Re: OSGi information in TomEE 9 and 10

2023-12-12 Thread Richard Zowalla
So if no one was interested since ~ 2012 (no bug reports, etc.), should
n't we just remove it?

Am Dienstag, dem 12.12.2023 um 07:05 -0800 schrieb David Blevins:
> Those we there for Geronimo's benefit as it became osgi-based in the
> last few years it was around.  I suspect they've not consistently
> been updated after around 2012.
> 
> 
> -David
> 
> > On Nov 9, 2023, at 4:51 AM, Mark Struberg
> >  wrote:
> > 
> > Hi!
> > 
> > Seems we do need to update our OSGi import declarations?
> > view-
> > source:https://repo1.maven.org/maven2/org/apache/tomee/openejb-
> > core/9.1.1/openejb-core-9.1.1.pom
> > 
> >  org.apache.openejb.jee.wls;version="[4.0,5)",
> >  org.apache.openejb.loader;version="[4.0,5)",
> >  org.apache.openejb.client;bundle-
> > version="[4.0,5.0)";resolution:=optional,
> >  org.apache.openejb.client.proxy;bundle-
> > version="[4.0,5.0)";resolution:=optional,
> >  org.apache.openejb.client.java;bundle-
> > version="[4.0,5.0)";resolution:=optional,
> >  org.openejb.client;bundle-
> > version="[4.0,5.0)";resolution:=optional,
> > 
> > org.apache.openjpa.event;resolution:=optional;version="[2.1,3)",
> > 
> > org.apache.openjpa.persistence;resolution:=optional;version="[2.1,3
> > )",
> >  org.apache.webbeans.annotation;version="[1.1,2)",
> >  org.apache.webbeans.component;version="[1.1,2)",
> >  org.apache.webbeans.component.creation;version="[1.1,2)",
> >  org.apache.webbeans.config;version="[1.1,2)",
> > Sounds really outdated to me.
> > 
> > LieGrue,
> > strub
> 



signature.asc
Description: This is a digitally signed message part


Re: [VOTE] Release Apache TomEE 9.1.2 (take 2)

2023-12-12 Thread Richard Zowalla
Hi Jon,

thanks.

+1 (binding)

