+1 from me. I agree with Freeman, sometimes we have to break backwards compatibility for security fixes.
Colm. On Tue, Oct 6, 2026 at 3:03 PM Fabio Burzigotti via dev <[email protected]> wrote: > > Thanks Freeman, I've followed up on Jira. > I am aware the changes in both CXF and WSS4J are meant to work together, so I > am okay with this not blocking the release, now that we've discussed the > reported issue. > With that being said, even if a configurable opt-in approach doesn't look to > be right in this specific situation, I do think it should be documented. > > Cheers, > Fabio. > ________________________________ > From: Freeman Fang <[email protected]> > Sent: Monday, October 5, 2026 4:03 PM > To: [email protected] <[email protected]> > Cc: Fabio Burzigotti <[email protected]> > Subject: [EXTERNAL] Re: [VOTE] Release Apache CXF 4.2.4, 4.1.9 and 3.6.13 > > Hi Fabio, Thanks for raising your concern, and please see my comment in > https: //issues. apache. org/jira/browse/CXF-9253 I don't think this should > block the release: Updating a dependency in a patch release is normal for > CXF, and it's > > Hi Fabio, > > Thanks for raising your concern, and please see my comment in > https://issues.apache.org/jira/browse/CXF-9253<https://urldefense.proofpoint.com/v2/url?u=https-3A__issues.apache.org_jira_browse_CXF-2D9253&d=DwMFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=6DfnpHA4c8_1RRukaC5NgaPkggwObJL3tohfoe-PGLI&m=sGqPrCjYm7G64es8zpKbF8434NxVU_3-mvq_0K1Ri0ZGN1iZNOgDFupjf62cUGef&s=ptmsMTGAv5aemgwxDbrOco84n8SXQlUPoKwLJefPeQk&e=> > > I don't think this should block the release: > > Updating a dependency in a patch release is normal for CXF, and it's expected > that downstream projects upgrade it along with CXF. In many cases we release > CXF in order to pick up the fixes from dependencies. Back to your concern > here, the two changes(from WSS4J and CXF) are two halves of one hardening fix > and only work together. > > Hope this helps. > > Best Regards > Freeman > > On Fri, Oct 2, 2026 at 11:33 AM Fabio Burzigotti via dev > <[email protected]<mailto:[email protected]>> wrote: > Hi, > We've been running JBossWS CXF tests and logged > https://issues.apache.org/jira/browse/CXF-9253<https://urldefense.proofpoint.com/v2/url?u=https-3A__issues.apache.org_jira_browse_CXF-2D9253&d=DwMFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=6DfnpHA4c8_1RRukaC5NgaPkggwObJL3tohfoe-PGLI&m=sGqPrCjYm7G64es8zpKbF8434NxVU_3-mvq_0K1Ri0ZGN1iZNOgDFupjf62cUGef&s=ptmsMTGAv5aemgwxDbrOco84n8SXQlUPoKwLJefPeQk&e=>. > I'd cast a -1, at least it would be good to discuss about the reported bug. > > Cheers, > Fabio. > ________________________________ > From: Freeman Fang <[email protected]<mailto:[email protected]>> > Sent: Thursday, October 1, 2026 9:32 PM > To: CXF DEV <[email protected]<mailto:[email protected]>> > Subject: [EXTERNAL] [VOTE] Release Apache CXF 4.2.4, 4.1.9 and 3.6.13 > > Hi, > > > It’s been a while since last releases and