You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@tomcat.apache.org by Mark Thomas <ma...@apache.org> on 2022/07/14 09:25:40 UTC

[VOTE] Release Apache Tomcat 10.0.23

The proposed Apache Tomcat 10.0.23 release is now available for
voting.

Apache Tomcat 10.0.x implements Jakarta EE 9 and, as such, the primary
package for all the specification APIs has changed from javax.* to jakarta.*

Applications that run on Tomcat 9 will not run on Tomcat 10 without 
changes. Java EE applications designed for Tomcat 9 and earlier may be 
placed in the $CATALINA_BASE/webapps-javaee directory and Tomcat will 
automatically convert them to Jakarta EE and copy them to the webapps 
directory

The notable changes compared to 10.0.22 are:

- Implement support for repeatable builds

- Update the packaged version of the Tomcat Native Library to 1.2.35.
   This includes Windows binaries built with with OpenSSL 1.1.1q.

- Fix CVE-2022-34305, a low severity XSS vulnerability in the Form
   authentication example

Along with lots of other bug fixes and improvements.

For full details, see the changelog:
https://nightlies.apache.org/tomcat/tomcat-10.0.x/docs/changelog.html

It can be obtained from:
https://dist.apache.org/repos/dist/dev/tomcat/tomcat-10/v10.0.23/

The Maven staging repo is:
https://repository.apache.org/content/repositories/orgapachetomcat-1383

The tag is:
https://github.com/apache/tomcat/tree/10.0.23
cda46e050e09bd394c82ba874633367f80eeb259

The proposed 10.0.23 release is:
[ ] Broken - do not release
[ ] Stable - go ahead and release as 10.0.23 (stable)

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@tomcat.apache.org
For additional commands, e-mail: dev-help@tomcat.apache.org


Re: [VOTE] Release Apache Tomcat 10.0.23

Posted by Mark Thomas <ma...@apache.org>.
On 14/07/2022 10:25, Mark Thomas wrote:
> The proposed 10.0.23 release is:
> [ ] Broken - do not release
> [X] Stable - go ahead and release as 10.0.23 (stable)

Unit tests pass with Tomcat Native 1.2.35 built with OpenSSL 1.1.1q on 
Windows, Linux and MacOS.

Mark

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@tomcat.apache.org
For additional commands, e-mail: dev-help@tomcat.apache.org


Re: [VOTE] Release Apache Tomcat 10.0.23

Posted by Rémy Maucherat <re...@apache.org>.
On Thu, Jul 14, 2022 at 11:26 AM Mark Thomas <ma...@apache.org> wrote:
>
> The proposed Apache Tomcat 10.0.23 release is now available for
> voting.
>
> Apache Tomcat 10.0.x implements Jakarta EE 9 and, as such, the primary
> package for all the specification APIs has changed from javax.* to jakarta.*
>
> Applications that run on Tomcat 9 will not run on Tomcat 10 without
> changes. Java EE applications designed for Tomcat 9 and earlier may be
> placed in the $CATALINA_BASE/webapps-javaee directory and Tomcat will
> automatically convert them to Jakarta EE and copy them to the webapps
> directory
>
> The notable changes compared to 10.0.22 are:
>
> - Implement support for repeatable builds
>
> - Update the packaged version of the Tomcat Native Library to 1.2.35.
>    This includes Windows binaries built with with OpenSSL 1.1.1q.
>
> - Fix CVE-2022-34305, a low severity XSS vulnerability in the Form
>    authentication example
>
> Along with lots of other bug fixes and improvements.
>
> For full details, see the changelog:
> https://nightlies.apache.org/tomcat/tomcat-10.0.x/docs/changelog.html
>
> It can be obtained from:
> https://dist.apache.org/repos/dist/dev/tomcat/tomcat-10/v10.0.23/
>
> The Maven staging repo is:
> https://repository.apache.org/content/repositories/orgapachetomcat-1383
>
> The tag is:
> https://github.com/apache/tomcat/tree/10.0.23
> cda46e050e09bd394c82ba874633367f80eeb259
>
> The proposed 10.0.23 release is:
> [ ] Broken - do not release
> [X] Stable - go ahead and release as 10.0.23 (stable)

Remy

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@tomcat.apache.org
For additional commands, e-mail: dev-help@tomcat.apache.org


Re: [VOTE] Release Apache Tomcat 10.0.23

Posted by Mark Thomas <ma...@apache.org>.
Ping. This vote has been open for 10 days and we still need one more PMC 
vote for it to pass.

