The proposed Apache Tomcat 10.0.20 release is now available for
voting.
Apache Tomcat 10.0.x implements Jakarta EE 9 and, as such, the primary
package for all the specification APIs has changed from javax.* to jakarta.*
Applications that run on Tomcat 9 will not run on Tomcat 10 without
changes. Java EE applications designed for Tomcat 9 and earlier may be
placed in the $CATALINA_BASE/webapps-javaee directory and Tomcat will
automatically convert them to Jakarta EE and copy them to the webapps
directory
The notable changes compared to 10.0.18 are:
- Update the packaged version of the Tomcat Native Library to 1.2.32 to
pick up Windows binaries built with OpenSSL 1.1.1n.
- Improve logging of unknown HTTP/2 settings frames. Pull request by
Thomas Hoffmann.
- Add additional warnings if incompatible TLS configurations are used
such as HTTP/2 with CLIENT-CERT authentication
- Harden the class loader to provide a mitigation for CVE-2022-22965
a Spring Framework vulnerability
Along with lots of other bug fixes and improvements.
For full details, see the changelog:
https://nightlies.apache.org/tomcat/tomcat-10.0.x/docs/changelog.html
It can be obtained from:
https://dist.apache.org/repos/dist/dev/tomcat/tomcat-10/v10.0.20/
The Maven staging repo is:
https://repository.apache.org/content/repositories/orgapachetomcat-1369
The tag is:
https://github.com/apache/tomcat/tree/10.0.20
2a46c651529a9d237b4d6beb1ef846922d949342
The proposed 10.0.20 release is:
[ ] Broken - do not release
[ ] Stable - go ahead and release as 10.0.20 (stable)
---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org