Java Buildpack v4.43
I'm pleased to announce the release of the java-buildpack, version 4.43. This release focuses on bug fixes, including new Java quarterly updates for versions 8, 11, and 17.
- Relax escaping of values to enable limited access to the shell for AppDynamnics config (#911)
- Version matcher now prefers a specific match over a partial match (#907)
- Shell escape the value of Elastic APM custom properties (#908)
- Modify default Tomcat configuration to include HTTP/2 support (#906)
- Rename framework-seeker-security-provider.md (via @mureinik #910)
- Notable updated Dependencies
- Java Quarterly Updates Oct 2021
- Apache Tomcat 9.0.54 which resolves CVE-2021-42340
For a more detailed look at the changes in 4.43, please take a look at the commit log. The packaged version of the buildpack, suitable for use with create-buildpack and update-buildpack, can be found attached to this release.
Packaged Dependencies
| Dependency | Version | CVEs | Release Notes |
|---|---|---|---|
| AppDynamics Agent | 21.10.0_33144 |
Release Notes | |
| Azure Application Insights Agent | 2.6.2 |
||
| CA Introscope APM Framework | 21.6.0_28 |
||
| Client Certificate Mapper | 1.11.0_RELEASE |
Included inline above | Included inline above |
| Container Security Provider | 1.19.0_RELEASE |
Included inline above | Included inline above |
| Contrast Security Agent | 3.8.9_22663 |
Release Notes | |
| Datadog APM Javaagent | 0.89.0 |
Release Notes | |
| Elastic APM Agent | 1.26.0 |
Release Notes | |
| Gemalto Luna Security Provider | 7.4.0 |
Release Notes | |
| Gemalto ProtectApp Security Provider | 8.4.0 |
||
| Geode Tomcat Session Store | 1.11.0 |
||
| Google Stackdriver Debugger | 2.29.0 |
Release Notes | |
| Google Stackdriver Profiler | 0.1.0 |
Release Notes | |
| Groovy | 2.5.15 |
Release Notes | |
| JaCoCo Agent | 0.8.7 |
Release Notes | |
| Java Memory Assistant Agent | 0.5.0 |
||
| Java Memory Assistant Clean Up | 0.1.0 |
||
| JProfiler Profiler | 11.1.4 |
ChangeLog | |
| JRebel Agent | 2021.4.0 |
ChangeLog | |
| jvmkill Agent | 1.16.0_RELEASE |
Included inline above | Included inline above |
| MariaDB JDBC Driver | 2.7.2 |
Release Notes | |
| Memory Calculator | 3.13.0_RELEASE |
Included inline above | Included inline above |
| Metric Writer | 3.5.0_RELEASE |
Included inline above | Included inline above |
| New Relic Agent | 7.3.0 |
Release Notes | |
| OpenJDK JRE | 1.8.0_312 |
Risk Matrix | Release Notes |
| OpenJDK JRE 11 | 11.0.13_8 |
Risk Matrix | Release Notes |
| OpenJDK JRE 17 | 17.0.1_12 |
Risk Matrix | Release Notes |
| PostgreSQL JDBC Driver | 42.3.0 |
ChangeLog | |
| Redis Session Store | 1.3.6_RELEASE |
Included inline above | Included inline above |
| Riverbed Appinternals Agent | 11.8.5_BL527 |
||
| SeaLights Agent | 3.1.1995 |
||
| SkyWalking | 6.6.0 |
ChangeLog | |
| Spring Auto-reconfiguration | 2.12.0_RELEASE |
Included inline above | Included inline above |
| Spring Boot CLI | 2.5.6 |
||
| Spring Boot Container Customizer | 2.6.0_RELEASE |
Included inline above | Included inline above |
| Takipi Agent | 4.63.0 |
Release Notes | |
| Tomcat | 9.0.54 |
Security | ChangeLog |
| Tomcat Access Logging Support | 3.3.0_RELEASE |
Included inline above | Included inline above |
| Tomcat Lifecycle Support | 3.3.0_RELEASE |
Included inline above | Included inline above |
| Tomcat Logging Support | 3.3.0_RELEASE |
Included inline above | Included inline above |
| YourKit Profiler | 2021.3.233 |
Release Notes |