build(deps): Bump jetty.version from 9.3.14.v20161028 to 11.0.2 in /osgi-dependencies/w3chtml5validator by dependabot[bot] · Pull Request #654 · wttech/aet
Bumps jetty.version from 9.3.14.v20161028 to 11.0.2.
Updates jetty-http from 9.3.14.v20161028 to 11.0.2
Release notes
Sourced from jetty-http's releases.
11.0.2
Changelog
⚠️ Important Security related Changes
- CVE-2021-28165 - #6072 - jetty server high CPU when client send data length > 17408
- CVE-2021-28164 - #6101 - Normalize ambiguous URIs
- CVE-2021-28163 - #6102 - Exclude webapps directory from deployment scan
Other Changes
- #4275 - Path Normalization/Traversal - Context Matching
- #5828 - Allow to create a WebSocketContainer passing HttpClient
- #5832 - Ctrl-C after jetty:run produces NoClassDefFoundError
- #5835 - Review Durable Filters, Servlets and Listeners
- #5977 - Cache-Control header set by a filter is override by the value from DefaultServlet configuration
- #5994 - QueuedThreadPool "free" threads
- #5996 - ERROR : No module found to provide logback-impl for logback-access{enabled}
- #5999 - HttpURI ArrayIndexOutOfBounds
- #6001 - Ambiguous URI legacy compliance mode
- #6008 - Allow absolute paths to be provided in start.ini for request log directory.
- #6011 - OSGi Cannot start Jetty with osgi.boot - Configurations add wrong method taken
- #6020 - Review Jetty Maven Plugin scanning defaults
- #6021 - Standardize Path resolution in XmlConfiguration
- #6024 - Error starting jetty-10: Provider org.eclipse.jetty.websocket.javax.client.JavaxWebSocketShutdownContainer not found
- #6026 - the jvm DEBUG flag is not working org.eclipse.jetty.LEVEL=DEBUG
- #6034 - SslContextFactory may select a wildcard certificate during SNI selection when a more specific SSL certificate is present
- #6037 - Review logging modules for j.u.l.
- #6063 - Allow override of hazelcast version when using module
- #6076 - Embedded Jetty throws null pointer exception
- #6082 - SslConnection compacting
- #6085 - Jetty keeps Sessions in use after "Duplicate valid session cookies" Message
11.0.1
Changelog
- This release addresses and resolves CVE-2020-27223
- #5993 - Change more modules to glassfish-jstl
- #5941 - Use jakarta.servlet.jsp.jstl version 2 implementation from Eclipse Glassfish
- #5901 - Starting Jetty with JPMS produces warnings about Servlet resources not found
- #5761 - Remove unneeded dependencies from apache-jsp module
- #5759 - Update jakarta transaction, mail and injection apis
- #5752 - Fix Servlet 5 Schema redirects
11.0.0
Eclipse Jetty 11.x Highlights
- Jetty 11.x has a minimum Java requirement of Java 11.
- Jetty 11.x modules are proper JPMS modules with
module-info.class.- Jetty 11.x supports the following technology specs (from the Jakarta EE 9 effort):
... (truncated)
Commits
14ed9a5Updating to version 11.0.261b5e1arevert back to 11.0.2-SNAPSHOT03f6a31Merge remote-tracking branch 'origin/jetty-10.0.x' into jetty-11.0.xb68a5feMerge pull request #6107 from eclipse/jetty-10.0.x-JavaxWebSocketContainerPro...47ec9b1Modify SecureClientContainerExample to use the new getContainer(HttpClient) m...a86a0c2Add static utility methods on container to add and remove beans.57779c6Make the HttpClient getContainer method static on JavaxWebSocketClientContain...e1f2f8cUpdating to version 11.0.3-SNAPSHOT0a126e2Updating to version 11.0.2e04e226Merged branch 'jetty-10.0.x' into 'jetty-11.0.x'.- Additional commits viewable in compare view
Updates jetty-io from 9.3.14.v20161028 to 11.0.2
Release notes
Sourced from jetty-io's releases.
