Re: [VOTE] Release Apache Tomcat 11.0.5

2025-03-05 Thread Tim Funk
+1 On Fri, Feb 28, 2025 at 12:06 PM Mark Thomas wrote: > The proposed Apache Tomcat 11.0.5 release is now available for voting. > > > The proposed 11.0.5 release is: > [ ] -1 Broken - do not release > [ X ] +1 Stable - go ahead and release as 11.0.5 > >

Re: [VOTE] Release Apache Tomcat 11.0.5

2025-03-05 Thread Mark Thomas
On 28/02/2025 17:06, Mark Thomas wrote: The proposed 11.0.5 release is: [ ] -1 Broken - do not release [ ] +1 Stable - go ahead and release as 11.0.5 Build is cross platform (Linux/Windows) reproducible. Tests pass on: - Linux (OpenSSL 3.0.13 from Ubuntu 24.04) - Windows (OpenSSL 3.0.14 - Nat

Re: [VOTE] Release Apache Tomcat 11.0.5

2025-03-03 Thread Christopher Schultz
Mark, Thanks for RMing. On 2/28/25 12:06 PM, Mark Thomas wrote: The proposed Apache Tomcat 11.0.5 release is now available for voting. The notable changes compared to 11.0.4 include: - Improve the checks for exposure to and protection against   CVE-2024-56337 so that reflection is not used u

Re: [VOTE] Release Apache Tomcat 11.0.5

2025-03-03 Thread Rémy Maucherat
On Fri, Feb 28, 2025 at 6:06 PM Mark Thomas wrote: > > The proposed Apache Tomcat 11.0.5 release is now available for voting. > > The notable changes compared to 11.0.4 include: > > - Improve the checks for exposure to and protection against >CVE-2024-56337 so that reflection is not used unles

Re: [VOTE] Release Apache Tomcat 11.0.5

2025-03-02 Thread Rainer Jung
Am 28.02.25 um 18:06 schrieb Mark Thomas: The proposed Apache Tomcat 11.0.5 release is now available for voting. The notable changes compared to 11.0.4 include: - Improve the checks for exposure to and protection against   CVE-2024-56337 so that reflection is not used unless required. The

Re: [VOTE] Release Apache Tomcat 11.0.5

2025-02-28 Thread Dimitris Soumis
On Fri, Feb 28, 2025 at 7:13 PM Mark Thomas wrote: > The proposed Apache Tomcat 11.0.5 release is now available for voting. > > The notable changes compared to 11.0.4 include: > > - Improve the checks for exposure to and protection against >CVE-2024-56337 so that reflection is not used unless