[ubuntu/resolute-updates] tomcat10 10.1.55-1ubuntu2~26.04.1 (Accepted)

Timo Aaltonen tjaalton at ubuntu.com
Thu Jul 9 18:43:11 UTC 2026


tomcat10 (10.1.55-1ubuntu2~26.04.1) resolute; urgency=medium

  * Backport to Resolute (LP: #2155817)

tomcat10 (10.1.55-1ubuntu2) stonking; urgency=medium

  * debian/tomcat10-common.links: Fixed jakartaee-migration-shaded.jar
    source location

tomcat10 (10.1.55-1ubuntu1) stonking; urgency=medium

  * Merge with Debian unstable (LP: #2155606). Remaining changes:
    - Restored tomcat10 server packages since dropped in 10.1.52-2
      (LP: 2154326)
      + Depend on libtcnative-2 instead of libtcnative-1
    - Added autopkgtest integrations:
      + Smoke-tests for default webapp and tomcat-native.
      + Enabled JUnit testing to work with autopkgtest.
  * New Changes:
    - Install jakartaee-migration-shaded.jar into the Tomcat lib directory
      (Closes: #1108280)
    - Fixed up various bugs due to historical packaging.
      Thanks to Utkarsh Gupta <utkarsh.gupta at canonical.com> (LP: #2155105)
      + debian/sysuser/tomcat11.conf: User home directory was inconsistent
        with CATALINA_BASE, changed to /nonexistent
      + debian/tomcat11.dirs: Removed empty dir creation of etc/logrotate.d
        as it is handled by ucf from template
      + debian/tomcat11.postrm.in: Added leading / to
        /var/lib/tomcat11/lib/classes since should be an absolute path
      + debian/README.Debian: Added some comments regarding historical
        packaging notes.
        - tomcat user is shared by tomcatXX packages
        - tomcat log rotation

tomcat10 (10.1.55-1) unstable; urgency=medium

  * New upstream version 10.1.55.
    - The source package includes the security fixes for the following reported
      vulnerabilities: CVE-2026-41284, CVE-2026-41293, CVE-2026-42498,
      CVE-2026-43512, CVE-2026-43513, CVE-2026-43514, CVE-2026-43515.
      Debian dropped the server packages in 10.1.52-2 thus these issues are no
      longer relevant for sid and forky.
  * Refresh the patches.

tomcat10 (10.1.54-1ubuntu2) stonking; urgency=medium

  * Added autopkgtest integrations:
    - Smoke-tests for default webapp and tomcat-native.
    - Enabled JUnit testing to work with autopkgtest.

tomcat10 (10.1.54-1ubuntu1) stonking; urgency=medium

  * Restored tomcat10 server packages since dropped in 10.1.52-2 (LP: #2154326)
    - Depend on libtcnative-2 instead of libtcnative-1

tomcat10 (10.1.54-1) unstable; urgency=medium

  * New upstream release
    - Refreshed the patches
    - New build dependency on Bouncy Castle

tomcat10 (10.1.52-2) unstable; urgency=medium

  * Drop tomcat10 server packages because only one Tomcat version is supported
    per release. Only retain libtomcat10-java because of compatibility reasons
    for now. Users are strongly encouraged to switch to Tomcat 11 instead.
  * Standards-Version updated to 4.7.4

tomcat10 (10.1.52-1) unstable; urgency=medium

  * New upstream version 10.1.52.
   - Fix CVE-2025-61795: denial-of-service (Closes: #1119294)
   - Fix CVE-2025-48989: "made you reset attack" (Closes: #1111096)
  * Declare compliance with Debian Policy 4.7.3.
  * Refresh the patches.

tomcat10 (10.1.46-1) unstable; urgency=medium

  * New upstream release
    - Refreshed the patches

Date: 2026-06-23 20:14:10.389159+00:00
Changed-By: Reuben Roessler <reuben.roessler at canonical.com>
Signed-By: Timo Aaltonen <tjaalton at ubuntu.com>
https://launchpad.net/ubuntu/+source/tomcat10/10.1.55-1ubuntu2~26.04.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Resolute-changes mailing list