Gruß
Richard

Am Dienstag, dem 12.12.2023 um 16:57 + schrieb Jonathan Gallimore:
> Hi All,
> 
> I'd like to start a vote for the release of Apache TomEE 9.1.2. TomEE
> 9.1.2
> is a maintenance release with dependencies upgrades and bug fixes. It
> also
> fixes the latest Tomcat vulnerabilities
> as well as other CVEs.
> 
> ###
> 
> Maven Repo:
> https://repository.apache.org/content/repositories/orgapachetomee-1225/
> 
> ###
> 
> Binaries & Sources:
> https://dist.apache.org/repos/dist/dev/tomee/staging-1225/tomee-9.1.2/
> 
> ###
> 
> Tags:
> https://github.com/apache/tomee/releases/tag/tomee-9.1.2
> 
> ###
> 
> = Apache TomEE 9.1.2 Release Notes
> :index-group: Release Notes
> :jbake-type: page
> :jbake-status: published
> 
> == Dependency upgrade
> 
> [.compact]
>  - link:https://issues.apache.org/jira/browse/TOMEE-4266[TOMEE-4266]
> ActiveMQ 5.16.7 / 5.18.3
>  - link:https://issues.apache.org/jira/browse/TOMEE-4278[TOMEE-4278]
> Commons CLI 1.6.0
>  - link:https://issues.apache.org/jira/browse/TOMEE-4277[TOMEE-4277]
> Commons Codec 1.16.0
>  - link:https://issues.apache.org/jira/browse/TOMEE-4274[TOMEE-4274]
> Commons DBCP 2.11.0
>  - link:https://issues.apache.org/jira/browse/TOMEE-4275[TOMEE-4275]
> Commons Lang3 3.13.0
>  - link:https://issues.apache.org/jira/browse/TOMEE-4276[TOMEE-4276]
> Jackson 2.15.3
>  -
> link:https://issues.apache.org/jira/browse/TOMEE-4279[TOMEE-4279] Log
> 4J2
> 2.21.1
>  -
> link:https://issues.apache.org/jira/browse/TOMEE-4280[TOMEE-4280] WSS
> 4J
> 3.0.2
> 
> == New Feature
> 
> [.compact]
>  - link:https://issues.apache.org/jira/browse/TOMEE-4281[TOMEE-4281]
> Improve logging when failing to load a class
>  -
> link:https://issues.apache.org/jira/browse/TOMEE-4268[TOMEE-4268] Cre
> ate
> MicroProfile OpenAPI Reader exemple
> 
> == Bug
> 
> [.compact]
>  - link:https://issues.apache.org/jira/browse/TOMEE-4267[TOMEE-4267]
> MicroProfile Metrics JMX Registrar must be initialized once
> 
> == Improvement
> 
> [.compact]
>  -
> link:https://issues.apache.org/jira/browse/TOMEE-4285[TOMEE-4285] Por
> t
> fix for CVE-2023-46589 for TomEE 9.x
>  - link:https://issues.apache.org/jira/browse/TOMEE-4286[TOMEE-4286]
> Namespace error when processing web-fragment.xml
>  -
> link:https://issues.apache.org/jira/browse/TOMEE-4287[TOMEE-4287] Bet
> ter
> information when XBean Finder fails to read a class/jar file
>  - link:https://issues.apache.org/jira/browse/TOMEE-4289[TOMEE-4289]
>  java.util.NoSuchElementException in SystemLogHandler
>  -
> link:https://issues.apache.org/jira/browse/TOMEE-4269[TOMEE-4269] Ena
> ble
> SLF4J 2.x webapps to include bindings in their WEB-INF/lib
> 
> == Task
> 
> [.compact]
>  - link:https://issues.apache.org/jira/browse/TOMEE-4284[TOMEE-4284]
> Implement tomee.mp.jwt.allow.no-exp property over
> mp.jwt.tomee.allow.no-exp
> 
> ###
> 
> Please VOTE
> 
> [+1] go ship it
> [+0] meh, don't care
> [-1] stop, there is a ${showstopper}
> 
> The VOTE is open for 72h or as long as needed.
> 
> Thanks
> 
> Jon



signature.asc
Description: This is a digitally signed message part


[VOTE] Release Apache TomEE 9.1.2 (take 2)

2023-12-12 Thread Jonathan Gallimore
Hi All,

I'd like to start a vote for the release of Apache TomEE 9.1.2. TomEE 9.1.2
is a maintenance release with dependencies upgrades and bug fixes. It also
fixes the latest Tomcat vulnerabilities
as well as other CVEs.

###

Maven Repo:
https://repository.apache.org/content/repositories/orgapachetomee-1225/

###

Binaries & Sources:
https://dist.apache.org/repos/dist/dev/tomee/staging-1225/tomee-9.1.2/

###

Tags:
https://github.com/apache/tomee/releases/tag/tomee-9.1.2

###

= Apache TomEE 9.1.2 Release Notes
:index-group: Release Notes
:jbake-type: page
:jbake-status: published

== Dependency upgrade

[.compact]
 - link:https://issues.apache.org/jira/browse/TOMEE-4266[TOMEE-4266]
ActiveMQ 5.16.7 / 5.18.3
 - link:https://issues.apache.org/jira/browse/TOMEE-4278[TOMEE-4278]
Commons CLI 1.6.0
 - link:https://issues.apache.org/jira/browse/TOMEE-4277[TOMEE-4277]
Commons Codec 1.16.0
 - link:https://issues.apache.org/jira/browse/TOMEE-4274[TOMEE-4274]
Commons DBCP 2.11.0
 - link:https://issues.apache.org/jira/browse/TOMEE-4275[TOMEE-4275]
Commons Lang3 3.13.0
 - link:https://issues.apache.org/jira/browse/TOMEE-4276[TOMEE-4276]
Jackson 2.15.3
 - link:https://issues.apache.org/jira/browse/TOMEE-4279[TOMEE-4279] Log4J2
2.21.1
 - link:https://issues.apache.org/jira/browse/TOMEE-4280[TOMEE-4280] WSS4J
3.0.2

