Re: [VOTE] Release Apache Tomcat 10.0.20

2022-03-31 Thread Felix Schumacher


Am 31.03.22 um 17:20 schrieb Mark Thomas:

The proposed Apache Tomcat 10.0.20 release is now available for
voting.

Apache Tomcat 10.0.x implements Jakarta EE 9 and, as such, the primary
package for all the specification APIs has changed from javax.* to 
jakarta.*


Applications that run on Tomcat 9 will not run on Tomcat 10 without 
changes. Java EE applications designed for Tomcat 9 and earlier may be 
placed in the $CATALINA_BASE/webapps-javaee directory and Tomcat will 
automatically convert them to Jakarta EE and copy them to the webapps 
directory


The notable changes compared to 10.0.18 are:

- Update the packaged version of the Tomcat Native Library to 1.2.32 to
  pick up Windows binaries built with OpenSSL 1.1.1n.

- Improve logging of unknown HTTP/2 settings frames. Pull request by
  Thomas Hoffmann.

- Add additional warnings if incompatible TLS configurations are used
  such as HTTP/2 with CLIENT-CERT authentication

- Harden the class loader to provide a mitigation for CVE-2022-22965
  a Spring Framework vulnerability

Along with lots of other bug fixes and improvements.

For full details, see the changelog:
https://nightlies.apache.org/tomcat/tomcat-10.0.x/docs/changelog.html

It can be obtained from:
https://dist.apache.org/repos/dist/dev/tomcat/tomcat-10/v10.0.20/

The Maven staging repo is:
https://repository.apache.org/content/repositories/orgapachetomcat-1369

The tag is:
https://github.com/apache/tomcat/tree/10.0.20
2a46c651529a9d237b4d6beb1ef846922d949342

The proposed 10.0.20 release is:
[ ] Broken - do not release
[x] Stable - go ahead and release as 10.0.20 (stable)


Unit test run under Linux with Java 11

Felix




-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



OpenPGP_0xEA6C3728EA91C4AF.asc
Description: OpenPGP public key


OpenPGP_signature
Description: OpenPGP digital signature


Re: [VOTE] Release Apache Tomcat 10.0.20

2022-03-31 Thread Raymond Augé
> [X] Stable - go ahead and release as 10.0.20 (stable)

Ray

On Thu, Mar 31, 2022 at 11:23 AM Rémy Maucherat  wrote:

> On Thu, Mar 31, 2022 at 5:20 PM Mark Thomas  wrote:
> >
> > The proposed Apache Tomcat 10.0.20 release is now available for
> > voting.
> >
> > Apache Tomcat 10.0.x implements Jakarta EE 9 and, as such, the primary
> > package for all the specification APIs has changed from javax.* to
> jakarta.*
> >
> > Applications that run on Tomcat 9 will not run on Tomcat 10 without
> > changes. Java EE applications designed for Tomcat 9 and earlier may be
> > placed in the $CATALINA_BASE/webapps-javaee directory and Tomcat will
> > automatically convert them to Jakarta EE and copy them to the webapps
> > directory
> >
> > The notable changes compared to 10.0.18 are:
> >
> > - Update the packaged version of the Tomcat Native Library to 1.2.32 to
> >pick up Windows binaries built with OpenSSL 1.1.1n.
> >
> > - Improve logging of unknown HTTP/2 settings frames. Pull request by
> >Thomas Hoffmann.
> >
> > - Add additional warnings if incompatible TLS configurations are used
> >such as HTTP/2 with CLIENT-CERT authentication
> >
> > - Harden the class loader to provide a mitigation for CVE-2022-22965
> >a Spring Framework vulnerability
> >
> > Along with lots of other bug fixes and improvements.
> >
> > For full details, see the changelog:
> > https://nightlies.apache.org/tomcat/tomcat-10.0.x/docs/changelog.html
> >
> > It can be obtained from:
> > https://dist.apache.org/repos/dist/dev/tomcat/tomcat-10/v10.0.20/
> >
> > The Maven staging repo is:
> > https://repository.apache.org/content/repositories/orgapachetomcat-1369
> >
> > The tag is:
> > https://github.com/apache/tomcat/tree/10.0.20
> > 2a46c651529a9d237b4d6beb1ef846922d949342
> >
> > The proposed 10.0.20 release is:
> > [ ] Broken - do not release
> > [X] Stable - go ahead and release as 10.0.20 (stable)
>
> Rémy
>
> -
> To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
> For additional commands, e-mail: dev-h...@tomcat.apache.org
>
>

