Skip to content

Conversation

@pull
Copy link

@pull pull bot commented May 7, 2023

See Commits and Changes for more details.


Created by pull[bot]

Can you help keep this open source service alive? 💖 Please sponsor : )

@pull pull bot added the ⤵️ pull label May 7, 2023
marc0der and others added 25 commits May 9, 2023 21:30
This includes
- Tomcat 8.5.89 as latest from 8.5 line
- Tomcat 9.0.75 as latest from 9.0 line
- Tomcat 10.1.9 as latest from 10.1 line (will be new default version)
- Tomcat 11.0.0-M6 as latest from 11 line (this is the latest alpha release)

Tomcat 10.0.0-M5 dropped because it's only an alpha release and superseded by M6.
Co-authored-by: Eddú Meléndez Gonzales <[email protected]>
This includes
- Tomcat 8.5.90 as latest from 8.5 line
- Tomcat 9.0.76 as latest from 9.0 line
- Tomcat 10.1.10 as latest from 10.1 line (will be new default version)
- Tomcat 11.0.0-M7 as latest from 11 line (this is the latest alpha release)

Tomcat 10.0.0-M6 dropped because it's only an alpha release and superseded by M7.
> Avoid using this event if you need to build or run code from the pull request.

According to the `pull_request_target`
[docs](https://docs.github.com/en/actions/using-workflows/events-that-trigger-workflows#pull_request_target)
Co-authored-by: Eddú Meléndez <[email protected]>
This includes
- Tomcat 8.5.91 and 8.5.92 from 8.5 line
- Tomcat 9.0.78 and 9.0.79 from 9.0 line
- Tomcat 10.1.11 and 10.1.12 from 10.1 line (10.1.12 will be new default version)
- Tomcat 11.0.0-M10 as latest from 11 line (this is the latest alpha release)

Tomcat 11.0.0-M7 dropped because it's only an alpha release and superseded by M10.
Fixes several Tomcat CVE:
- Important: Request smuggling CVE-2023-45648
- Important: Denial of Service CVE-2023-44487
- Important: Information Disclosure CVE-2023-42795
- Low: Denial of Service CVE-2023-42794

Upgrade includes
- Tomcat 8.5.94 from 8.5 line
- Tomcat 9.0.81 from 9.0 line
- Tomcat 10.1.14 from 10.1 line (will be new default version)
- Tomcat 11.0.0-M12 as latest from 11 line (this is the latest alpha release)

Tomcat 11.0.0-M10 dropped because it's only an alpha release and superseded by M10.
Oliver Weiler and others added 30 commits October 29, 2024 09:30
Upgrade includes
- Tomcat 9.0.100 from 9.0 line
- Tomcat 10.1.36 from 10.1 line
- Tomcat 11.0.4 from 11.0 line (will be new default version)
Upgrade includes
- Tomcat 9.0.102 from 9.0 line
- Tomcat 10.1.39 from 10.1 line
- Tomcat 11.0.5 from 11.0 line (will be new default version)

The Tomcat releases 9.0.101, 10.1.37 and 10.1.38 have been skipped by Tomcat team.
Upgrade includes
- Tomcat 9.0.108 from 9.0 line
- Tomcat 10.1.44 from 10.1 line
- Tomcat 11.0.10 from 11.0 line (will be the new default version)
Upgrade includes
- Tomcat 9.0.109 from 9.0 line
- Tomcat 10.1.46 from 10.1 line
- Tomcat 11.0.11 from 11.0 line (will be the new default version)

Tomcat 10.1.45 was skipped due to a severe regression for some users. Out of band release 10.1.46 was chosen instead.
Upgrade includes
- Tomcat 9.0.112 from 9.0 line
- Tomcat 10.1.49 from 10.1 line
- Tomcat 11.0.14 from 11.0 line (will be the new default version)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.