Re: using cocoon 2.1 in the long-term, security concerns

2021-07-19 Thread Christopher Schultz
Vincent, On 7/19/21 08:03, Vincent Neyt wrote: Hi Cocoon users, I'd like to ask your opinion on the long-term security risks of running Cocoon on a server. The colleague responsible for the servers at my university is inquiring if the software I'm using for my website is up to date and is

Re: using cocoon 2.1 in the long-term, security concerns

2021-07-19 Thread gelo1234
Hello Vincent, It depends on your future Strategy. Cocoon is very flexible. We've been running Cocoon 3.0-beta in production with Tomcat9/10, Quarkus and even Kubernetes 1.20 etc. No problems at all :) with Java 8 :) We cannot switch to Java 11, because it's not compatible with Cocoon libraries

Re: using cocoon 2.1 in the long-term, security concerns

2021-07-19 Thread Cédric Damioli
Hi, Not only Tomcat, but each and every dependency your particular project uses. As of today, Cocoon 2.1 works well in a Java 11+/Tomcat 9+ environment, with all dependencies upgraded. Cocoon 2.1.13 itself contained a fix for a security-related issue, but in the past years, there wasn't many

Re: using cocoon 2.1 in the long-term, security concerns

2021-07-19 Thread warrell harries
The Tomcat version must be updated to address these concerns. That should do it On Mon, 19 Jul 2021, 13:03 Vincent Neyt, wrote: > Hi Cocoon users, > > I'd like to ask your opinion on the long-term security risks of running > Cocoon on a server. The colleague responsible for the servers at my >

using cocoon 2.1 in the long-term, security concerns

2021-07-19 Thread Vincent Neyt
Hi Cocoon users, I'd like to ask your opinion on the long-term security risks of running Cocoon on a server. The colleague responsible for the servers at my university is inquiring if the software I'm using for my website is up to date and is concerned that I'm using outdated software that could