Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Java (and maybe Tomcat) version #4106

Closed
matthias-ronge opened this issue Nov 25, 2020 · 5 comments
Closed

Update Java (and maybe Tomcat) version #4106

matthias-ronge opened this issue Nov 25, 2020 · 5 comments
Labels
dependencies Pull requests that update a dependency file security

Comments

@matthias-ronge
Copy link
Collaborator

matthias-ronge commented Nov 25, 2020

Java 8 has run out of support at the end of 2020. Current Java version at the time of writing is 14, or 11 LTS. Probably the Tomcat version also needs to be increased.

@matthias-ronge matthias-ronge added 3.x dependencies Pull requests that update a dependency file labels Nov 25, 2020
@henning-gerhardt
Copy link
Collaborator

For Tomcat update see #2929. Ignored since a long time :-(

@matthias-ronge
Copy link
Collaborator Author

I added the security badge because Java 8 is no longer receiving updates, so running Production on Java 8 must now be considered insecure.

@henning-gerhardt
Copy link
Collaborator

Oracle stopped Java 8 public updates in January 2019 for commercial usage but indefinitely for personal usage. Some forks like AdoptOpenJDK will provide support until May 2026.

You can run 3.x on Java 11 but can not compile it as some build requirements are removed from OpenJDK 11 package.

@matthias-ronge
Copy link
Collaborator Author

I can confirm: Production 3 is running here on an Ubuntu 18 under OpenJDK 11. (I wasn't even aware of that.) Redhat states the end of support for OpenJDK 11 for October 2024, for OpenJDK 8 even for May 2026. Those who are already using OpenJDK 11 would then have to carry out a version downgrade, with everything that means.

I'll leave the security label in place as a reminder that everyone here has to check which JVM version and update strategy the used distribution is using to ensure that this is secured.

@Kathrin-Huber Kathrin-Huber mentioned this issue Feb 18, 2021
5 tasks
@Kathrin-Huber
Copy link
Contributor

is updated

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file security
Projects
None yet
Development

No branches or pull requests

3 participants