struts-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Rene Gielen <rgie...@apache.org>
Subject Re: [VOTE] [FAST TRACK] Struts 2.3.4.1
Date Wed, 08 Aug 2012 07:23:55 GMT
+1 GA

- René

Am 8/4/12 12:45 , schrieb Rene Gielen:
> The Struts 2.3.4.1 test build is now available. It includes the latest
> security patches which fix two possible vulnerabilities:
> * Token parameter names should be decoupled from session attribute names
> * Parameter name length should be restricted
> 
> For details and the rationale behind these changes, please consult the
> corresponding security bulletins:
> * https://cwiki.apache.org/confluence/display/WW/S2-010
> * https://cwiki.apache.org/confluence/display/WW/S2-011
> 
> Please note that currently these bulletins and the release notes are
> only visible to logged-in users with the struts-committer role. This is
> a needed requirement to control disclosure until the actual release is
> announced.
> 
> Release notes:
> * [https://cwiki.apache.org/confluence/display/WW/Version+Notes+2.3.4.1]
> 
> Distribution:
> * [http://people.apache.org/builds/struts/2.3.4.1/]
> 
> Maven 2 staging repository:
> * [https://repository.apache.org/content/repositories/orgapachestruts-116/]
> 
> Once you have had a chance to review the test build, please respond
> with a vote on its quality:
> 
> [ ] Leave at test build
> [ ] Alpha
> [ ] Beta
> [ ] General Availability (GA)
> 
> Everyone who has tested the build is invited to vote. Votes by PMC
> members are considered binding. A vote passes if there are at least
> three binding +1s and more +1s than -1s.
> 
> The vote will remain open for at least 72 hours, longer upon request.
> A vote can be amended at any time to upgrade or downgrade the quality
> of the release based on future experience. If an initial vote
> designates the build as "Beta", the release will be submitted for
> mirroring and announced to the user list. Once released as a public
> beta, subsequent quality votes on a build may be held on the user
> list.
> 
> As always, the act of voting carries certain obligations. A binding
> vote not only states an opinion, but means that the voter is agreeing
> to help do the work
> 
> Thank in advance,
> René
> 

-- 
René Gielen
http://twitter.com/rgielen

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@struts.apache.org
For additional commands, e-mail: dev-help@struts.apache.org


Mime
View raw message