Skip to content

Update Jetty to 9.4.58.v20250814 - #10203

Merged
zbynek merged 11 commits into
gwtproject:mainfrom
Lonzak:main
Dec 21, 2025
Merged

zbynek merged 11 commits into
gwtproject:mainfrom
Lonzak:main

Conversation

@Lonzak

@Lonzak Lonzak commented Dec 3, 2025

Copy link
Copy Markdown
Contributor

This pull requests updates the jetty libraries due to a security issue. I know that gwt-dev is not for production code however explain this to the security guys ;-)

There is a related PR in the gwt-tools project as well.

Please note, that the checks are failing since the libs are missing from the gwt-tools project. I think there is no way to link both project's here.

@niloc132

niloc132 commented Dec 3, 2025

Copy link
Copy Markdown
Member

Thanks! You can temporarily edit the .github/ yml files to point to your own tools branch, so that this PR can be reviewed on its own, help validate the changes in tools.

@Lonzak

Lonzak commented Dec 4, 2025

Copy link
Copy Markdown
Contributor Author

Ok this was new to me - but got it working...

@zbynek

zbynek commented Dec 4, 2025

Copy link
Copy Markdown
Collaborator

Not sure how important it is to keep the Eclipse config up to date:
https://github.com/gwtproject/gwt/blob/main/eclipse/dev/.classpath
(some dependency PRs update it, others don't)

@zbynek zbynek added the ready This PR has been reviewed by a maintainer and is ready for a CI run. label Dec 4, 2025
@zbynek

zbynek commented Dec 4, 2025

Copy link
Copy Markdown
Collaborator

(ready label is just to get a full test run on this, obviously this can be only merged after gwtproject/tools#38)

@Lonzak

Lonzak commented Dec 5, 2025

Copy link
Copy Markdown
Contributor Author

Not sure how important it is to keep the Eclipse config up to date: https://github.com/gwtproject/gwt/blob/main/eclipse/dev/.classpath (some dependency PRs update it, others don't)

Thanks - missed that. Already fixed.

zbynek
zbynek previously approved these changes Dec 5, 2025
niloc132 pushed a commit to gwtproject/tools that referenced this pull request Dec 14, 2025

@niloc132 niloc132 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good so far, thanks for doing this. I've merged the tools change, so the CI tweaks can be reverted and we can land this?

@Lonzak

Lonzak commented Dec 14, 2025

Copy link
Copy Markdown
Contributor Author

Yes I would say so...

@zbynek zbynek changed the title Security related update of jetty and jetty related libraries Update Jetty to 9.4.58.v20250814 Dec 15, 2025

@niloc132 niloc132 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

With these reverted, I think we can do another build and merge?

Comment thread .github/workflows/full-check.yml Outdated
Comment thread .github/workflows/full-check.yml Outdated
Comment thread .github/workflows/quick-check.yml Outdated
Comment thread .github/workflows/quick-check.yml Outdated
Co-authored-by: Colin Alworth <colin@vertispan.com>
zbynek and others added 3 commits December 21, 2025 09:59
Co-authored-by: Colin Alworth <colin@vertispan.com>
Co-authored-by: Colin Alworth <colin@vertispan.com>
Co-authored-by: Colin Alworth <colin@vertispan.com>
Comment thread .github/workflows/full-check.yml Outdated
Comment thread .github/workflows/quick-check.yml Outdated
@zbynek
zbynek requested a review from niloc132 December 21, 2025 12:20
@zbynek
zbynek merged commit 0704a33 into gwtproject:main Dec 21, 2025
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ready This PR has been reviewed by a maintainer and is ready for a CI run.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants