1. 719edea Fuix checkstyle by Mark Thomas · 17 hours ago main
  2. 7af5cfa Better check for CRL support by Mark Thomas · 18 hours ago
  3. d4c3f29 Skip CRL tests if unsupporterd by Mark Thomas · 36 hours ago
  4. 5eaee22 Require the request to the FORM login action to use HTTP POST by Mark Thomas · 2 days ago
  5. dec85ea Harden CGI servlet against scripts with excessive output on error status by Mark Thomas · 2 days ago
  6. 5ae8ae4 Additional clean-up after HTTP/2 stream reset to aid GC by Mark Thomas · 2 weeks ago
  7. 6d21236 Clear per request error marker when request is recycled by Mark Thomas · 12 days ago
  8. 9c91bba Reject HTTP/1.0 requests with a transfer-encoding header by Mark Thomas · 2 weeks ago
  9. b112274 Add AI generated tests for Listener notification fixes by Mark Thomas · 2 days ago
  10. a8faeb7 Fix BZ 72003. Correct RegistrationListener notifications by Mark Thomas · 2 days ago
  11. 6869b93 Fix broken link by Mark Thomas · 2 days ago
  12. 3a1c06b Refactor JASPIC caching by Mark Thomas · 3 weeks ago
  13. 46394cd Fix OpenSSL with OpenSSL trust, server cert in a keys tore and a CRL by Mark Thomas · 3 weeks ago
  14. 9979b6b Performance optimisation for AJP. Don't swallow body on error conditions by Mark Thomas · 13 days ago
  15. fa50a17 Allow WebSocket request URIs to contain '{' and/or '}' by Mark Thomas · 3 weeks ago
  16. 9c13a7c Cleaner handling of response header message overflow by remm · 3 days ago
  17. a60a945 Reduce CPU usage while sending WebSocket close message by Mark Thomas · 2 weeks ago
  18. 2047cfb Fix possible NPE by Mark Thomas · 3 days ago
  19. 353045f Refactor WebSocket writes to use a consistent per message timeout by Mark Thomas · 3 days ago
  20. 5615d05 Simplify by Mark Thomas · 3 days ago
  21. 0201c6d WebSocket write timeout improvements by Mark Thomas · 3 days ago
  22. 1959db4 Ensure evictions from the static resource cache are in the correct order by Mark Thomas · 3 days ago
  23. 046e3f2 Fix attribute name by remm · 3 days ago
  24. bf95315 WAR URL connection should propagate use of cache by remm · 3 days ago
  25. 98a6956 Fix saving context in server.xml by remm · 3 days ago
  26. 9459890 Undeploy missing context by remm · 3 days ago
  27. bd7828f Stricter OCSP handling when soft-fail is disabled. by Mark Thomas · 3 days ago
  28. f320596 Another robustness improvement for OCSP responses. by Mark Thomas · 3 days ago
  29. eb72baa Make the processing of OCSP responses more robust. by Mark Thomas · 3 days ago
  30. c84b153 Fix jmxproxy URL for tasks by remm · 3 days ago
  31. 4dec7b0 Align OCSP URL parsing with Tomcat Native by Mark Thomas · 3 days ago
  32. af1d293 Use correct length for OID when parsing OCSP URLs by Mark Thomas · 3 days ago
  33. 83c1401 Length validation for ALPN name. More robust certificate verification. by Mark Thomas · 3 days ago
  34. 8b4c51f Java 28-ea appears to not be available yet by Mark Thomas · 3 days ago
  35. 9ee81ab 26 is now GA. Add 27 and 28 EA by Mark Thomas · 4 days ago
  36. 5c2bd00 Simplify - MacOS is now in separate file by Mark Thomas · 4 days ago
  37. d8dcd7d Implement stricter ALPN matching for Connectors using FFM. by Mark Thomas · 4 days ago
  38. 16e3f69 Update bnd to 7.4.0 by Mark Thomas · 4 days ago
  39. cc2a730 Update Checkstyle to 14.1.0 by Mark Thomas · 4 days ago
  40. bfcae2b Update Easymock to 5.7.0 by Mark Thomas · 4 days ago
  41. be0cba7 Follow up to "Improve handshake robustness" by Mark Thomas · 4 days ago
  42. c4afba3 Fix max connections after pause resume by remm · 4 days ago
  43. 36e4df1 Consistency for extension header processing issues by remm · 4 days ago
  44. 6c5a6c0 Improve handshake robustness by remm · 4 days ago
  45. 47faf2b Need to update 1.3.x as well by Mark Thomas · 4 days ago
  46. 0f45084 Update minimum required native version due to new option setting API by Mark Thomas · 4 days ago
  47. 13d470f Update OpenSSL options constants by Mark Thomas · 10 days ago
  48. 1f156f4 Add a warning by Mark Thomas · 4 days ago
  49. e930e96 Only try and load the native library from CATALINA_HOME when it is set by Mark Thomas · 4 days ago
  50. f691d30 Fix Javadoc error and 4 warnings by Mark Thomas · 5 days ago
  51. 6874871 No password is not the same as a password of "" by Mark Thomas · 5 days ago
