All,

On 8/13/26 1:10 PM, Christopher Schultz wrote:
The proposed Apache Tomcat 10.1.59 release is now available for
voting.

All committers and PMC members are kindly requested to provide a vote if possible. ANY TOMCAT USER MAY VOTE, though only PMC members votes are binding. We welcome non-committer votes or comments on release builds.

The notable changes compared to 10.1.57[*] are:

- Add a new attribute to the Context, urlPatternsProvidedInDecodedForm.
   This attribute controls whether URLs and URL patterns provided in the
   deployment descriptor (web.xml), annotations and/or their programmatic
   equivalents are treated as being provided in URL-encoded form (i.e.
   using %nn encoding) or in decoded form. The Servlet specification
   requires that they are provided in decoded form. However, Tomcat has
   historically treated them as if they are provided in encoded form. In
   Tomcat 12, they will always be treated as if they are provided in
   decoded form. This setting enables migration from encoded form to
   decoded form on an application by application basis. This attribute
   will be removed in Tomcat 12 where it will effectively be hard-coded
   to true.

- Require every HTTP/2 request to provide an authority (either an
   :authority pseudo header or a Host header).

- Change the default encryptionAlgorithm for the EncryptInterceptor to
   AES/GCM/NoPadding. **This is a breaking change for the
   EncryptInterceptor.**

[*] A small bug was found and fixed from the 10.1.58 release, so the major changes remain the same for 10.1.59.

For full details, see the change log:
https://nightlies.apache.org/tomcat/tomcat-10.1.x/docs/changelog.html

Applications that run on Tomcat 9 and earlier will not run on Tomcat 10 without changes. Java EE applications designed for Tomcat 9 and earlier may be placed in the $CATALINA_BASE/webapps-javaee directory and Tomcat will automatically convert them to Jakarta EE and copy them to the webapps directory.

It can be obtained from:
https://dist.apache.org/repos/dist/dev/tomcat/tomcat-10/v10.1.59/

The Maven staging repo is:
https://repository.apache.org/content/repositories/orgapachetomcat-1603

The tag is:
https://github.com/apache/tomcat/tree/10.1.59
https://github.com/apache/tomcat/ commit/08382643a5aaf23bea2915ff88143aedbf8764f5

Please reply with a +1 for release or +0/-0/-1 with an explanation.

+1 for stable release.

Unit tests pass on MacOS aarch64.

Details:
* Environment
* Java (build): openjdk version "25.0.4" 2026-07-21 LTS OpenJDK Runtime Environment Temurin-25.0.4+7 (build 25.0.4+7-LTS) OpenJDK 64-Bit Server VM Temurin-25.0.4+7 (build 25.0.4+7-LTS, mixed mode, sharing) * Java (test): openjdk version "25.0.4" 2026-07-21 LTS OpenJDK Runtime Environment Temurin-25.0.4+7 (build 25.0.4+7-LTS) OpenJDK 64-Bit Server VM Temurin-25.0.4+7 (build 25.0.4+7-LTS, mixed mode, sharing)
*  Ant:             Apache Ant(TM) version 1.10.17 compiled on April 6 2026
*  OS:              Darwin 25.3.0 arm64
*  cc:              Apple clang version 21.0.0 (clang-2100.1.1.101)
*  make:            GNU Make 3.81
* OpenSSL: OpenSSL 3.6.3 9 Jun 2026 (Library: OpenSSL 3.6.3 9 Jun 2026)
*  APR:             1.7.6
*
* Valid SHA-512 signature for apache-tomcat-10.1.59.zip
* Valid GPG signature for apache-tomcat-10.1.59.zip
* Valid SHA-512 signature for apache-tomcat-10.1.59.tar.gz
* Valid GPG signature for apache-tomcat-10.1.59.tar.gz
* Valid SHA-512 signature for apache-tomcat-10.1.59.exe
* Valid GPG signature for apache-tomcat-10.1.59.exe
* Valid Windows Digital Signature for apache-tomcat-10.1.59.exe
* Valid SHA512 signature for apache-tomcat-10.1.59-src.zip
* Valid GPG signature for apache-tomcat-10.1.59-src.zip
* Valid SHA512 signature for apache-tomcat-10.1.59-src.tar.gz
* Valid GPG signature for apache-tomcat-10.1.59-src.tar.gz
*
* Binary Zip and tarball: Same
* Source Zip and tarball: Same
*
* Building dependencies returned: 0
* Tomcat builds cleanly
* tcnative builds cleanly
* Junit Tests: PASSED

-chris


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to