11.0.2
Changelog
⚠️ Important Security related Changes
- CVE-2021-28165 - #6072 - jetty server high CPU when client send data length > 17408
- CVE-2021-28164 - #6101 - Normalize ambiguous URIs
- CVE-2021-28163 - #6102 - Exclude webapps directory from deployment scan
Other Changes
- #4275 - Path Normalization/Traversal - Context Matching
- #5828 - Allow to create a WebSocketContainer passing HttpClient
- #5832 - Ctrl-C after jetty:run produces NoClassDefFoundError
- #5835 - Review Durable Filters, Servlets and Listeners
- #5977 - Cache-Control header set by a filter is override by the value from DefaultServlet configuration
- #5994 - QueuedThreadPool "free" threads
- #5996 - ERROR : No module found to provide logback-impl for logback-access{enabled}
- #5999 - HttpURI ArrayIndexOutOfBounds
- #6001 - Ambiguous URI legacy compliance mode
- #6008 - Allow absolute paths to be provided in start.ini for request log directory.
- #6011 - OSGi Cannot start Jetty with osgi.boot - Configurations add wrong method taken
- #6020 - Review Jetty Maven Plugin scanning defaults
- #6021 - Standardize Path resolution in XmlConfiguration
- #6024 - Error starting jetty-10: Provider org.eclipse.jetty.websocket.javax.client.JavaxWebSocketShutdownContainer not found
- #6026 - the jvm DEBUG flag is not working org.eclipse.jetty.LEVEL=DEBUG
- #6034 - SslContextFactory may select a wildcard certificate during SNI selection when a more specific SSL certificate is present
- #6037 - Review logging modules for j.u.l.
- #6063 - Allow override of hazelcast version when using module
- #6076 - Embedded Jetty throws null pointer exception
- #6082 - SslConnection compacting
- #6085 - Jetty keeps Sessions in use after "Duplicate valid session cookies" Message
11.0.1
Changelog
- This release addresses and resolves CVE-2020-27223
- #5993 - Change more modules to glassfish-jstl
- #5941 - Use jakarta.servlet.jsp.jstl version 2 implementation from Eclipse Glassfish
- #5901 - Starting Jetty with JPMS produces warnings about Servlet resources not found
- #5761 - Remove unneeded dependencies from apache-jsp module
- #5759 - Update jakarta transaction, mail and injection apis
- #5752 - Fix Servlet 5 Schema redirects
11.0.0
Eclipse Jetty 11.x Highlights
- Jetty 11.x has a minimum Java requirement of Java 11.
- Jetty 11.x modules are proper JPMS modules with
module-info.class.- Jetty 11.x supports the following technology specs (from the Jakarta EE 9 effort):
... (truncated)
Commits
14ed9a5Updating to version 11.0.261b5e1arevert back to 11.0.2-SNAPSHOT03f6a31Merge remote-tracking branch 'origin/jetty-10.0.x' into jetty-11.0.xb68a5feMerge pull request #6107 from eclipse/jetty-10.0.x-JavaxWebSocketContainerPro...47ec9b1Modify SecureClientContainerExample to use the new getContainer(HttpClient) m...a86a0c2Add static utility methods on container to add and remove beans.57779c6Make the HttpClient getContainer method static on JavaxWebSocketClientContain...e1f2f8cUpdating to version 11.0.3-SNAPSHOT0a126e2Updating to version 11.0.2e04e226Merged branch 'jetty-10.0.x' into 'jetty-11.0.x'.- Additional commits viewable in compare view
Updates jetty-security from 9.3.14.v20161028 to 11.0.2
Release notes
Sourced from jetty-security's releases.
11.0.2
Changelog
⚠️ Important Security related Changes
- CVE-2021-28165 - #6072 - jetty server high CPU when client send data length > 17408
- CVE-2021-28164 - #6101 - Normalize ambiguous URIs
- CVE-2021-28163 - #6102 - Exclude webapps directory from deployment scan
Other Changes
- #4275 - Path Normalization/Traversal - Context Matching
- #5828 - Allow to create a WebSocketContainer passing HttpClient
- #5832 - Ctrl-C after jetty:run produces NoClassDefFoundError
- #5835 - Review Durable Filters, Servlets and Listeners
- #5977 - Cache-Control header set by a filter is override by the value from DefaultServlet configuration
- #5994 - QueuedThreadPool "free" threads
- #5996 - ERROR : No module found to provide logback-impl for logback-access{enabled}
- #5999 - HttpURI ArrayIndexOutOfBounds
- #6001 - Ambiguous URI legacy compliance mode
- #6008 - Allow absolute paths to be provided in start.ini for request log directory.