== New Feature

[.compact]
 - link:https://issues.apache.org/jira/browse/TOMEE-4281[TOMEE-4281]
Improve logging when failing to load a class
 - link:https://issues.apache.org/jira/browse/TOMEE-4268[TOMEE-4268] Create
MicroProfile OpenAPI Reader exemple

== Bug

[.compact]
 - link:https://issues.apache.org/jira/browse/TOMEE-4267[TOMEE-4267]
MicroProfile Metrics JMX Registrar must be initialized once

== Improvement

[.compact]
 - link:https://issues.apache.org/jira/browse/TOMEE-4285[TOMEE-4285] Port
fix for CVE-2023-46589 for TomEE 9.x
 - link:https://issues.apache.org/jira/browse/TOMEE-4286[TOMEE-4286]
Namespace error when processing web-fragment.xml
 - link:https://issues.apache.org/jira/browse/TOMEE-4287[TOMEE-4287] Better
information when XBean Finder fails to read a class/jar file
 - link:https://issues.apache.org/jira/browse/TOMEE-4289[TOMEE-4289]
 java.util.NoSuchElementException in SystemLogHandler
 - link:https://issues.apache.org/jira/browse/TOMEE-4269[TOMEE-4269] Enable
SLF4J 2.x webapps to include bindings in their WEB-INF/lib

== Task

[.compact]
 - link:https://issues.apache.org/jira/browse/TOMEE-4284[TOMEE-4284]
Implement tomee.mp.jwt.allow.no-exp property over mp.jwt.tomee.allow.no-exp

###

Please VOTE

[+1] go ship it
[+0] meh, don't care
[-1] stop, there is a ${showstopper}

The VOTE is open for 72h or as long as needed.

Thanks

Jon


Re: OSGi information in TomEE 9 and 10

2023-12-12 Thread David Blevins
Those we there for Geronimo's benefit as it became osgi-based in the last few 
years it was around.  I suspect they've not consistently been updated after 
around 2012.


-David

> On Nov 9, 2023, at 4:51 AM, Mark Struberg  wrote:
> 
> Hi!
> 
> Seems we do need to update our OSGi import declarations?
> view-source:https://repo1.maven.org/maven2/org/apache/tomee/openejb-core/9.1.1/openejb-core-9.1.1.pom
> 
>  org.apache.openejb.jee.wls;version="[4.0,5)",
>  org.apache.openejb.loader;version="[4.0,5)",
>  
> org.apache.openejb.client;bundle-version="[4.0,5.0)";resolution:=optional,
>  
> org.apache.openejb.client.proxy;bundle-version="[4.0,5.0)";resolution:=optional,
>  
> org.apache.openejb.client.java;bundle-version="[4.0,5.0)";resolution:=optional,
>  org.openejb.client;bundle-version="[4.0,5.0)";resolution:=optional,
>  org.apache.openjpa.event;resolution:=optional;version="[2.1,3)",
>  org.apache.openjpa.persistence;resolution:=optional;version="[2.1,3)",
>  org.apache.webbeans.annotation;version="[1.1,2)",
>  org.apache.webbeans.component;version="[1.1,2)",
>  org.apache.webbeans.component.creation;version="[1.1,2)",
>  org.apache.webbeans.config;version="[1.1,2)",
> Sounds really outdated to me.
> 
> LieGrue,
> strub



[CANCELLED] [VOTE] Release Apache TomEE 9.1.2

2023-12-12 Thread Jonathan Gallimore
Re-rerolling, hopefully with my GPG config sorted out, and a fix for
TOMEE-4289. New vote will be up shortly.