  52. 0e1cc40 Mark read-only fields as read-only by Mark Thomas · 5 days ago
  53. 242c254 Improve cloud membership robustness by remm · 5 days ago
  54. ec8bca4 Fix compatibility with tag files by remm · 5 days ago
  55. 7b3ba12 Follow-up to resource path validation - align with WebResources by Mark Thomas · 5 days ago
  56. 1553a20 Remove test code. Fix intermittent test failure. by Mark Thomas · 5 days ago
  57. 87fe54f Avoid evaluating twice by remm · 5 days ago
  58. a6184e0 Should be using a direct buffer by Mark Thomas · 5 days ago
  59. 39a989a Fix a regression in HALF_CLOSED_REMOTE unexpected frame handling fix by Mark Thomas · 5 days ago
  60. 679bebf Fix evaluation of some lambda expressions by remm · 5 days ago
  61. 11172f1 Minor user database fixes by remm · 5 days ago
  62. 1f452b4 Validate more lengths in ASN1 by remm · 6 days ago
  63. 7b7565d Avoid exceptions on invalid content-length by remm · 6 days ago
  64. 875c79e Fix incorrect window size when upgrading from HTTP/1.1 by remm · 6 days ago
  65. 3319ae9 Validate resource paths to avoid exceptions by remm · 6 days ago
  66. 6775db6 Fix HALF_CLOSED_REMOTE unexpected frames handling by remm · 6 days ago
  67. 5dbb991 Fix xreflection stack overflow issue found by code review by remm · 6 days ago
  68. 9f98160 Skip certificate logging if SSLContext is null by remm · 9 days ago
  69. e70460d Follow-up "Avoid some scenarios of expiration of never expire sessions" by Mark Thomas · 9 days ago
  70. 0961086 Clarify the meaning of various RewriteValve server variables by Mark Thomas · 9 days ago
  71. 0ec0239 Avoid some scenarios of expiration of never expire sessions by remm · 9 days ago
  72. 579594e Tweak the bloom filter for the root by remm · 9 days ago
  73. aaa3906 Add some clarification to the comments by remm · 9 days ago
  74. b9fafd4 Add best efforts protection for a mis-configured Valve by Mark Thomas · 9 days ago
  75. 07fe0a0 Fix IDE warning by Mark Thomas · 9 days ago
  76. 0c12319 Remove deprecated code by Mark Thomas · 10 days ago
  77. 91f7934 Deprecate unused code by Mark Thomas · 10 days ago
  78. 2506fda Remove deprecated code by Mark Thomas · 10 days ago
  79. d3c07ee Deprecate unused code by Mark Thomas · 10 days ago
  80. 5621372 Remove deprecated code by Mark Thomas · 10 days ago
  81. 818e4fd Deprecate unused code by Mark Thomas · 10 days ago
  82. f819462 Resolve missing back references or variables as empty string by remm · 10 days ago
  83. 3631e85 Improve robustness of o.a.c.core package to system clock jumps by Mark Thomas · 11 days ago
  84. 5437dfa Ensure namespace attributes are XML escaped in WebDAV responses by Mark Thomas · 11 days ago
  85. 8fe274d Improve handling of get[Pooled]Connection(String,String) by Mark Thomas · 11 days ago
  86. a530ce4 Skip tribes membership tests when IP multicast is unavailable (#1052) by Coty Sutherland · 11 days ago
  87. 648009e Skip OCSP tests when responder port is unavailable instead of fail (#1051) by Coty Sutherland · 11 days ago
  88. a42a5db Hardening: Use SecureRandom to generate Sec-WebSocket-Key by Mark Thomas · 12 days ago
  89. 013fa14 Fix broken test by Mark Thomas · 13 days ago
  90. 23aee9a Prevent session swap out if associated with currently active request by Mark Thomas · 13 days ago
  91. 84ac9af Drop backwards compatibility implementation by Mark Thomas · 2 weeks ago
  92. 811636f Fix concurrency issues with session Store load/save by Mark Thomas · 2 weeks ago
  93. e7dc8f0 Code clean-up - re-apply standard formatting by Mark Thomas · 2 weeks ago
  94. 3f7d132 Re-work x-forwarded-proto multiple header fix by Mark Thomas · 2 weeks ago
  95. 4ea7d6d Add some additional validation in RemoteIp[Filter|Valve] by Mark Thomas · 2 weeks ago
  96. a7d9a04 Improve robustness of DIGEST authentication to system clock jumps. by Mark Thomas · 3 weeks ago
  97. 52fd842 Re-apply standard code formatting by Mark Thomas · 3 weeks ago
  98. 9db4555 web.xml logged output should also use decoded URL patterns by Mark Thomas · 3 weeks ago
  99. 4229025 Add SECURITY.md per dev-list discussion 'Considering AI suggestions/guardrails for the tomcat project' (#1001) by Coty Sutherland · 3 weeks ago
  100. 5e19c26 Follow-up to 853b54eb7c by Mark Thomas · 3 weeks ago