[prev in list] [next in list] [prev in thread] [next in thread] 

List:       jakarta-commons-dev
Subject:    svn commit: r49103 - /release/commons/compress/RELEASE-NOTES.txt
From:       ggregory () apache ! org
Date:       2021-07-31 13:10:42
Message-ID: 20210731131043.19EC017DDF8 () svn01-us-east ! apache ! org
[Download RAW message or body]

Author: ggregory
Date: Sat Jul 31 13:10:42 2021
New Revision: 49103

Log:
Update release notes for COMPRESS-404.

Modified:
    release/commons/compress/RELEASE-NOTES.txt

Modified: release/commons/compress/RELEASE-NOTES.txt
==============================================================================
--- release/commons/compress/RELEASE-NOTES.txt (original)
+++ release/commons/compress/RELEASE-NOTES.txt Sat Jul 31 13:10:42 2021
@@ -8,16 +8,17 @@ Brotli, Zstandard and ar, cpio, jar, tar
 Release 1.21
 ------------
 
-Compress 1.20 now at least requires Java 8 to build and run.
+Compress 1.21 is the first release to require Java 8 to build and run.
 
-SevenZFileOptions has a new setting that needs to be enabled explicity
-if SevenZFile should try to recover broken archives - a feature
-introduced with Commons Compress 1.19. This is a breaking change if
-you relied on the recovery attempt.
+SevenZFileOptions has a new setting that needs to be enabled
+explicitly if SevenZFile should try to recover broken archives - a
+feature introduced with Commons Compress 1.19. This is a breaking
+change if you relied on the recovery attempt. The change was made to
+detect broken archives sooner, and to mitigate the OOM exploit.
 
-Several formats may now throw IOExceptions when reading broken
-archives or streams that would have caused arbitrary RuntimeExceptions
-in earlier versions of Compress.
+Several formats now throw IOExceptions when reading broken archives or
+streams that would have caused arbitrary RuntimeExceptions in earlier
+versions of Compress.
 
 New features:
 o Add writePreamble to ZipArchiveInputStream. This method could


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic