Rainer,

Thanks for the heads-up.

I'll re-roll again.

-chris

On 3/4/25 5:03 AM, Rainer Jung wrote:
Am 04.03.25 um 00:30 schrieb Christopher Schultz:
The proposed Apache Tomcat 10.1.38 release is now available for
voting.

All committers and PMC members are kindly requested to provide a vote if possible. ANY TOMCAT USER MAY VOTE, though only PMC members votes are binding. We welcome non-committer votes or comments on release builds.

Note that 10.1.37 was not released due to a packaging error.

The notable changes compared to 10.1.36 are:

- Improve the checks for exposure to and protection against
   CVE-2024-56337 so that reflection is not used unless required. The
   checks for whether the file system is case sensitive or not have been
   removed.

- Use Transfer-Encoding for compression rather than Content-Encoding if
   the client submits a TE header containing gzip.

- Add makensis as an option for building the Installer for Windows on
   non-Windows platforms.

For full details, see the change log:
https://nightlies.apache.org/tomcat/tomcat-10.1.x/docs/changelog.html

Applications that run on Tomcat 9 and earlier will not run on Tomcat 10 without changes. Java EE applications designed for Tomcat 9 and earlier may be placed in the $CATALINA_BASE/webapps-javaee directory and Tomcat will automatically convert them to Jakarta EE and copy them to the webapps directory.

It can be obtained from:
https://dist.apache.org/repos/dist/dev/tomcat/tomcat-10/v10.1.38/

The Maven staging repo is:
https://repository.apache.org/content/repositories/orgapachetomcat-1538

The tag is:
https://github.com/apache/tomcat/tree/10.1.38
https://github.com/apache/tomcat/commit/ baa2f2a3149533d3fd51748b4bf7d6fb6f7b0ee1

Please reply with a +1 for release or +0/-0/-1 with an explanation.

I think the release artefacts differ from the tag.

It looks like you deleted the 10.1.38 tag to apply a small additional fix to the changelog and then tried to retag the new HEAD. But the new tag has the same commit hash as the old one and also contains the same file contents.

Now the src tarball we vote on contains later contents as the tag in git. For example ant.tstamp.now.iso in build.properties.release differs between the tag and the source download, but also the signature files and the changelog.

Best regards,

Rainer




---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org

Reply via email to