Jon

On Thu, Dec 7, 2023 at 2:12 PM Jonathan Gallimore <
jonathan.gallim...@gmail.com> wrote:

> Hi All,
>
> I'd like to start a vote for the release of Apache TomEE 9.1.2. TomEE
> 9.1.2 is a maintenance release with dependencies upgrades and bug fixes. It
> also fixes the latest Tomcat vulnerabilities
> as well as other CVEs.
>
> ###
>
> Maven Repo:
> https://repository.apache.org/content/repositories/orgapachetomee-1224/
>
> ###
>
> Binaries & Sources:
> https://dist.apache.org/repos/dist/dev/tomee/staging-1224/tomee-9.1.2/
>
> ###
>
> Tags:
> https://github.com/apache/tomee/releases/tag/tomee-9.1.2
>
> ###
>
> Release notes:
>
> https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12312320&version=12353729
>
> ###
>
> Here's an adoc generated version of the changelog:
>
> = Apache TomEE 9.1.2 Release Notes
> :index-group: Release Notes
> :jbake-type: page
> :jbake-status: published
>
> == Dependency upgrade
>
> [.compact]
>  - link:https://issues.apache.org/jira/browse/TOMEE-4266[TOMEE-4266]
> ActiveMQ 5.16.7 / 5.18.3
>  - link:https://issues.apache.org/jira/browse/TOMEE-4278[TOMEE-4278]
> Commons CLI 1.6.0
>  - link:https://issues.apache.org/jira/browse/TOMEE-4277[TOMEE-4277]
> Commons Codec 1.16.0
>  - link:https://issues.apache.org/jira/browse/TOMEE-4274[TOMEE-4274]
> Commons DBCP 2.11.0
>  - link:https://issues.apache.org/jira/browse/TOMEE-4275[TOMEE-4275]
> Commons Lang3 3.13.0
>  - link:https://issues.apache.org/jira/browse/TOMEE-4276[TOMEE-4276]
> Jackson 2.15.3
>  - link:https://issues.apache.org/jira/browse/TOMEE-4279[TOMEE-4279]
> Log4J2 2.21.1
>  - link:https://issues.apache.org/jira/browse/TOMEE-4280[TOMEE-4280]
> WSS4J 3.0.2
>
> == New Feature
>
> [.compact]
>  - link:https://issues.apache.org/jira/browse/TOMEE-4281[TOMEE-4281]
> Improve logging when failing to load a class
>  - link:https://issues.apache.org/jira/browse/TOMEE-4268[TOMEE-4268]
> Create MicroProfile OpenAPI Reader exemple
>
> == Bug
>
> [.compact]
>  - link:https://issues.apache.org/jira/browse/TOMEE-4267[TOMEE-4267]
> MicroProfile Metrics JMX Registrar must be initialized once
>
> == Improvement
>
> [.compact]
>  - link:https://issues.apache.org/jira/browse/TOMEE-4285[TOMEE-4285] Port
> fix for CVE-2023-46589 for TomEE 9.x
>  - link:https://issues.apache.org/jira/browse/TOMEE-4286[TOMEE-4286]
> Namespace error when processing web-fragment.xml
>  - link:https://issues.apache.org/jira/browse/TOMEE-4287[TOMEE-4287]
> Better information when XBean Finder fails to read a class/jar file
>  - link:https://issues.apache.org/jira/browse/TOMEE-4269[TOMEE-4269]
> Enable SLF4J 2.x webapps to include bindings in their WEB-INF/lib
>
> == Task
>
> [.compact]
>  - link:https://issues.apache.org/jira/browse/TOMEE-4284[TOMEE-4284]
> Implement tomee.mp.jwt.allow.no-exp property over mp.jwt.tomee.allow.no-exp
>
> ###
>
> Please VOTE
>
> [+1] go ship it
> [+0] meh, don't care
> [-1] stop, there is a ${showstopper}
>
> The VOTE is open for 72h or as long as needed.
>
> Thanks
>
> Jon
>
>
>
>


Re: OSGi information in TomEE 9 and 10

2023-12-12 Thread Richard Zowalla
Yeah, looks broken. 

