Re: [VOTE] Apache TomEE 8.0.13 - First Attempt

2022-10-23 Thread Cesar Hernandez
+1 (binding) Thank you all! On Sun, Oct 23, 2022 at 12:34 Jean-Louis Monteiro wrote: > Sorry for the delay Richard. The weekend was a bit busy. > > +1 (binding) > Tested quickly and looked at the packages > > -- > Jean-Louis Monteiro > http://twitter.com/jlouismonteiro > http://www.tomitribe.co

Re: [VOTE] Apache TomEE 8.0.13 - First Attempt

2022-10-23 Thread Jean-Louis Monteiro
Sorry for the delay Richard. The weekend was a bit busy. +1 (binding) Tested quickly and looked at the packages -- Jean-Louis Monteiro http://twitter.com/jlouismonteiro http://www.tomitribe.com On Sun, Oct 23, 2022 at 3:33 PM Daniel Dias Dos Santos < daniel.dias.analist...@gmail.com> wrote: >

Re: [VOTE] Apache TomEE 8.0.13 - First Attempt

2022-10-23 Thread Daniel Dias Dos Santos
Hi, +1 Thanks On Sun, Oct 23, 2022, 08:29 Richard Zowalla wrote: > Any more votes? > > Am Dienstag, dem 11.10.2022 um 19:59 +0200 schrieb Richard Zowalla: > > Hi all, > > > > this is a first attempt at a vote for a release of Apache TomEE > > 8.0.13. > > > > It is a maintenance release with so

Re: [VOTE] Apache TomEE 8.0.13 - First Attempt

2022-10-23 Thread Richard Zowalla
Any more votes? Am Dienstag, dem 11.10.2022 um 19:59 +0200 schrieb Richard Zowalla: > Hi all, > > this is a first attempt at a vote for a release of Apache TomEE > 8.0.13. > > It is a maintenance release with some bug fixes and dependencies > upgrades. > > ### > > Maven Repo: > htt

Re: [VOTE] Apache TomEE 8.0.13 - First Attempt

2022-10-18 Thread Zowalla, Richard
Here is my own +1 (binding) Am Dienstag, dem 11.10.2022 um 19:59 +0200 schrieb Richard Zowalla: > > Hi all, > > > > this is a first attempt at a vote for a release of Apache TomEE > > > 8.0.13. > > > > It is a maintenance release with some bug fixes and dependencies > > upgrades. > > > > ##

Re: [VOTE] Apache TomEE 8.0.13 - First Attempt

2022-10-18 Thread Zowalla, Richard
"or as long as needed" ;-) - waiting for PMC votes. Am Dienstag, dem 18.10.2022 um 08:36 +0200 schrieb Alex The Rocker: > Hi here, the vote for TomEE 8.0.13 launched 1 week ago was supposed > to > hold for 72 hours... > Is it still valid or will a new release candidate show up ? > > Alex > > Le

Re: [VOTE] Apache TomEE 8.0.13 - First Attempt

2022-10-17 Thread Alex The Rocker
Hi here, the vote for TomEE 8.0.13 launched 1 week ago was supposed to hold for 72 hours... Is it still valid or will a new release candidate show up ? Alex Le dim. 16 oct. 2022 à 08:33, Wiesner, Martin a écrit : > > Hi all, > > +1 (non-binding) > > Tested with several projects (primarily web se

Re: [VOTE] Apache TomEE 8.0.13 - First Attempt

2022-10-15 Thread Wiesner, Martin
Hi all, +1 (non-binding) Tested with several projects (primarily web services, JSF…), both on Linux & Mac OS, each under OpenJDK 17 (latest). Best Martin — https://twitter.com/mawiesne > Am 15.10.2022 um 19:41 schrieb Daniel Dias Dos Santos > : > > Hello, > >

Re: [VOTE] Apache TomEE 8.0.13 - First Attempt

2022-10-15 Thread Swell
i did not had time to test the candidate deliverables yet if you go on with the release, i'll definitely test them from the apache cdn at https://dlcdn.apache.org/tomee/ --- Swell On Sat, 15 Oct 2022 at 19:39, Richard Zowalla wrote: > Any more votes? > > Am Dienstag, dem 11.10.2022 um 19:59 +0

Re: [VOTE] Apache TomEE 8.0.13 - First Attempt

2022-10-15 Thread Daniel Dias Dos Santos
Hello, +1 On Sat, Oct 15, 2022, 14:39 Richard Zowalla wrote: > Any more votes? > > Am Dienstag, dem 11.10.2022 um 19:59 +0200 schrieb Richard Zowalla: > > Hi all, > > > > this is a first attempt at a vote for a release of Apache TomEE > > 8.0.13. > > > > It is a maintenance release with some bu

Re: [VOTE] Apache TomEE 8.0.13 - First Attempt

2022-10-15 Thread Richard Zowalla
Any more votes? Am Dienstag, dem 11.10.2022 um 19:59 +0200 schrieb Richard Zowalla: > Hi all, > > this is a first attempt at a vote for a release of Apache TomEE > 8.0.13. > > It is a maintenance release with some bug fixes and dependencies > upgrades. > > ### > > Maven Repo: > htt

Re: [VOTE] Apache TomEE 8.0.13 - First Attempt

2022-10-13 Thread Richard Zowalla
Thanks for your time and detailed testing! Gruß Richard Am Donnerstag, dem 13.10.2022 um 17:10 +0200 schrieb Alex The Rocker: > [+1] (non binding) > Tested TomEE+ 8.0.13 with our web apps in VMs including using > embedded ActiveMQ, also using servlets, JAX-RS, JAX-WS, JMS and > Websockets on L

Re: [VOTE] Apache TomEE 8.0.13 - First Attempt

2022-10-13 Thread Alex The Rocker
[+1] (non binding) Tested TomEE+ 8.0.13 with our web apps in VMs including using embedded ActiveMQ, also using servlets, JAX-RS, JAX-WS, JMS and Websockets on Linux CentOS 7.9 with IBM Semeru 17.0.4 as the Java runtime + Tested in Container-based services with same stack No problems found !

