Am 28.02.25 um 18:06 schrieb Mark Thomas:
The proposed Apache Tomcat 11.0.5 release is now available for voting.

The notable changes compared to 11.0.4 include:

- Improve the checks for exposure to and protection against
   CVE-2024-56337 so that reflection is not used unless required. The
   checks for whether the file system is case sensitive or not have been
   removed.

- Use Transfer-Encoding for compression rather than Content-Encoding if
   the client submits a TE header containing gzip

- Add makensis as an option for building the Installer for Windows on
   non-Windows platforms.

For full details, see the change log:
https://nightlies.apache.org/tomcat/tomcat-11.0.x/docs/changelog.html

Applications that run on Tomcat 9 and earlier will not run on Tomcat 11 without changes. Java EE applications designed for Tomcat 9 and earlier may be placed in the $CATALINA_BASE/webapps-javaee directory and Tomcat will automatically convert them to Jakarta EE and copy them to the webapps directory. Applications using deprecated APIs may require further changes.

It can be obtained from:
https://dist.apache.org/repos/dist/dev/tomcat/tomcat-11/v11.0.5/

The Maven staging repo is:
https://repository.apache.org/content/repositories/orgapachetomcat-1534

The tag is:
https://github.com/apache/tomcat/tree/11.0.5
1ba1f9061e49ce03c77b57beff3d50e5c2c3ee29

The proposed 11.0.5 release is:
[ ] -1 Broken - do not release
[X] +1 Stable - go ahead and release as 11.0.5

+1 to release.

Reproducibility of the build checked (including the Windows installer) on Linux Mint 22.0. OK after setting LANG.

Tested on platforms

- RHEL 6, 7, 8 and 9, SLES 11, 12 and 15

using

- recent patch versions of JDK 17, 21, 23 and 24+25 (current EAs)

from

- Eclipse Adoptium, Azul Zulu, Amazon Coretto, Oracle, RedHat and OpenJDK (for the EAs)

where available.

Also tested with

- tcnative 1.3.1, tcnative 2.0.8 and panama

based on

- OpenSSL 3.0.16, 3.1.8, 3.2.4, 3.3.3 and 3.4.1.

All fine, except for

- the usual sporadic crashes with tcnative during shutdown.

- a minor annoyance when trying to build with skip.installer=true. Fixed in HEAD, A workaround should be setting installer.ok=true.

Thanks for RM!

Best regards,

Rainer

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org

Reply via email to