-- 
*Raymond Augé* (@rotty3000)
Senior Software Architect *Liferay, Inc.* (@Liferay)
OSGi Fellow, Java Champion


Re: [VOTE] Release Apache Tomcat 10.0.20

2022-03-31 Thread Rémy Maucherat
On Thu, Mar 31, 2022 at 5:20 PM Mark Thomas  wrote:
>
> The proposed Apache Tomcat 10.0.20 release is now available for
> voting.
>
> Apache Tomcat 10.0.x implements Jakarta EE 9 and, as such, the primary
> package for all the specification APIs has changed from javax.* to jakarta.*
>
> Applications that run on Tomcat 9 will not run on Tomcat 10 without
> changes. Java EE applications designed for Tomcat 9 and earlier may be
> placed in the $CATALINA_BASE/webapps-javaee directory and Tomcat will
> automatically convert them to Jakarta EE and copy them to the webapps
> directory
>
> The notable changes compared to 10.0.18 are:
>
> - Update the packaged version of the Tomcat Native Library to 1.2.32 to
>pick up Windows binaries built with OpenSSL 1.1.1n.
>
> - Improve logging of unknown HTTP/2 settings frames. Pull request by
>Thomas Hoffmann.
>
> - Add additional warnings if incompatible TLS configurations are used
>such as HTTP/2 with CLIENT-CERT authentication
>
> - Harden the class loader to provide a mitigation for CVE-2022-22965
>a Spring Framework vulnerability
>
> Along with lots of other bug fixes and improvements.
>
> For full details, see the changelog:
> https://nightlies.apache.org/tomcat/tomcat-10.0.x/docs/changelog.html
>
> It can be obtained from:
> https://dist.apache.org/repos/dist/dev/tomcat/tomcat-10/v10.0.20/
>
> The Maven staging repo is:
> https://repository.apache.org/content/repositories/orgapachetomcat-1369
>
> The tag is:
> https://github.com/apache/tomcat/tree/10.0.20
> 2a46c651529a9d237b4d6beb1ef846922d949342
>
> The proposed 10.0.20 release is:
> [ ] Broken - do not release
> [X] Stable - go ahead and release as 10.0.20 (stable)

Rémy

-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



Re: [VOTE] Release Apache Tomcat 10.0.20

2022-03-31 Thread Mark Thomas

On 31/03/2022 16:20, Mark Thomas wrote:


The proposed 10.0.20 release is:
[ ] Broken - do not release
[X] Stable - go ahead and release as 10.0.20 (stable)


Unit tests pass on Linux, Windows and MacOS

-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



[VOTE] Release Apache Tomcat 10.0.20

2022-03-31 Thread Mark Thomas

The proposed Apache Tomcat 10.0.20 release is now available for
voting.

Apache Tomcat 10.0.x implements Jakarta EE 9 and, as such, the primary
package for all the specification APIs has changed from javax.* to jakarta.*

Applications that run on Tomcat 9 will not run on Tomcat 10 without 
changes. Java EE applications designed for Tomcat 9 and earlier may be 
placed in the $CATALINA_BASE/webapps-javaee directory and Tomcat will 
automatically convert them to Jakarta EE and copy them to the webapps 
directory


The notable changes compared to 10.0.18 are:

- Update the packaged version of the Tomcat Native Library to 1.2.32 to
  pick up Windows binaries built with OpenSSL 1.1.1n.

- Improve logging of unknown HTTP/2 settings frames. Pull request by
  Thomas Hoffmann.

- Add additional warnings if incompatible TLS configurations are used
  such as HTTP/2 with CLIENT-CERT authentication

- Harden the class loader to provide a mitigation for CVE-2022-22965
  a Spring Framework vulnerability

Along with lots of other bug fixes and improvements.

For full details, see the changelog:
https://nightlies.apache.org/tomcat/tomcat-10.0.x/docs/changelog.html

It can be obtained from:
https://dist.apache.org/repos/dist/dev/tomcat/tomcat-10/v10.0.20/

The Maven staging repo is:
https://repository.apache.org/content/repositories/orgapachetomcat-1369

The tag is:
https://github.com/apache/tomcat/tree/10.0.20
2a46c651529a9d237b4d6beb1ef846922d949342

The proposed 10.0.20 release is:
[ ] Broken - do not release
[ ] Stable - go ahead and release as 10.0.20 (stable)

-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org