Re: [VOTE] Apache TomEE 8.0.13 - First Attempt

2022-10-12 Thread Zowalla, Richard
Hi Alex, I can confirm, that 2.14.0-rc1 fixes the vulnerability as I cherry- picked the related fixes to an upcoming 2.13.4.1 (micro patch version) yesterday. My PR was merged in earlier today. The issue is, that the fix version is set to 2.14.0 in the CVE itself although it is included in 2.14.0

Re: [VOTE] Apache TomEE 8.0.13 - First Attempt

2022-10-11 Thread Alex The Rocker
Hello Again, Completed some basic tests with TomEE+ 8.0.13 (more complex tests to come), but also I ran https://github.com/anchore/grype latest version on TomEE+ 8.0.12 versus this candidate 8.0.13, with focus on Jackson CVEs, and here's the outcome: With TomEE+ 8.0.12, the jackson-databind-2.13.

Re: [VOTE] Apache TomEE 8.0.13 - First Attempt

2022-10-11 Thread Zowalla, Richard
Good catch. This is expected:  https://issues.apache.org/jira/browse/TOMEE-4021 or  https://lists.apache.org/thread/8tky9dr2sf99cs2hrj95j81w1rhrtdfn Gruß Richard Am Dienstag, dem 11.10.2022 um 22:23 +0200 schrieb Alex The Rocker: > okay I probably make a mistake somewhere. > Also I see ehcache

Re: [VOTE] Apache TomEE 8.0.13 - First Attempt

2022-10-11 Thread Alex The Rocker
okay I probably make a mistake somewhere. Also I see ehcache*.jar is removed in TomEE+ 8.0.13 => is it intentional (I love seeing less JARs;) ? Alex Le mar. 11 oct. 2022 à 22:17, Zowalla, Richard a écrit : > > I am currently not on my dev system but I checked via: > > $ gpg --batch --keyserver h

Re: [VOTE] Apache TomEE 8.0.13 - First Attempt

2022-10-11 Thread Zowalla, Richard
I am currently not on my dev system but I checked via: $ gpg --batch --keyserver hkp://keyserver.ubuntu.com:80 --recv-keys B83D15E72253ED1104EB4FBBDAB472F0E5B8A431 $ gpg --verify apache-tomee-8.0.13-plus.tar.gz.asc apache-tomee-8.0.13- plus.tar.gz gpg: Signatur vom Di 11 Okt 2022 13:14:04 CEST g

Re: [VOTE] Apache TomEE 8.0.13 - First Attempt

2022-10-11 Thread Alex The Rocker
Sorry previous mail sent too quickly. What's wrong here ? $ gpg --verify /tmp/tomee8013.asc apache-tomee-8.0.13-plus.tar.gz gpg: Signature made Tue 11 Oct 2022 01:14:04 PM CEST using RSA key ID E5B8A431 gpg: Can't check signature: No public key Le mar. 11 oct. 2022 à 22:03, Alex The Rocker a éc

Re: [VOTE] Apache TomEE 8.0.13 - First Attempt

2022-10-11 Thread Alex The Rocker
Hum... what's wrong here: Le mar. 11 oct. 2022 à 21:22, Alex The Rocker a écrit : > > +1 for more frequent releases (at least based on CVE with at least > high severity) > and yes, I have a relatively large test base ; stay tuned! > > Le mar. 11 oct. 2022 à 21:16, Richard Zowalla a écrit : > > >

Re: [VOTE] Apache TomEE 8.0.13 - First Attempt

2022-10-11 Thread Alex The Rocker
+1 for more frequent releases (at least based on CVE with at least high severity) and yes, I have a relatively large test base ; stay tuned! Le mar. 11 oct. 2022 à 21:16, Richard Zowalla a écrit : > > Hi Alex, > > we can maybe get into the habit of realising more often (yes, I know: > we discusse

Re: [VOTE] Apache TomEE 8.0.13 - First Attempt

2022-10-11 Thread Richard Zowalla
Hi Alex, we can maybe get into the habit of realising more often (yes, I know: we discussed this over and over on the list...). I was just copying from the VOTE template docs, which mention to write "first attempt" and so on... - so no regrets just copy & paste. I don't expect any suprises but w

Re: [VOTE] Apache TomEE 8.0.13 - First Attempt

2022-10-11 Thread Alex The Rocker
Hi Richard, Thanks for this quick TomEE 8.0.3 release after not so long discussions! I'll run some tests ASAP and then give my vote (non-binding). Why do you mention "1st attempt"? Any regrets ? Alex Le mar. 11 oct. 2022 à 20:01, Richard Zowalla a écrit : > > Hi all, > > this is a first attempt

[VOTE] Apache TomEE 8.0.13 - First Attempt

2022-10-11 Thread Richard Zowalla
Hi all, this is a first attempt at a vote for a release of Apache TomEE 8.0.13. It is a maintenance release with some bug fixes and dependencies upgrades. ### Maven Repo: https://repository.apache.org/content/repositories/orgapachetomee-1207 tomee-8.0.13-release-test