+1 from me. I agree with Freeman, sometimes we have to break backwards
compatibility for security fixes.

Colm.

On Tue, Oct 6, 2026 at 3:03 PM Fabio Burzigotti via dev
<[email protected]> wrote:
>
> Thanks Freeman, I've followed up on Jira.
> I am aware the changes in both CXF and WSS4J are meant to work together, so I 
> am okay with this not blocking the release, now that we've discussed the 
> reported issue.
> With that being said, even if a configurable opt-in approach doesn't look to 
> be right in this specific situation, I do think it should be documented.
>
> Cheers,
> Fabio.
> ________________________________
> From: Freeman Fang <[email protected]>
> Sent: Monday, October 5, 2026 4:03 PM
> To: [email protected] <[email protected]>
> Cc: Fabio Burzigotti <[email protected]>
> Subject: [EXTERNAL] Re: [VOTE] Release Apache CXF 4.2.4, 4.1.9 and 3.6.13
>
> Hi Fabio, Thanks for raising your concern, and please see my comment in 
> https: //issues. apache. org/jira/browse/CXF-9253 I don't think this should 
> block the release: Updating a dependency in a patch release is normal for 
> CXF, and it's
>
> Hi Fabio,
>
> Thanks for raising your concern, and please see my comment in 
> https://issues.apache.org/jira/browse/CXF-9253<https://urldefense.proofpoint.com/v2/url?u=https-3A__issues.apache.org_jira_browse_CXF-2D9253&d=DwMFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=6DfnpHA4c8_1RRukaC5NgaPkggwObJL3tohfoe-PGLI&m=sGqPrCjYm7G64es8zpKbF8434NxVU_3-mvq_0K1Ri0ZGN1iZNOgDFupjf62cUGef&s=ptmsMTGAv5aemgwxDbrOco84n8SXQlUPoKwLJefPeQk&e=>
>
> I don't think this should block the release:
>
> Updating a dependency in a patch release is normal for CXF, and it's expected 
> that downstream projects upgrade it along with CXF. In many cases we release 
> CXF in order to pick up the fixes from dependencies. Back to your concern 
> here, the two changes(from WSS4J and CXF) are two halves of one hardening fix 
> and only work together.
>
> Hope this helps.
>
> Best Regards
> Freeman
>
> On Fri, Oct 2, 2026 at 11:33 AM Fabio Burzigotti via dev 
> <[email protected]<mailto:[email protected]>> wrote:
> Hi,
>   We've been running JBossWS CXF tests and logged 
> https://issues.apache.org/jira/browse/CXF-9253<https://urldefense.proofpoint.com/v2/url?u=https-3A__issues.apache.org_jira_browse_CXF-2D9253&d=DwMFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=6DfnpHA4c8_1RRukaC5NgaPkggwObJL3tohfoe-PGLI&m=sGqPrCjYm7G64es8zpKbF8434NxVU_3-mvq_0K1Ri0ZGN1iZNOgDFupjf62cUGef&s=ptmsMTGAv5aemgwxDbrOco84n8SXQlUPoKwLJefPeQk&e=>.
> I'd cast a -1, at least it would be good to discuss about the reported bug.
>
> Cheers,
> Fabio.
> ________________________________
> From: Freeman Fang <[email protected]<mailto:[email protected]>>
> Sent: Thursday, October 1, 2026 9:32 PM
> To: CXF DEV <[email protected]<mailto:[email protected]>>
> Subject: [EXTERNAL] [VOTE] Release Apache CXF 4.2.4, 4.1.9 and 3.6.13
>
> Hi,
>
>
> It’s been a while since last releases and many issues have been addressed,