- #6011 - OSGi Cannot start Jetty with osgi.boot - Configurations add wrong method taken
- #6020 - Review Jetty Maven Plugin scanning defaults
- #6021 - Standardize Path resolution in XmlConfiguration
- #6024 - Error starting jetty-10: Provider org.eclipse.jetty.websocket.javax.client.JavaxWebSocketShutdownContainer not found
- #6026 - the jvm DEBUG flag is not working org.eclipse.jetty.LEVEL=DEBUG
- #6034 - SslContextFactory may select a wildcard certificate during SNI selection when a more specific SSL certificate is present
- #6037 - Review logging modules for j.u.l.
- #6063 - Allow override of hazelcast version when using module
- #6076 - Embedded Jetty throws null pointer exception
- #6082 - SslConnection compacting
- #6085 - Jetty keeps Sessions in use after "Duplicate valid session cookies" Message
11.0.1
Changelog
- This release addresses and resolves CVE-2020-27223
- #5993 - Change more modules to glassfish-jstl
- #5941 - Use jakarta.servlet.jsp.jstl version 2 implementation from Eclipse Glassfish
- #5901 - Starting Jetty with JPMS produces warnings about Servlet resources not found
- #5761 - Remove unneeded dependencies from apache-jsp module
- #5759 - Update jakarta transaction, mail and injection apis
- #5752 - Fix Servlet 5 Schema redirects
11.0.0
Eclipse Jetty 11.x Highlights
- Jetty 11.x has a minimum Java requirement of Java 11.
- Jetty 11.x modules are proper JPMS modules with
module-info.class.- Jetty 11.x supports the following technology specs (from the Jakarta EE 9 effort):
... (truncated)
Commits
14ed9a5Updating to version 11.0.261b5e1arevert back to 11.0.2-SNAPSHOT03f6a31Merge remote-tracking branch 'origin/jetty-10.0.x' into jetty-11.0.xb68a5feMerge pull request #6107 from eclipse/jetty-10.0.x-JavaxWebSocketContainerPro...47ec9b1Modify SecureClientContainerExample to use the new getContainer(HttpClient) m...a86a0c2Add static utility methods on container to add and remove beans.57779c6Make the HttpClient getContainer method static on JavaxWebSocketClientContain...e1f2f8cUpdating to version 11.0.3-SNAPSHOT0a126e2Updating to version 11.0.2e04e226Merged branch 'jetty-10.0.x' into 'jetty-11.0.x'.- Additional commits viewable in compare view
Updates jetty-server from 9.3.14.v20161028 to 11.0.2
Release notes
Sourced from jetty-server's releases.
11.0.2
Changelog
⚠️ Important Security related Changes
- CVE-2021-28165 - #6072 - jetty server high CPU when client send data length > 17408
- CVE-2021-28164 - #6101 - Normalize ambiguous URIs
- CVE-2021-28163 - #6102 - Exclude webapps directory from deployment scan
Other Changes
- #4275 - Path Normalization/Traversal - Context Matching
- #5828 - Allow to create a WebSocketContainer passing HttpClient
- #5832 - Ctrl-C after jetty:run produces NoClassDefFoundError
- #5835 - Review Durable Filters, Servlets and Listeners
- #5977 - Cache-Control header set by a filter is override by the value from DefaultServlet configuration
- #5994 - QueuedThreadPool "free" threads
- #5996 - ERROR : No module found to provide logback-impl for logback-access{enabled}
- #5999 - HttpURI ArrayIndexOutOfBounds
- #6001 - Ambiguous URI legacy compliance mode
- #6008 - Allow absolute paths to be provided in start.ini for request log directory.
- #6011 - OSGi Cannot start Jetty with osgi.boot - Configurations add wrong method taken
- #6020 - Review Jetty Maven Plugin scanning defaults
- #6021 - Standardize Path resolution in XmlConfiguration
- #6024 - Error starting jetty-10: Provider org.eclipse.jetty.websocket.javax.client.JavaxWebSocketShutdownContainer not found
- #6026 - the jvm DEBUG flag is not working org.eclipse.jetty.LEVEL=DEBUG
- #6034 - SslContextFactory may select a wildcard certificate during SNI selection when a more specific SSL certificate is present
- #6037 - Review logging modules for j.u.l.
- #6063 - Allow override of hazelcast version when using module
- #6076 - Embedded Jetty throws null pointer exception
- #6082 - SslConnection compacting
- #6085 - Jetty keeps Sessions in use after "Duplicate valid session cookies" Message
11.0.1
Changelog
- This release addresses and resolves CVE-2020-27223
- #5993 - Change more modules to glassfish-jstl
- #5941 - Use jakarta.servlet.jsp.jstl version 2 implementation from Eclipse Glassfish
- #5901 - Starting Jetty with JPMS produces warnings about Servlet resources not found
- #5761 - Remove unneeded dependencies from apache-jsp module
- #5759 - Update jakarta transaction, mail and injection apis
- #5752 - Fix Servlet 5 Schema redirects
11.0.0
Eclipse Jetty 11.x Highlights
- Jetty 11.x has a minimum Java requirement of Java 11.
