Great !! Thanks for the info Robert From: robertlazarski <[email protected]> Sent: Monday, April 19, 2021 6:47 PM To: [email protected] Subject: Re: Axis2 1.8.0 Release timelines
Thanks for mentioning CVE-2020-0822. We discussed this problem last month on the axis2 dev list. The clustering component depends on Tomcat Tribes - a decision made many years ago. We upgraded those Tomcat deps in git from 6.0.53 to 10.0.2. We now have GitHub Dependabot enabled for auto pull requests on jar updates, so in general the release will be up to date. git clone https://github.com/apache/axis-axis2-java-core.git<https://urldefense.com/v3/__https:/github.com/apache/axis-axis2-java-core.git__;!!KpaPruflFCEp!0N_Xdjlb_C3wx_nVwOYGC8Z6Hfp4h3J3bnb5jO6bt3pFKq_F_ImVVzlUqElmAJTj4ho$> Robert On Mon, Apr 19, 2021 at 2:47 AM Holechi, Vijeta <[email protected]<mailto:[email protected]>> wrote: Thanks Robert!! For your response. We are facing issue with one issue which you have mentioned i.e., AXIS2-5959. And also facing issue with one of the security vulnerability in Axis2 1.7.9 : CVE-2020-0822. From: robertlazarski <[email protected]<mailto:[email protected]>> Sent: Monday, April 19, 2021 6:08 PM To: [email protected]<mailto:[email protected]> Subject: Re: Axis2 1.8.0 Release timelines We are wrapping up the release now. We are volunteers so it's hard to say exactly when the release will be. The largest hurdle has been AXIS2-5959 regarding the complete removal of commons httpclient 3.x. I did a lot of coding in the last week on this. All that is remaining is some doc updates and a decision on whether to upgrade OSGI since it seems to bundle that lib - my initial attempts were unsuccessful and I don't know a lot about that area of axis2. Robert On Thu, Apr 15, 2021 at 8:18 PM Holechi, Vijeta <[email protected]<mailto:[email protected]>> wrote: HI, Want to know when is Axis2 1.8.0 version is getting released. Please share the details. Thanks
