Hi Philipp, all,

I have updated the OFBiz security page
(https://ofbiz.apache.org/security.html) to include references to the
PRs and commits that fix the latest disclosed CVEs.

Moreover, to make it easier to search for security-related code
changes, I have labeled the PRs associated with CVEs with the 'cve'
and 'security' labels and added a comment reporting the corresponding
CVE number. For PRs that introduce security hardening without being
associated with a specific CVE, I have used only the 'security' label.

Regards

Anahita

Il giorno gio 9 lug 2026 alle ore 11:30 Anahita Goljahani
<[email protected]> ha scritto:
>
> Hi Philipp,
>
> I agree with your point. I will coordinate with Jacopo, who is in the
> PMC, and add the commits relevant to each CVE.
>
> Best regards,
> Anahita
>
> Il giorno mer 8 lug 2026 alle ore 11:18 Philipp Hoppen via user
> <[email protected]> ha scritto:
> >
> > Hi all,
> >
> > I noticed that for all OFBiz vulnerabilities published this year, there are 
> > no associated commits published here: https://ofbiz.apache.org/security.html
> >
> > We have some OFBiz installations where it is not always easy to quickly to 
> > migrate to the newest version. Therefore, we usually went through the 
> > associated commits and applied those to our OFBiz versions. Now without the 
> > list of associated commits, we have to go through the commit history 
> > manually and do some guesswork as to which commits are associated with the 
> > published vulnerabilities. This is not a very efficient or relieable 
> > process.
> >
> > Why are those associated commits no longer published, and is there any 
> > chance to have them published again?
> >
> > Regards,
> > Philipp
> >
> >
> > Philipp Hoppen, Software Engineer / System Engineer
> > nowhow solutions AG, Laupenstrasse 1, CH-3008 Bern
> > +41 (0) 31 380 00 76, www.nowhow.ch
> >

Reply via email to