Re: Invalid CVE on sonatype?

2023-10-16 Thread Romain Manni-Bucau
Think it had been done since the report seems to concern v8/v9, this is why from my window sonatype missed a data in their db and it triggers false positives for any recent tomcat build. Romain Manni-Bucau @rmannibucau | Blog

Re: Invalid CVE on sonatype?

2023-10-16 Thread Mark Thomas
On 16/10/2023 13:11, Romain Manni-Bucau wrote: Hi all, It seems ossindex reports an invalid CVE for tomcat: https://ossindex.sonatype.org/component/pkg:maven/org.apache.tomcat/tomcat-coyote@10.1.15 (https://ossindex.sonatype.org/vulnerability/CVE-2023-42794) Am I right assuming it is due to

Invalid CVE on sonatype?

2023-10-16 Thread Romain Manni-Bucau
Hi all, It seems ossindex reports an invalid CVE for tomcat: https://ossindex.sonatype.org/component/pkg:maven/org.apache.tomcat/tomcat-coyote@10.1.15 (https://ossindex.sonatype.org/vulnerability/CVE-2023-42794) Am I right assuming it is due to the way coordinates are entered in their system

[ANN] Apache Tomcat 8.5.95 available

2023-10-16 Thread Christopher Schultz
The Apache Tomcat team announces the immediate availability of Apache Tomcat 8.5.95. Apache Tomcat 8 is an open source software implementation of the Java Servlet, JavaServer Pages, Java Unified Expression Language, Java WebSocket and JASPIC technologies. Apache Tomcat 8.5.95 is a bugfix and

[tomcat] branch 8.5.x updated: Add release date for 8.5.95.

2023-10-16 Thread schultz
This is an automated email from the ASF dual-hosted git repository. schultz pushed a commit to branch 8.5.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/8.5.x by this push: new 750a0931c7 Add release date for 8.5.95.

[tomcat] branch 10.1.x updated: Update release date for 10.1.15.

2023-10-16 Thread schultz
This is an automated email from the ASF dual-hosted git repository. schultz pushed a commit to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/10.1.x by this push: new d66900389b Update release date for 10.1.15.

svn commit: r1913015 - in /tomcat/site/trunk: ./ docs/ docs/tomcat-8.5-doc/ docs/tomcat-8.5-doc/annotationapi/ docs/tomcat-8.5-doc/annotationapi/javax/annotation/ docs/tomcat-8.5-doc/annotationapi/jav

2023-10-16 Thread schultz
Author: schultz Date: Mon Oct 16 11:53:48 2023 New Revision: 1913015 URL: http://svn.apache.org/viewvc?rev=1913015=rev Log: Update web site to include Tomcat 8.5.95. [This commit notification would consist of 67 parts, which exceeds the limit of 50 ones, so it was shortened to the summary.]

svn commit: r1913011 - in /tomcat/site/trunk: ./ docs/ docs/tomcat-10.1-doc/ docs/tomcat-10.1-doc/annotationapi/ docs/tomcat-10.1-doc/annotationapi/jakarta/annotation/ docs/tomcat-10.1-doc/annotationa

2023-10-16 Thread schultz
Author: schultz Date: Mon Oct 16 11:45:57 2023 New Revision: 1913011 URL: http://svn.apache.org/viewvc?rev=1913011=rev Log: Update website to include Tomcat 10.1.15. [This commit notification would consist of 67 parts, which exceeds the limit of 50 ones, so it was shortened to the summary.]

svn commit: r64551 - /dev/tomcat/tomcat-8/v8.5.95/ /release/tomcat/tomcat-8/v8.5.95/

2023-10-16 Thread schultz
Author: schultz Date: Mon Oct 16 11:32:09 2023 New Revision: 64551 Log: Promote Tomcat 8.5.95 to released. Added: release/tomcat/tomcat-8/v8.5.95/ - copied from r64550, dev/tomcat/tomcat-8/v8.5.95/ Removed: dev/tomcat/tomcat-8/v8.5.95/

svn commit: r64550 - /dev/tomcat/tomcat-10/v10.1.15/ /release/tomcat/tomcat-10/v10.1.15/

2023-10-16 Thread schultz
Author: schultz Date: Mon Oct 16 11:18:58 2023 New Revision: 64550 Log: Promote v10.1.15 to released. Added: release/tomcat/tomcat-10/v10.1.15/ - copied from r64549, dev/tomcat/tomcat-10/v10.1.15/ Removed: dev/tomcat/tomcat-10/v10.1.15/

[VOTE][RELEASE] Release Apache Tomcat 8.5.95

2023-10-16 Thread Christopher Schultz
All, The following votes were cast: +1: isapir, lihan, remm, michaelo, schultz Non-binding: +1: cesarhernandezgt There were no other votes cast, therefore the vote passes. I will begin the release process very shortly. -chris On 10/11/23 21:31, Christopher Schultz wrote: > The proposed

[VOTE][RESULT] Release Apache Tomcat 10.1.15

2023-10-16 Thread Christopher Schultz
All, The following votes were cast: +1: isapir, schultz, lihan, remm Non-binding: +1: rmannibucau There were no other votes cast, therefore the vote passes. I will begin the release process very shortly. -chris On 10/11/23 20:50, Christopher Schultz wrote: The proposed Apache Tomcat

Re: [VOTE] Release Apache Tomcat 10.1.15

2023-10-16 Thread Romain Manni-Bucau
+1, thanks for the quick fix Romain Manni-Bucau @rmannibucau | Blog | Old Blog | Github | LinkedIn | Book