Mark


On 20/07/2022 19:30, Mark Thomas wrote:
> Ping.
> 
> We need one more PMC vote for this release.
> 
> Mark
> 
> 
> On 14/07/2022 10:25, Mark Thomas wrote:
>> The proposed Apache Tomcat 10.0.23 release is now available for
>> voting.
>>
>> Apache Tomcat 10.0.x implements Jakarta EE 9 and, as such, the primary
>> package for all the specification APIs has changed from javax.* to 
>> jakarta.*
>>
>> Applications that run on Tomcat 9 will not run on Tomcat 10 without 
>> changes. Java EE applications designed for Tomcat 9 and earlier may be 
>> placed in the $CATALINA_BASE/webapps-javaee directory and Tomcat will 
>> automatically convert them to Jakarta EE and copy them to the webapps 
>> directory
>>
>> The notable changes compared to 10.0.22 are:
>>
>> - Implement support for repeatable builds
>>
>> - Update the packaged version of the Tomcat Native Library to 1.2.35.
>>    This includes Windows binaries built with with OpenSSL 1.1.1q.
>>
>> - Fix CVE-2022-34305, a low severity XSS vulnerability in the Form
>>    authentication example
>>
>> Along with lots of other bug fixes and improvements.
>>
>> For full details, see the changelog:
>> https://nightlies.apache.org/tomcat/tomcat-10.0.x/docs/changelog.html
>>
>> It can be obtained from:
>> https://dist.apache.org/repos/dist/dev/tomcat/tomcat-10/v10.0.23/
>>
>> The Maven staging repo is:
>> https://repository.apache.org/content/repositories/orgapachetomcat-1383
>>
>> The tag is:
>> https://github.com/apache/tomcat/tree/10.0.23
>> cda46e050e09bd394c82ba874633367f80eeb259
>>
>> The proposed 10.0.23 release is:
>> [ ] Broken - do not release
>> [ ] Stable - go ahead and release as 10.0.23 (stable)
>>
>> ---------------------------------------------------------------------
>> To unsubscribe, e-mail: dev-unsubscribe@tomcat.apache.org
>> For additional commands, e-mail: dev-help@tomcat.apache.org
>>
> 
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: dev-unsubscribe@tomcat.apache.org
> For additional commands, e-mail: dev-help@tomcat.apache.org
> 

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@tomcat.apache.org
For additional commands, e-mail: dev-help@tomcat.apache.org


Re: [VOTE] Release Apache Tomcat 10.0.23

Posted by Mark Thomas <ma...@apache.org>.
Ping.

We need one more PMC vote for this release.

