Return-Path: X-Original-To: apmail-struts-dev-archive@www.apache.org Delivered-To: apmail-struts-dev-archive@www.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id 5FB57D0A6 for ; Wed, 8 Aug 2012 07:24:38 +0000 (UTC) Received: (qmail 70071 invoked by uid 500); 8 Aug 2012 07:24:37 -0000 Delivered-To: apmail-struts-dev-archive@struts.apache.org Received: (qmail 69428 invoked by uid 500); 8 Aug 2012 07:24:30 -0000 Mailing-List: contact dev-help@struts.apache.org; run by ezmlm Precedence: bulk List-Unsubscribe: List-Help: List-Post: List-Id: "Struts Developers List" Reply-To: "Struts Developers List" Delivered-To: mailing list dev@struts.apache.org Received: (qmail 69373 invoked by uid 99); 8 Aug 2012 07:24:28 -0000 Received: from athena.apache.org (HELO athena.apache.org) (140.211.11.136) by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 08 Aug 2012 07:24:28 +0000 X-ASF-Spam-Status: No, hits=0.7 required=5.0 tests=SPF_NEUTRAL X-Spam-Check-By: apache.org Received-SPF: neutral (athena.apache.org: local policy) Received: from [85.214.44.140] (HELO e.nrgie.net) (85.214.44.140) by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 08 Aug 2012 07:24:20 +0000 Received: from imac-rene.fritz.box (p508A1773.dip.t-dialin.net [80.138.23.115]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by e.nrgie.net (Postfix) with ESMTP id A3BC4EFCBD5 for ; Wed, 8 Aug 2012 09:45:58 +0200 (CEST) Message-ID: <5022140B.4000208@apache.org> Date: Wed, 08 Aug 2012 09:23:55 +0200 From: Rene Gielen User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.7; rv:14.0) Gecko/20120713 Thunderbird/14.0 MIME-Version: 1.0 To: Struts Developers List Subject: Re: [VOTE] [FAST TRACK] Struts 2.3.4.1 References: <501CFD58.4080304@apache.org> In-Reply-To: <501CFD58.4080304@apache.org> Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 8bit X-Virus-Checked: Checked by ClamAV on apache.org +1 GA - Ren� Am 8/4/12 12:45 , schrieb Rene Gielen: > The Struts 2.3.4.1 test build is now available. It includes the latest > security patches which fix two possible vulnerabilities: > * Token parameter names should be decoupled from session attribute names > * Parameter name length should be restricted > > For details and the rationale behind these changes, please consult the > corresponding security bulletins: > * https://cwiki.apache.org/confluence/display/WW/S2-010 > * https://cwiki.apache.org/confluence/display/WW/S2-011 > > Please note that currently these bulletins and the release notes are > only visible to logged-in users with the struts-committer role. This is > a needed requirement to control disclosure until the actual release is > announced. > > Release notes: > * [https://cwiki.apache.org/confluence/display/WW/Version+Notes+2.3.4.1] > > Distribution: > * [http://people.apache.org/builds/struts/2.3.4.1/] > > Maven 2 staging repository: > * [https://repository.apache.org/content/repositories/orgapachestruts-116/] > > Once you have had a chance to review the test build, please respond > with a vote on its quality: > > [ ] Leave at test build > [ ] Alpha > [ ] Beta > [ ] General Availability (GA) > > Everyone who has tested the build is invited to vote. Votes by PMC > members are considered binding. A vote passes if there are at least > three binding +1s and more +1s than -1s. > > The vote will remain open for at least 72 hours, longer upon request. > A vote can be amended at any time to upgrade or downgrade the quality > of the release based on future experience. If an initial vote > designates the build as "Beta", the release will be submitted for > mirroring and announced to the user list. Once released as a public > beta, subsequent quality votes on a build may be held on the user > list. > > As always, the act of voting carries certain obligations. A binding > vote not only states an opinion, but means that the voter is agreeing > to help do the work > > Thank in advance, > Ren� > -- Ren� Gielen http://twitter.com/rgielen --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscribe@struts.apache.org For additional commands, e-mail: dev-help@struts.apache.org