> so here is the VOTE to release CXF 4.2.4, 4.1.9 and 3.6.13
>
>
> Staging areas:
>
> https://urldefense.proofpoint.com/v2/url?u=https-3A__repository.apache.org_content_repositories_orgapachecxf-2D1301&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=6DfnpHA4c8_1RRukaC5NgaPkggwObJL3tohfoe-PGLI&m=u8dm96TQMtFeHsbRUIZ6Ma2_cUOJxeWyLMr52Qhn9mL_-c55Fm1QPlYIliTE9dS2&s=41K-EYRQoN9XnpGa5dGQzHt6VLx4uxgVWgFDK1z5pjA&e=
>
> https://urldefense.proofpoint.com/v2/url?u=https-3A__repository.apache.org_content_repositories_orgapachecxf-2D1303&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=6DfnpHA4c8_1RRukaC5NgaPkggwObJL3tohfoe-PGLI&m=u8dm96TQMtFeHsbRUIZ6Ma2_cUOJxeWyLMr52Qhn9mL_-c55Fm1QPlYIliTE9dS2&s=g5ZOEyZEoNICNQVajin5fW6p5aEXEIjh6cGn1OKGjII&e=
>
> https://urldefense.proofpoint.com/v2/url?u=https-3A__repository.apache.org_content_repositories_orgapachecxf-2D1304&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=6DfnpHA4c8_1RRukaC5NgaPkggwObJL3tohfoe-PGLI&m=u8dm96TQMtFeHsbRUIZ6Ma2_cUOJxeWyLMr52Qhn9mL_-c55Fm1QPlYIliTE9dS2&s=r0uj2lzCcOcjt1JhBrPCS_6hEU7EgWyf37Cn4QvkEtc&e=
>
>
> Tags:
>
> https://urldefense.proofpoint.com/v2/url?u=https-3A__github.com_apache_cxf_commit_5e324f121104cc76af1b8f3ec0d1a20ef9e98c3b&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=6DfnpHA4c8_1RRukaC5NgaPkggwObJL3tohfoe-PGLI&m=u8dm96TQMtFeHsbRUIZ6Ma2_cUOJxeWyLMr52Qhn9mL_-c55Fm1QPlYIliTE9dS2&s=13e4JG1bNA-lZ5Lv8u0ooMk8JrHXEbqOAFX9_J9zUyI&e=
>
> https://urldefense.proofpoint.com/v2/url?u=https-3A__github.com_apache_cxf_commit_043829b193a6ead389864e636a07ddf6bfa2ca8a&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=6DfnpHA4c8_1RRukaC5NgaPkggwObJL3tohfoe-PGLI&m=u8dm96TQMtFeHsbRUIZ6Ma2_cUOJxeWyLMr52Qhn9mL_-c55Fm1QPlYIliTE9dS2&s=QYFP-gFR8mFHaOIG3IBuzNvAj0ZItiBL1H3rW5YQtsk&e=
>
> https://urldefense.proofpoint.com/v2/url?u=https-3A__github.com_apache_cxf_commit_8999af05d26ef2e63dc4c77a798595e2a53435ad&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=6DfnpHA4c8_1RRukaC5NgaPkggwObJL3tohfoe-PGLI&m=u8dm96TQMtFeHsbRUIZ6Ma2_cUOJxeWyLMr52Qhn9mL_-c55Fm1QPlYIliTE9dS2&s=dVS-0AACqDCe4LTcx9RvxP1ed7_4jlPP00D3q3I43sY&e=
>
>
> I will keep the vote open for at least 72 hours.
>
> Happy VOTE!
>
>
> Cheers
>
>
> Freeman
>
> Unless otherwise stated above:
>
> IBM Italia S.p.A.
> Sede Legale: Circonvallazione Idroscalo - 20054 Segrate (MI)
> Cap. Soc. euro 247.656.998.20
> C. F. e Reg. Imprese MI 01442240030 - Partita IVA 10914660153
> Società con unico azionista
> Società soggetta all'attività di direzione e coordinamento di International 
> Business Machines Corporation
>
> Unless otherwise stated above:
>
> IBM Italia S.p.A.
> Sede Legale: Circonvallazione Idroscalo - 20054 Segrate (MI)
> Cap. Soc. euro 247.656.998.20
> C. F. e Reg. Imprese MI 01442240030 - Partita IVA 10914660153
> Società con unico azionista
> Società soggetta all'attività di direzione e coordinamento di International 
> Business Machines Corporation

Reply via email to