Hi Philipp, all, I have updated the OFBiz security page (https://ofbiz.apache.org/security.html) to include references to the PRs and commits that fix the latest disclosed CVEs.
Moreover, to make it easier to search for security-related code changes, I have labeled the PRs associated with CVEs with the 'cve' and 'security' labels and added a comment reporting the corresponding CVE number. For PRs that introduce security hardening without being associated with a specific CVE, I have used only the 'security' label. Regards Anahita Il giorno gio 9 lug 2026 alle ore 11:30 Anahita Goljahani <[email protected]> ha scritto: > > Hi Philipp, > > I agree with your point. I will coordinate with Jacopo, who is in the > PMC, and add the commits relevant to each CVE. > > Best regards, > Anahita > > Il giorno mer 8 lug 2026 alle ore 11:18 Philipp Hoppen via user > <[email protected]> ha scritto: > > > > Hi all, > > > > I noticed that for all OFBiz vulnerabilities published this year, there are > > no associated commits published here: https://ofbiz.apache.org/security.html > > > > We have some OFBiz installations where it is not always easy to quickly to > > migrate to the newest version. Therefore, we usually went through the > > associated commits and applied those to our OFBiz versions. Now without the > > list of associated commits, we have to go through the commit history > > manually and do some guesswork as to which commits are associated with the > > published vulnerabilities. This is not a very efficient or relieable > > process. > > > > Why are those associated commits no longer published, and is there any > > chance to have them published again? > > > > Regards, > > Philipp > > > > > > Philipp Hoppen, Software Engineer / System Engineer > > nowhow solutions AG, Laupenstrasse 1, CH-3008 Bern > > +41 (0) 31 380 00 76, www.nowhow.ch > >