Am Donnerstag, dem 09.11.2023 um 13:51 +0100 schrieb Mark Struberg:
> Hi!
> 
> Seems we do need to update our OSGi import declarations?
> view-
> source:https://repo1.maven.org/maven2/org/apache/tomee/openejb-core/9
> .1.1/openejb-core-9.1.1.pom
> 
>   org.apache.openejb.jee.wls;version="[4.0,5)",
>   org.apache.openejb.loader;version="[4.0,5)",
>   org.apache.openejb.client;bundle-
> version="[4.0,5.0)";resolution:=optional,
>   org.apache.openejb.client.proxy;bundle-
> version="[4.0,5.0)";resolution:=optional,
>   org.apache.openejb.client.java;bundle-
> version="[4.0,5.0)";resolution:=optional,
>   org.openejb.client;bundle-
> version="[4.0,5.0)";resolution:=optional,
>  
> org.apache.openjpa.event;resolution:=optional;version="[2.1,3)",
>  
> org.apache.openjpa.persistence;resolution:=optional;version="[2.1,3)"
> ,
>   org.apache.webbeans.annotation;version="[1.1,2)",
>   org.apache.webbeans.component;version="[1.1,2)",
>   org.apache.webbeans.component.creation;version="[1.1,2)",
>   org.apache.webbeans.config;version="[1.1,2)",
> Sounds really outdated to me.
> 
> LieGrue,
> strub



signature.asc
Description: This is a digitally signed message part


Re: [PR] TOMEE-4289 Patch SystemLogHandler (tomee)

2023-12-12 Thread via GitHub


jgallimore merged PR #1088:
URL: https://github.com/apache/tomee/pull/1088


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@tomee.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



Re: [VOTE] Release Apache TomEE 9.1.2

2023-12-12 Thread Jonathan Gallimore
Yes - I'll get that sorted out. Thanks for the script.

While we're here, I've got one issue I'd like to get fixed in the release:
https://issues.apache.org/jira/browse/TOMEE-4289 (
https://github.com/apache/tomee/pull/1088).

Let me know if there's any objections. I'll re-roll today and put another
vote up to include it if that's ok.

Jon

On Tue, Dec 12, 2023 at 7:31 AM Richard Zowalla  wrote:

