Trending Topics This Week

Here is what people are talking about this week in the world of free and open source software: 

Key Security, Maintenance, and Features Releases

 

Non-Security Updates

Apache Struts 2.5.26
[WW-5095] - Junit plugin does not push ACTION_MAPPING into the context resulting in NPE
[WW-5096] - Struts2 StaticParametersInterceptor's addParametersToContext method is not working as expected.

Apache Tomcat 8.5.61 and 9.0.41
8.5.61
Fix:  56181: Update the RemoteIpValve and RemoteIpFilter so that calls to ServletRequest.getRemoteHost() are consistent with the return value of ServletRequest.getRemoteAddr() rather than always returning a value for the proxy. (markt)
Fix:  56890: Align the behaviour of ServletContext.getRealPath(String path) with the recent clarification from the Servlet specification project. If the path parameter does not start with / then Tomcat processes the call as if / is appended to the beginning of the provided path. (markt)
Fix:  64921: Ensure that the LoadBalancerDrainingValve uses the correct setting for the secure attribute for any session cookies it creates. Based on a pull request by Andreas Kurth. (markt)
Fix:  64947: Don't assume that the Upgrade header has been set on the HttpServletResponse before any call is made to HttpServletRequest.upgrade(). (markt)
9.0.41
Fix:  56181: Update the RemoteIpValve and RemoteIpFilter so that calls to ServletRequest.getRemoteHost() are consistent with the return value of ServletRequest.getRemoteAddr() rather than always returning a value for the proxy. (markt)
Fix:  56890: Align the behaviour of ServletContext.getRealPath(String path) with the recent clarification from the Servlet specification project. If the path parameter does not start with / then Tomcat processes the call as if / is appended to the beginning of the provided path. (markt)
Add:  64080: Enhance the graceful shutdown feature. Includes a new option for StandardService, gracefulStopAwaitMillis, that allows a time to be specified to wait for client connections to complete and close before the Container hierarchy is stopped. (markt)
Fix:  64921: Ensure that the LoadBalancerDrainingValve uses the correct setting for the secure attribute for any session cookies it creates. Based on a pull request by Andreas Kurth. (markt)

Drools 7.47.0.Final
[DROOLS-5700] - Implement range index in Alpha Network Compiler
[DROOLS-5783] - Make droolsjbpm-integration repo independent from appformer
[DROOLS-5792] - [Scesim Editor] Error thrown when assigning a multiple nested collection property
[DROOLS-5804] - Column rule name be increased / number be right-aligned in Scenario Coverage Report

jBPM 7.47.0.Final
[JBPM-9411] - Runtime Engine - Provide a way to access task details in boundary event
[JBPM-9436] - AMQ Streams (Kafka) integration - Consume events from Kafka by Signal or Messages Events
[JBPM-9465] - Add support for using the public API to retrieve a node type
[JBPM-9470] - User Task output variable mapping to an object attribute
 

The Future of CentOS Discussion 

Last week, RedHat announced their decision to end CentOS 8 in 2021 and shift development focus to CentOS Stream, the upstream version of RHEL. This change has left many organizations with questions. Join our experts December 22nd, for an interactive discussion on the CentOS announcement.

View all OpenUpdate editions >