apache.catalina.startup.HostConfig.deployWARs(HostConfig.java:772)

 at org.apache.catalina.startup.HostConfig.deployApps(HostConfig.java:426)

 at org.apache.catalina.startup.HostConfig.start(HostConfig.java:1585)

 at org.apache.catalina.startup.HostConfig.lifecycleEvent(HostConfig.java:308)

 at 
org.apache.catalina.util.LifecycleBase.fireLifecycleEvent(LifecycleBase.java:123)

 at 
org.apache.catalina.util.LifecycleBase.setStateInternal(LifecycleBase.java:424)

 at org.apache.catalina.util.LifecycleBase.setState(LifecycleBase.java:367)

 at org.apache.catalina.core.ContainerBase.startInternal(ContainerBase.java:969)

 at org.apache.catalina.core.StandardHost.startInternal(StandardHost.java:839)

 at org.apache.catalina.util.LifecycleBase.start(LifecycleBase.java:183)

 

Am I doing anything wrong?

Thanks

 

Jon

> example-mvc-resteasy
> 
>
> Key: TOMEE-2368
> URL: https://issues.apache.org/jira/browse/TOMEE-2368
> Project: TomEE
>  Issue Type: Documentation
>  Components: Examples and Documentation
>Reporter: Daniel Dias dos Santos
>Priority: Minor
>  Labels: pull-request-available
> Fix For: 8.0.0-M2
>
>
> I made a simple hello world example with MVC 1.0 using RestEasy.



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)


[jira] [Commented] (TOMEE-2363) Introduce OWASP dependency checking in the Maven build process

2018-12-18 Thread ASF GitHub Bot (JIRA)


[ 
https://issues.apache.org/jira/browse/TOMEE-2363?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16723920#comment-16723920
 ] 

ASF GitHub Bot commented on TOMEE-2363:
---

Github user radcortez commented on the issue:

https://github.com/apache/tomee/pull/276
  
@rzo1 that sounds great. I'll try it.


> Introduce OWASP dependency checking in the Maven build process
> --
>
> Key: TOMEE-2363
> URL: https://issues.apache.org/jira/browse/TOMEE-2363
> Project: TomEE
>  Issue Type: Improvement
>  Components: TomEE Build
>Affects Versions: 7.0.5, 7.1.0, 8.0.0-M1
>Reporter: Richard Zowalla
>Priority: Minor
>  Labels: pull-request-available
> Fix For: 7.0.6, 7.1.1, 8.0.0-M2
>
>
> As discussed on the mailing list
>  
> {quote}Hey, 
>  
> any objectives against automatic checking of known, publicly disclosed 
> dependency vulnerabilities in the Maven build process (e.g. via a profile). 
>  
> I was thinking about introducing OWASP dependency checking (see 
> [https://www.owasp.org/index.php/OWASP_Dependency_Check]) in the TomEE 
> project, so we are aware of security risks introduced by (transient) 
> dependencies. 
>  
> Any thoughs on this? 
>  
> Best, 
>  
> Richard 
> {quote}



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)


[jira] [Commented] (TOMEE-2363) Introduce OWASP dependency checking in the Maven build process

2018-12-18 Thread ASF GitHub Bot (JIRA)


[ 
https://issues.apache.org/jira/browse/TOMEE-2363?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16723905#comment-16723905
 ] 

ASF GitHub Bot commented on TOMEE-2363:
---

Github user rzo1 commented on the issue:

https://github.com/apache/tomee/pull/276
  
I adjusted the PR to my comments above.

Feel free to give any other suggestions. If we introduce this, I would 
recommend to add `owasp-check` to the CI system. Who can do this? 

The CVE score to fail the build needs to be greater 8.0 atm.


> Introduce OWASP dependency checking in the Maven build process
> --
>
> Key: TOMEE-2363
> URL: https://issues.apache.org/jira/browse/TOMEE-2363
> Project: TomEE
>  Issue Type: Improvement
>  Components: TomEE Build
>Affects Versions: 7.0.5, 7.1.0, 8.0.0-M1
>Reporter: Richard Zowalla
>Priority: Minor
>  Labels: pull-request-available
> Fix For: 7.0.6, 7.1.1, 8.0.0-M2
>
>
> As discussed on the mailing list
>  
> {quote}Hey, 
>  
> any objectives against automatic checking of known, publicly disclosed 
> dependency vulnerabilities in the Maven build process (e.g. via a profile). 
>  
> I was thinking about introducing OWASP dependency checking (see 
> [https://www.owasp.org/index.php/OWASP_Dependency_Check]) in the TomEE 
> project, so we are aware of security risks introduced by (transient) 
> dependencies. 
>  
> Any thoughs on this? 
>  
> Best, 
>  
> Richard 
> {quote}



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)