- Jetty 11.x modules are proper JPMS modules with
module-info.class.- Jetty 11.x supports the following technology specs (from the Jakarta EE 9 effort):
... (truncated)
Commits
14ed9a5Updating to version 11.0.261b5e1arevert back to 11.0.2-SNAPSHOT03f6a31Merge remote-tracking branch 'origin/jetty-10.0.x' into jetty-11.0.xb68a5feMerge pull request #6107 from eclipse/jetty-10.0.x-JavaxWebSocketContainerPro...47ec9b1Modify SecureClientContainerExample to use the new getContainer(HttpClient) m...a86a0c2Add static utility methods on container to add and remove beans.57779c6Make the HttpClient getContainer method static on JavaxWebSocketClientContain...e1f2f8cUpdating to version 11.0.3-SNAPSHOT0a126e2Updating to version 11.0.2e04e226Merged branch 'jetty-10.0.x' into 'jetty-11.0.x'.- Additional commits viewable in compare view
Updates jetty-servlets from 9.3.14.v20161028 to 11.0.2
Release notes
Sourced from jetty-servlets's releases.
11.0.2
Changelog
⚠️ Important Security related Changes
- CVE-2021-28165 - #6072 - jetty server high CPU when client send data length > 17408
- CVE-2021-28164 - #6101 - Normalize ambiguous URIs
- CVE-2021-28163 - #6102 - Exclude webapps directory from deployment scan
Other Changes
- #4275 - Path Normalization/Traversal - Context Matching
- #5828 - Allow to create a WebSocketContainer passing HttpClient
- #5832 - Ctrl-C after jetty:run produces NoClassDefFoundError
- #5835 - Review Durable Filters, Servlets and Listeners
- #5977 - Cache-Control header set by a filter is override by the value from DefaultServlet configuration
- #5994 - QueuedThreadPool "free" threads
- #5996 - ERROR : No module found to provide logback-impl for logback-access{enabled}
- #5999 - HttpURI ArrayIndexOutOfBounds
- #6001 - Ambiguous URI legacy compliance mode
- #6008 - Allow absolute paths to be provided in start.ini for request log directory.
- #6011 - OSGi Cannot start Jetty with osgi.boot - Configurations add wrong method taken
- #6020 - Review Jetty Maven Plugin scanning defaults
- #6021 - Standardize Path resolution in XmlConfiguration
- #6024 - Error starting jetty-10: Provider org.eclipse.jetty.websocket.javax.client.JavaxWebSocketShutdownContainer not found
- #6026 - the jvm DEBUG flag is not working org.eclipse.jetty.LEVEL=DEBUG
- #6034 - SslContextFactory may select a wildcard certificate during SNI selection when a more specific SSL certificate is present
- #6037 - Review logging modules for j.u.l.
- #6063 - Allow override of hazelcast version when using module
- #6076 - Embedded Jetty throws null pointer exception
- #6082 - SslConnection compacting
- #6085 - Jetty keeps Sessions in use after "Duplicate valid session cookies" Message
11.0.1
Changelog
- This release addresses and resolves CVE-2020-27223
- #5993 - Change more modules to glassfish-jstl
- #5941 - Use jakarta.servlet.jsp.jstl version 2 implementation from Eclipse Glassfish
- #5901 - Starting Jetty with JPMS produces warnings about Servlet resources not found
- #5761 - Remove unneeded dependencies from apache-jsp module
- #5759 - Update jakarta transaction, mail and injection apis
- #5752 - Fix Servlet 5 Schema redirects
11.0.0
Eclipse Jetty 11.x Highlights
- Jetty 11.x has a minimum Java requirement of Java 11.
