Am 04.03.25 um 00:30 schrieb Christopher Schultz:
The proposed Apache Tomcat 10.1.38 release is now available for
voting.
All committers and PMC members are kindly requested to provide a vote if
possible. ANY TOMCAT USER MAY VOTE, though only PMC members votes are
binding. We welcome non-committer votes or comments on release builds.
Note that 10.1.37 was not released due to a packaging error.
The notable changes compared to 10.1.36 are:
- Improve the checks for exposure to and protection against
CVE-2024-56337 so that reflection is not used unless required. The
checks for whether the file system is case sensitive or not have been
removed.
- Use Transfer-Encoding for compression rather than Content-Encoding if
the client submits a TE header containing gzip.
- Add makensis as an option for building the Installer for Windows on
non-Windows platforms.
For full details, see the change log:
https://nightlies.apache.org/tomcat/tomcat-10.1.x/docs/changelog.html
Applications that run on Tomcat 9 and earlier will not run on Tomcat 10
without changes. Java EE applications designed for Tomcat 9 and earlier
may be placed in the $CATALINA_BASE/webapps-javaee directory and Tomcat
will automatically convert them to Jakarta EE and copy them to the
webapps directory.
It can be obtained from:
https://dist.apache.org/repos/dist/dev/tomcat/tomcat-10/v10.1.38/
The Maven staging repo is:
https://repository.apache.org/content/repositories/orgapachetomcat-1538
The tag is:
https://github.com/apache/tomcat/tree/10.1.38
https://github.com/apache/tomcat/commit/
baa2f2a3149533d3fd51748b4bf7d6fb6f7b0ee1
Please reply with a +1 for release or +0/-0/-1 with an explanation.
I think the release artefacts differ from the tag.
It looks like you deleted the 10.1.38 tag to apply a small additional
fix to the changelog and then tried to retag the new HEAD. But the new
tag has the same commit hash as the old one and also contains the same
file contents.
Now the src tarball we vote on contains later contents as the tag in
git. For example ant.tstamp.now.iso in build.properties.release differs
between the tag and the source download, but also the signature files
and the changelog.
Best regards,
Rainer
---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org