many issues have been addressed, > so here is the VOTE to release CXF 4.2.4, 4.1.9 and 3.6.13 > > > Staging areas: > > https://urldefense.proofpoint.com/v2/url?u=https-3A__repository.apache.org_content_repositories_orgapachecxf-2D1301&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=6DfnpHA4c8_1RRukaC5NgaPkggwObJL3tohfoe-PGLI&m=u8dm96TQMtFeHsbRUIZ6Ma2_cUOJxeWyLMr52Qhn9mL_-c55Fm1QPlYIliTE9dS2&s=41K-EYRQoN9XnpGa5dGQzHt6VLx4uxgVWgFDK1z5pjA&e= > > https://urldefense.proofpoint.com/v2/url?u=https-3A__repository.apache.org_content_repositories_orgapachecxf-2D1303&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=6DfnpHA4c8_1RRukaC5NgaPkggwObJL3tohfoe-PGLI&m=u8dm96TQMtFeHsbRUIZ6Ma2_cUOJxeWyLMr52Qhn9mL_-c55Fm1QPlYIliTE9dS2&s=g5ZOEyZEoNICNQVajin5fW6p5aEXEIjh6cGn1OKGjII&e= > > https://urldefense.proofpoint.com/v2/url?u=https-3A__repository.apache.org_content_repositories_orgapachecxf-2D1304&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=6DfnpHA4c8_1RRukaC5NgaPkggwObJL3tohfoe-PGLI&m=u8dm96TQMtFeHsbRUIZ6Ma2_cUOJxeWyLMr52Qhn9mL_-c55Fm1QPlYIliTE9dS2&s=r0uj2lzCcOcjt1JhBrPCS_6hEU7EgWyf37Cn4QvkEtc&e= > > > Tags: > > https://urldefense.proofpoint.com/v2/url?u=https-3A__github.com_apache_cxf_commit_5e324f121104cc76af1b8f3ec0d1a20ef9e98c3b&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=6DfnpHA4c8_1RRukaC5NgaPkggwObJL3tohfoe-PGLI&m=u8dm96TQMtFeHsbRUIZ6Ma2_cUOJxeWyLMr52Qhn9mL_-c55Fm1QPlYIliTE9dS2&s=13e4JG1bNA-lZ5Lv8u0ooMk8JrHXEbqOAFX9_J9zUyI&e= > > https://urldefense.proofpoint.com/v2/url?u=https-3A__github.com_apache_cxf_commit_043829b193a6ead389864e636a07ddf6bfa2ca8a&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=6DfnpHA4c8_1RRukaC5NgaPkggwObJL3tohfoe-PGLI&m=u8dm96TQMtFeHsbRUIZ6Ma2_cUOJxeWyLMr52Qhn9mL_-c55Fm1QPlYIliTE9dS2&s=QYFP-gFR8mFHaOIG3IBuzNvAj0ZItiBL1H3rW5YQtsk&e= > > https://urldefense.proofpoint.com/v2/url?u=https-3A__github.com_apache_cxf_commit_8999af05d26ef2e63dc4c77a798595e2a53435ad&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=6DfnpHA4c8_1RRukaC5NgaPkggwObJL3tohfoe-PGLI&m=u8dm96TQMtFeHsbRUIZ6Ma2_cUOJxeWyLMr52Qhn9mL_-c55Fm1QPlYIliTE9dS2&s=dVS-0AACqDCe4LTcx9RvxP1ed7_4jlPP00D3q3I43sY&e= > > > I will keep the vote open for at least 72 hours. > > Happy VOTE! > > > Cheers > > > Freeman > > Unless otherwise stated above: > > IBM Italia S.p.A. > Sede Legale: Circonvallazione Idroscalo - 20054 Segrate (MI) > Cap. Soc. euro 247.656.998.20 > C. F. e Reg. Imprese MI 01442240030 - Partita IVA 10914660153 > Società con unico azionista > Società soggetta all'attività di direzione e coordinamento di International > Business Machines Corporation > > Unless otherwise stated above: > > IBM Italia S.p.A. > Sede Legale: Circonvallazione Idroscalo - 20054 Segrate (MI) > Cap. Soc. euro 247.656.998.20 > C. F. e Reg. Imprese MI 01442240030 - Partita IVA 10914660153 > Società con unico azionista > Società soggetta all'attività di direzione e coordinamento di International > Business Machines Corporation
