Sync jetty 6.1.20-1 (universe) from Debian unstable (main)

Bug #425561 reported by Dominic Evans
This bug report is a duplicate of:  Bug #131570: update to Jetty 6.x. Edit Remove
12
This bug affects 1 person
Affects Status Importance Assigned to Milestone
jetty (Ubuntu)
Triaged
Wishlist
Unassigned

Bug Description

Please sync jetty 6.1.20-1 (universe) from Debian unstable (main). This
should also be used to fix bug 312824 as they include the migration of
jetty to main in debian.

Changelog entries since current karmic version 5.1.14-1:

jetty (6.1.20-1) unstable; urgency=medium

  [ Niels Thykier ]
  * New upstream release.
  * Stop using Build-Depends-Indep, since the policy and the build
    daemons disagree on when it should be used (Closes: #540861).
  * Corrected jetty.install to reflect the move of some license files
    in the source tree.
  * Bumped to Standard-Versions 3.8.3 - no changes required.
  * Updated jetty.post{install,rm} scripts to use "set -e" instead of
    passing it to sh.
  * Installed "VERSION.txt" as upstream changelog.
  * A previous version (6.1.18-1) fixed the following security problems, which
    were not mentioned in the changelog: CVE-2007-5613, CVE-2007-5614,
    CVE-2007-5615, CVE-2009-1523, and CVE-2009-1524 (see below for more
    information).

  [ Torsten Werner ]
  * Set urgency to medium because this version fixes a FTBFS.

 -- Torsten Werner <email address hidden> Sun, 06 Sep 2009 23:06:45 +0200

jetty (6.1.19-2) unstable; urgency=low

  * Upload to unstable.

 -- Torsten Werner <email address hidden> Sun, 09 Aug 2009 08:48:10 +0200

jetty (6.1.19-1) experimental; urgency=low

  [ Ludovic Claude ]
  * New upstream release fixing a security vulnerability
    (cookies are not secure if you are running behind a netscaler)
  * Remove the bootstrap patch as it has been added upstream and update
    the build to use the new start-daemon component
  * Remove the Build-Depend on quilt as the patch is not needed anymore.
  * Add the Maven POM to the package
  * Add a Build-Depends dependency on maven-repo-helper
  * Use mh_installpom and mh_installjar to install the POM and the jar to the
    Maven repository
  * Add optional support for web applications located in /usr/share/webapps.
  * Add a cron job that cleans up the old log files in /var/log/jetty.
  * Register the Javadoc into Debian documentation and put it in a
    separate package (libjetty-java-doc)
  * Use openjdk-6-jdk for the build; add a Build-Depends on this
    package. Required to build the javadoc.
  * Update debian/copyright (patch provided by Jan Pascal Vanbest
    <email address hidden>)

  [ Torsten Werner ]
  * Add myself to Uploaders.
  * Update Standards-Version: 3.8.2.
  * Move package libjetty-java-doc to Section: doc.
  * Fix init script: check for /etc/default/rcS before reading it.

 -- Torsten Werner <email address hidden> Tue, 14 Jul 2009 11:50:43 +0200

jetty (6.1.18-1) unstable; urgency=low

  [Ludovic Claude]
  * Add myself to Uploaders
  * Change the build dependency on java-gcj to default-jdk
  * Add init.d startup script
  * Add dependencies on ant, libslf4j-java, libxerces2-java, libtomcat6-java
    for libjetty-extra-java, add links for the lib folder
  * Add dependency on jsvc to run jetty as a daemon
  * Add the package libjetty-setuid-java for the Setuid module (with native
    code)
  * Add an index page used when Jetty starts
  * Use latest jasper from Tomcat to provide jsp 2.1 instead of
    Glassfish JSP implementation as in the standard distribution
  * Add tools.jar to the classpath to be able to run JSP (Closes: #452586)
  * Fix Lintian warnings: add ${misc:Depends} to all Depends:
  * Move jetty to main as all its dependencies are in main,
    and jetty contains only code that complies with Debian guidelines,
    use java section like tomcat6
    (Closes: #498582)
  * Do not depend on tomcat 5.5 (Closes: #530720, #458399)
  * Remove empty prerm and preinst scripts
  * Remove old patches that don't apply anymore
  * Update copyright and remove full text of Apache license
  * Bump up compat to 6 and Standards-Version to 3.8.1

  [David Yu]
  * New upstream release for jetty
    (Closes: #528389, #527571, #454529, #425152).
  * Fixed jetty.links. Now delegates install of start.jar to libjetty-java.

 -- Ludovic Claude <email address hidden> Fri, 12 Jun 2009 17:19:08 +0100

Revision history for this message
Daniel Holbach (dholbach) wrote :

We're in Feature Freeze already, can you say a bit more about the new release?

https://wiki.ubuntu.com/FreezeExceptionProcess

Revision history for this message
Dominic Evans (oldmanuk) wrote :

Its hard to describe 4 years of development changes in a bug report :) but I've attached the changelog.diff between the two versions. Suffice to say the existing jetty package in karmic can be considered legacy.

The important reasons for getting the update into karmic are not necessarily the code changes in jetty, but the build and dependency changes that ensure it contains only code that complies with Debian guidelines and builds entirely using dependencies in main (hence allowing it to be included in main as well). This is groundwork for the future as it will allow other package updates (notable eclipse bug 312824) to depend on jetty whilst also remaining compliant with Debian guidelines.

Revision history for this message
Torsten Werner (twerner) wrote :

I think that all versions of jetty < 5 got removed from all versions of Debian due to security problems. BTW, we have 6.1.20-1 in Debian/unstable.

Revision history for this message
Torsten Werner (twerner) wrote :

ahem: ... all versions of jetty < 6 got removed...

Revision history for this message
Dominic Evans (oldmanuk) wrote :
summary: - Sync jetty 6.1.19-2 (universe) from Debian unstable (main)
+ Sync jetty 6.1.20-1 (universe) from Debian unstable (main)
description: updated
Revision history for this message
Thierry Carrez (ttx) wrote :

We have a jetty6 package in karmic/main that provides Jetty 6 libraries.

Convergence from the current jetty6 and jetty packages to a single jetty package in sync with Debian (and in main) is a karmic+1 (Lucid) objective.

Changed in jetty (Ubuntu):
milestone: none → later
importance: Undecided → Wishlist
status: New → Triaged
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.