> Hi Jon,
>
> tried checking the gpg signature with the following script:
>
> https://gist.github.com/rzo1/99dcf6719f5e027f38403545ef20bd80
>
> Looks like the key used "927AEAC4B9AD730DEC3BB2319969E985B1A390A9" to
> sign the artifacts isn't available
> in https://dist.apache.org/repos/dist/release/tomee/KEYS
>
> Can you update the file?
>
> Gruß
> Richard
>
> Am Donnerstag, dem 07.12.2023 um 14:12 + schrieb Jonathan
> Gallimore:
> > Hi All,
> >
> > I'd like to start a vote for the release of Apache TomEE 9.1.2. TomEE
> > 9.1.2
> > is a maintenance release with dependencies upgrades and bug fixes. It
> > also
> > fixes the latest Tomcat vulnerabilities
> > as well as other CVEs.
> >
> > ###
> >
> > Maven Repo:
> > https://repository.apache.org/content/repositories/orgapachetomee-1224/
> >
> > ###
> >
> > Binaries & Sources:
> > https://dist.apache.org/repos/dist/dev/tomee/staging-1224/tomee-9.1.2/
> >
> > ###
> >
> > Tags:
> > https://github.com/apache/tomee/releases/tag/tomee-9.1.2
> >
> > ###
> >
> > Release notes:
> >
> https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12312320&version=12353729
> >
> > ###
> >
> > Here's an adoc generated version of the changelog:
> >
> > = Apache TomEE 9.1.2 Release Notes
> > :index-group: Release Notes
> > :jbake-type: page
> > :jbake-status: published
> >
> > == Dependency upgrade
> >
> > [.compact]
> >  - link:https://issues.apache.org/jira/browse/TOMEE-4266[TOMEE-4266]
> > ActiveMQ 5.16.7 / 5.18.3
> >  - link:https://issues.apache.org/jira/browse/TOMEE-4278[TOMEE-4278]
> > Commons CLI 1.6.0
> >  - link:https://issues.apache.org/jira/browse/TOMEE-4277[TOMEE-4277]
> > Commons Codec 1.16.0
> >  - link:https://issues.apache.org/jira/browse/TOMEE-4274[TOMEE-4274]
> > Commons DBCP 2.11.0
> >  - link:https://issues.apache.org/jira/browse/TOMEE-4275[TOMEE-4275]
> > Commons Lang3 3.13.0
> >  - link:https://issues.apache.org/jira/browse/TOMEE-4276[TOMEE-4276]
> > Jackson 2.15.3
> >  -
> > link:https://issues.apache.org/jira/browse/TOMEE-4279[TOMEE-4279] Log
> > 4J2
> > 2.21.1
> >  -
> > link:https://issues.apache.org/jira/browse/TOMEE-4280[TOMEE-4280] WSS
> > 4J
> > 3.0.2
> >
> > == New Feature
> >
> > [.compact]
> >  - link:https://issues.apache.org/jira/browse/TOMEE-4281[TOMEE-4281]
> > Improve logging when failing to load a class
> >  -
> > link:https://issues.apache.org/jira/browse/TOMEE-4268[TOMEE-4268] Cre
> > ate
> > MicroProfile OpenAPI Reader exemple
> >
> > == Bug
> >
> > [.compact]
> >  - link:https://issues.apache.org/jira/browse/TOMEE-4267[TOMEE-4267]
> > MicroProfile Metrics JMX Registrar must be initialized once
> >
> > == Improvement
> >
> > [.compact]
> >  -
> > link:https://issues.apache.org/jira/browse/TOMEE-4285[TOMEE-4285] Por
> > t
> > fix for CVE-2023-46589 for TomEE 9.x
> >  - link:https://issues.apache.org/jira/browse/TOMEE-4286[TOMEE-4286]
> > Namespace error when processing web-fragment.xml
> >  -
> > link:https://issues.apache.org/jira/browse/TOMEE-4287[TOMEE-4287] Bet
> > ter
> > information when XBean Finder fails to read a class/jar file
> >  -
> > link:https://issues.apache.org/jira/browse/TOMEE-4269[TOMEE-4269] Ena
> > ble
> > SLF4J 2.x webapps to include bindings in their WEB-INF/lib
> >
> > == Task
> >
> > [.compact]
> >  - link:https://issues.apache.org/jira/browse/TOMEE-4284[TOMEE-4284]
> > Implement tomee.mp.jwt.allow.no-exp property over
> > mp.jwt.tomee.allow.no-exp
> >
> > ###
> >
> > Please VOTE
> >
> > [+1] go ship it
> > [+0] meh, don't care
> > [-1] stop, there is a ${showstopper}
> >
> > The VOTE is open for 72h or as long as needed.
> >
> > Thanks
> >
> > Jon
>
>


[PR] TOMEE-4289 Patch SystemLogHandler (tomee)

2023-12-12 Thread via GitHub


jgallimore opened a new pull request, #1088:
URL: https://github.com/apache/tomee/pull/1088

   (no comment)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@tomee.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org