Thanks Freeman, I've followed up on Jira.
I am aware the changes in both CXF and WSS4J are meant to work together, so I 
am okay with this not blocking the release, now that we've discussed the 
reported issue.
With that being said, even if a configurable opt-in approach doesn't look to be 
right in this specific situation, I do think it should be documented.

Cheers,
Fabio.
________________________________
From: Freeman Fang <[email protected]>
Sent: Monday, October 5, 2026 4:03 PM
To: [email protected] <[email protected]>
Cc: Fabio Burzigotti <[email protected]>
Subject: [EXTERNAL] Re: [VOTE] Release Apache CXF 4.2.4, 4.1.9 and 3.6.13

Hi Fabio, Thanks for raising your concern, and please see my comment in https: 
//issues. apache. org/jira/browse/CXF-9253 I don't think this should block the 
release: Updating a dependency in a patch release is normal for CXF, and it's

Hi Fabio,

Thanks for raising your concern, and please see my comment in 
https://issues.apache.org/jira/browse/CXF-9253<https://urldefense.proofpoint.com/v2/url?u=https-3A__issues.apache.org_jira_browse_CXF-2D9253&d=DwMFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=6DfnpHA4c8_1RRukaC5NgaPkggwObJL3tohfoe-PGLI&m=sGqPrCjYm7G64es8zpKbF8434NxVU_3-mvq_0K1Ri0ZGN1iZNOgDFupjf62cUGef&s=ptmsMTGAv5aemgwxDbrOco84n8SXQlUPoKwLJefPeQk&e=>

I don't think this should block the release:

Updating a dependency in a patch release is normal for CXF, and it's expected 
that downstream projects upgrade it along with CXF. In many cases we release 
CXF in order to pick up the fixes from dependencies. Back to your concern here, 
the two changes(from WSS4J and CXF) are two halves of one hardening fix and 
only work together.

Hope this helps.

Best Regards
Freeman

On Fri, Oct 2, 2026 at 11:33 AM Fabio Burzigotti via dev 
<[email protected]<mailto:[email protected]>> wrote:
Hi,
  We've been running JBossWS CXF tests and logged 
https://issues.apache.org/jira/browse/CXF-9253<https://urldefense.proofpoint.com/v2/url?u=https-3A__issues.apache.org_jira_browse_CXF-2D9253&d=DwMFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=6DfnpHA4c8_1RRukaC5NgaPkggwObJL3tohfoe-PGLI&m=sGqPrCjYm7G64es8zpKbF8434NxVU_3-mvq_0K1Ri0ZGN1iZNOgDFupjf62cUGef&s=ptmsMTGAv5aemgwxDbrOco84n8SXQlUPoKwLJefPeQk&e=>.
I'd cast a -1, at least it would be good to discuss about the reported bug.

Cheers,
Fabio.
________________________________
From: Freeman Fang <[email protected]<mailto:[email protected]>>
Sent: Thursday, October 1, 2026 9:32 PM
To: CXF DEV <[email protected]<mailto:[email protected]>>
Subject: [EXTERNAL] [VOTE] Release Apache CXF 4.2.4, 4.1.9 and 3.6.13

Hi,


It’s been a while since last releases and many issues have been addressed,
so here is the VOTE to release CXF 4.2.4, 4.1.9 and 3.6.13


Staging areas:

https://urldefense.proofpoint.com/v2/url?u=https-3A__repository.apache.org_content_repositories_orgapachecxf-2D1301&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=6DfnpHA4c8_1RRukaC5NgaPkggwObJL3tohfoe-PGLI&m=u8dm96TQMtFeHsbRUIZ6Ma2_cUOJxeWyLMr52Qhn9mL_-c55Fm1QPlYIliTE9dS2&s=41K-EYRQoN9XnpGa5dGQzHt6VLx4uxgVWgFDK1z5pjA&e=

https://urldefense.proofpoint.com/v2/url?u=https-3A__repository.apache.org_content_repositories_orgapachecxf-2D1303&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=6DfnpHA4c8_1RRukaC5NgaPkggwObJL3tohfoe-PGLI&m=u8dm96TQMtFeHsbRUIZ6Ma2_cUOJxeWyLMr52Qhn9mL_-c55Fm1QPlYIliTE9dS2&s=g5ZOEyZEoNICNQVajin5fW6p5aEXEIjh6cGn1OKGjII&e=

https://urldefense.proofpoint.com/v2/url?u=https-3A__repository.apache.org_content_repositories_orgapachecxf-2D1304&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=6DfnpHA4c8_1RRukaC5NgaPkggwObJL3tohfoe-PGLI&m=u8dm96TQMtFeHsbRUIZ6Ma2_cUOJxeWyLMr52Qhn9mL_-c55Fm1QPlYIliTE9dS2&s=r0uj2lzCcOcjt1JhBrPCS_6hEU7EgWyf37Cn4QvkEtc&e=


Tags:

https://urldefense.proofpoint.com/v2/url?u=https-3A__github.com_apache_cxf_commit_5e324f121104cc76af1b8f3ec0d1a20ef9e98c3b&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=6DfnpHA4c8_1RRukaC5NgaPkggwObJL3tohfoe-PGLI&m=u8dm96TQMtFeHsbRUIZ6Ma2_cUOJxeWyLMr52Qhn9mL_-c55Fm1QPlYIliTE9dS2&s=13e4JG1bNA-lZ5Lv8u0ooMk8JrHXEbqOAFX9_J9zUyI&e=

https://urldefense.proofpoint.com/v2/url?u=https-3A__github.com_apache_cxf_commit_043829b193a6ead389864e636a07ddf6bfa2ca8a&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=6DfnpHA4c8_1RRukaC5NgaPkggwObJL3tohfoe-PGLI&m=u8dm96TQMtFeHsbRUIZ6Ma2_cUOJxeWyLMr52Qhn9mL_-c55Fm1QPlYIliTE9dS2&s=QYFP-gFR8mFHaOIG3IBuzNvAj0ZItiBL1H3rW5YQtsk&e=

https://urldefense.proofpoint.com/v2/url?u=https-3A__github.com_apache_cxf_commit_8999af05d26ef2e63dc4c77a798595e2a53435ad&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=6DfnpHA4c8_1RRukaC5NgaPkggwObJL3tohfoe-PGLI&m=u8dm96TQMtFeHsbRUIZ6Ma2_cUOJxeWyLMr52Qhn9mL_-c55Fm1QPlYIliTE9dS2&s=dVS-0AACqDCe4LTcx9RvxP1ed7_4jlPP00D3q3I43sY&e=


I will keep the vote open for at least 72 hours.

Happy VOTE!


Cheers


Freeman

Unless otherwise stated above:

IBM Italia S.p.A.
Sede Legale: Circonvallazione Idroscalo - 20054 Segrate (MI)
Cap. Soc. euro 247.656.998.20
C. F. e Reg. Imprese MI 01442240030 - Partita IVA 10914660153
Società con unico azionista
Società soggetta all'attività di direzione e coordinamento di International 
Business Machines Corporation

Unless otherwise stated above:

IBM Italia S.p.A.
Sede Legale: Circonvallazione Idroscalo - 20054 Segrate (MI)
Cap. Soc. euro 247.656.998.20
C. F. e Reg. Imprese MI 01442240030 - Partita IVA 10914660153
Società con unico azionista
Società soggetta all'attività di direzione e coordinamento di International 
Business Machines Corporation

Reply via email to