- Jetty 11.x modules are proper JPMS modules with
module-info.class.- Jetty 11.x supports the following technology specs (from the Jakarta EE 9 effort):
... (truncated)
Commits
14ed9a5Updating to version 11.0.261b5e1arevert back to 11.0.2-SNAPSHOT03f6a31Merge remote-tracking branch 'origin/jetty-10.0.x' into jetty-11.0.xb68a5feMerge pull request #6107 from eclipse/jetty-10.0.x-JavaxWebSocketContainerPro...47ec9b1Modify SecureClientContainerExample to use the new getContainer(HttpClient) m...a86a0c2Add static utility methods on container to add and remove beans.57779c6Make the HttpClient getContainer method static on JavaxWebSocketClientContain...e1f2f8cUpdating to version 11.0.3-SNAPSHOT0a126e2Updating to version 11.0.2e04e226Merged branch 'jetty-10.0.x' into 'jetty-11.0.x'.- Additional commits viewable in compare view
Updates jetty-util from 9.3.14.v20161028 to 11.0.2
Release notes
Sourced from jetty-util's releases.
11.0.2
Changelog
⚠️ Important Security related Changes
- CVE-2021-28165 - #6072 - jetty server high CPU when client send data length > 17408
- CVE-2021-28164 - #6101 - Normalize ambiguous URIs
- CVE-2021-28163 - #6102 - Exclude webapps directory from deployment scan
Other Changes
- #4275 - Path Normalization/Traversal - Context Matching
- #5828 - Allow to create a WebSocketContainer passing HttpClient
- #5832 - Ctrl-C after jetty:run produces NoClassDefFoundError
- #5835 - Review Durable Filters, Servlets and Listeners
- #5977 - Cache-Control header set by a filter is override by the value from DefaultServlet configuration
- #5994 - QueuedThreadPool "free" threads
- #5996 - ERROR : No module found to provide logback-impl for logback-access{enabled}
- #5999 - HttpURI ArrayIndexOutOfBounds
- #6001 - Ambiguous URI legacy compliance mode
- #6008 - Allow absolute paths to be provided in start.ini for request log directory.
- #6011 - OSGi Cannot start Jetty with osgi.boot - Configurations add wrong method taken
- #6020 - Review Jetty Maven Plugin scanning defaults
- #6021 - Standardize Path resolution in XmlConfiguration
- #6024 - Error starting jetty-10: Provider org.eclipse.jetty.websocket.javax.client.JavaxWebSocketShutdownContainer not found
- #6026 - the jvm DEBUG flag is not working org.eclipse.jetty.LEVEL=DEBUG
- #6034 - SslContextFactory may select a wildcard certificate during SNI selection when a more specific SSL certificate is present
- #6037 - Review logging modules for j.u.l.
- #6063 - Allow override of hazelcast version when using module
- #6076 - Embedded Jetty throws null pointer exception
- #6082 - SslConnection compacting
- #6085 - Jetty keeps Sessions in use after "Duplicate valid session cookies" Message
11.0.1
Changelog
- This release addresses and resolves CVE-2020-27223
- #5993 - Change more modules to glassfish-jstl
- #5941 - Use jakarta.servlet.jsp.jstl version 2 implementation from Eclipse Glassfish
- #5901 - Starting Jetty with JPMS produces warnings about Servlet resources not found
- #5761 - Remove unneeded dependencies from apache-jsp module
- #5759 - Update jakarta transaction, mail and injection apis
- #5752 - Fix Servlet 5 Schema redirects
11.0.0
Eclipse Jetty 11.x Highlights
- Jetty 11.x has a minimum Java requirement of Java 11.
- Jetty 11.x modules are proper JPMS modules with
module-info.class.- Jetty 11.x supports the following technology specs (from the Jakarta EE 9 effort):
... (truncated)
Commits
14ed9a5Updating to version 11.0.261b5e1arevert back to 11.0.2-SNAPSHOT03f6a31Merge remote-tracking branch 'origin/jetty-10.0.x' into jetty-11.0.xb68a5feMerge pull request #6107 from eclipse/jetty-10.0.x-JavaxWebSocketContainerPro...47ec9b1Modify SecureClientContainerExample to use the new getContainer(HttpClient) m...a86a0c2Add static utility methods on container to add and remove beans.57779c6Make the HttpClient getContainer method static on JavaxWebSocketClientContain...e1f2f8cUpdating to version 11.0.3-SNAPSHOT0a126e2Updating to version 11.0.2e04e226Merged branch 'jetty-10.0.x' into 'jetty-11.0.x'.- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)@dependabot use these labelswill set the current labels as the default for future PRs for this repo and language@dependabot use these reviewerswill set the current reviewers as the default for future PRs for this repo and language@dependabot use these assigneeswill set the current assignees as the default for future PRs for this repo and language@dependabot use this milestonewill set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page.