Mark


On 14/07/2022 10:25, Mark Thomas wrote:
> The proposed Apache Tomcat 10.0.23 release is now available for
> voting.
> 
> Apache Tomcat 10.0.x implements Jakarta EE 9 and, as such, the primary
> package for all the specification APIs has changed from javax.* to 
> jakarta.*
> 
> Applications that run on Tomcat 9 will not run on Tomcat 10 without 
> changes. Java EE applications designed for Tomcat 9 and earlier may be 
> placed in the $CATALINA_BASE/webapps-javaee directory and Tomcat will 
> automatically convert them to Jakarta EE and copy them to the webapps 
> directory
> 
> The notable changes compared to 10.0.22 are:
> 
> - Implement support for repeatable builds
> 
> - Update the packaged version of the Tomcat Native Library to 1.2.35.
>    This includes Windows binaries built with with OpenSSL 1.1.1q.
> 
> - Fix CVE-2022-34305, a low severity XSS vulnerability in the Form
>    authentication example
> 
> Along with lots of other bug fixes and improvements.
> 
> For full details, see the changelog:
> https://nightlies.apache.org/tomcat/tomcat-10.0.x/docs/changelog.html
> 
> It can be obtained from:
> https://dist.apache.org/repos/dist/dev/tomcat/tomcat-10/v10.0.23/
> 
> The Maven staging repo is:
> https://repository.apache.org/content/repositories/orgapachetomcat-1383
> 
> The tag is:
> https://github.com/apache/tomcat/tree/10.0.23
> cda46e050e09bd394c82ba874633367f80eeb259
> 
> The proposed 10.0.23 release is:
> [ ] Broken - do not release
> [ ] Stable - go ahead and release as 10.0.23 (stable)
> 
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: dev-unsubscribe@tomcat.apache.org
> For additional commands, e-mail: dev-help@tomcat.apache.org
> 

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@tomcat.apache.org
For additional commands, e-mail: dev-help@tomcat.apache.org


Re: [VOTE] Release Apache Tomcat 10.0.23

Posted by Han Li <ao...@gmail.com>.

> 2022年7月14日 17:25,Mark Thomas <ma...@apache.org> 写道:
> 
> The proposed Apache Tomcat 10.0.23 release is now available for
> voting.
> 
> Apache Tomcat 10.0.x implements Jakarta EE 9 and, as such, the primary
> package for all the specification APIs has changed from javax.* to jakarta.*
> 
> Applications that run on Tomcat 9 will not run on Tomcat 10 without changes. Java EE applications designed for Tomcat 9 and earlier may be placed in the $CATALINA_BASE/webapps-javaee directory and Tomcat will automatically convert them to Jakarta EE and copy them to the webapps directory
> 
> The notable changes compared to 10.0.22 are:
> 
> - Implement support for repeatable builds
> 
> - Update the packaged version of the Tomcat Native Library to 1.2.35.
>  This includes Windows binaries built with with OpenSSL 1.1.1q.
> 
> - Fix CVE-2022-34305, a low severity XSS vulnerability in the Form
>  authentication example
> 
> Along with lots of other bug fixes and improvements.
> 
> For full details, see the changelog:
> https://nightlies.apache.org/tomcat/tomcat-10.0.x/docs/changelog.html
> 
> It can be obtained from:
> https://dist.apache.org/repos/dist/dev/tomcat/tomcat-10/v10.0.23/
> 
> The Maven staging repo is:
> https://repository.apache.org/content/repositories/orgapachetomcat-1383
> 
> The tag is:
> https://github.com/apache/tomcat/tree/10.0.23
> cda46e050e09bd394c82ba874633367f80eeb259
> 
> The proposed 10.0.23 release is:
> [ ] Broken - do not release
> [ X] Stable - go ahead and release as 10.0.23 (stable)

All unit tests pass on macOS 12.3.1

Han
> 
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: dev-unsubscribe@tomcat.apache.org
> For additional commands, e-mail: dev-help@tomcat.apache.org
> 


---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@tomcat.apache.org
For additional commands, e-mail: dev-help@tomcat.apache.org


Re: [VOTE] Release Apache Tomcat 10.0.23

Posted by jean-frederic clere <jf...@gmail.com>.
On 14/07/2022 11:25, Mark Thomas wrote:
> [X] Stable - go ahead and release as 10.0.23 (stable)

Tested on fedora36

-- 
Cheers

Jean-Frederic


---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@tomcat.apache.org
For additional commands, e-mail: dev-help@tomcat.apache.org


[VOTE][RESULT] Release Apache Tomcat 10.0.23

Posted by Mark Thomas <ma...@apache.org>.
The following votes were cast:

Binding:
+1: markt, remm, jfclere

Non-binding:
+1: Han Li

The vote therefore passes.

Thanks to everyone who contributed to this release.

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@tomcat.apache.org
For additional commands, e-mail: dev-help@tomcat.apache.org