PaxWeb 7.2.29 - Jetty upgrade?

17 views
Skip to first unread message

Daniel Stoch

unread,
Aug 10, 2022, 4:06:33 AM8/10/22
to OPS4J
Hi,

Is PaxWeb 7.2.x line is still maintained? Actual version 7.2.29 uses Jetty 9.4.43.v20210629 which has some vulnerabilities.
Is it possible to release a new PaxWeb 7.2.x version with newer Jetty version (as I can see PaxWeb 7.3.6 uses Jetty 9.4.48.v20220622)?

--
Best regards,
Daniel Stoch

Richard Hierlmeier

unread,
Aug 11, 2022, 2:30:11 AM8/11/22
to OPS4J
I tried to upgrade my application to Karaf 4.4 to get Jetty  9.4.48, however I found some show stoppers.

I really would appreciate a release of Karaf 4.3 with an updated PaxWeb 7 version.

Regards

   Richard

Grzegorz Grzybek

unread,
Aug 16, 2022, 7:18:49 AM8/16/22
to op...@googlegroups.com
Hello

I've created https://github.com/ops4j/org.ops4j.pax.web/issues/1748 and I can release 7.2.30 soon. However I can't promise when (if) updated Karaf 4.3.x will be released.

regards
Grzegorz Grzybek

--
--
------------------
OPS4J - http://www.ops4j.org - op...@googlegroups.com

---
You received this message because you are subscribed to the Google Groups "OPS4J" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ops4j+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/ops4j/08f475ac-d3d1-4ec1-be8b-662f12418ff8n%40googlegroups.com.

Jean-Baptiste Onofré

unread,
Aug 17, 2022, 1:08:06 AM8/17/22
to OPS4J
By the way, I just checked, and as I thought, it's already done for
Jetty 9.4.48 upgrade on Pax Web 7.3.x:

https://github.com/apache/karaf/commit/62ebc20609

Regarding upgrade on Pax Web 7.2.x, Karaf 4.2.x is not active anymore,
so I invite you to upgrade to Karaf 4.3.x.

Regards
JB

Richard Hierlmeier

unread,
Aug 25, 2022, 7:42:15 AM8/25/22
to OPS4J
Do you have a release schedule for PAX-WEB 7.2.x and Karaf 4.3.8?

Richard

Grzegorz Grzybek

unread,
Aug 25, 2022, 7:46:40 AM8/25/22
to op...@googlegroups.com
Hello

I can release Pax Web 7.2.30 (https://github.com/ops4j/org.ops4j.pax.web/milestone/220) any time, but I'm not sure about Karaf 4.3.x.

regards
Grzegorz Grzybek

Jean-Baptiste Onofré

unread,
Aug 26, 2022, 2:44:51 AM8/26/22
to OPS4J
Hi Richard,

Both releases are planned for next week on my TODO. I was busy with
ActiveMQ release, now on vote, so I will be back on Karaf this week
end.

Regards
JB

On Thu, Aug 25, 2022 at 1:42 PM 'Richard Hierlmeier' via OPS4J
> To view this discussion on the web visit https://groups.google.com/d/msgid/ops4j/b29a4ae0-8dd9-4cb5-93e0-d33e3f2c793en%40googlegroups.com.
Reply all
Reply to author
Forward
0 new messages