RE: Subscribe to Security Advisories

2025-01-21 Thread Valentijn Scholten
:27 To: users@activemq.apache.org Subject: Re: Subscribe to Security Advisories You don't often get email from jbert...@apache.org<mailto:jbert...@apache.org>. Learn why this is important<https://aka.ms/LearnAboutSenderIdentification> Part of the official process [1] is that when a

Re: Subscribe to Security Advisories

2025-01-21 Thread Justin Bertram
Part of the official process [1] is that when a release contains a fix for a CVE then the CVE is announced to the same list(s) where the release announcement is sent (which includes the dev and users list). However, sometimes that process is not completed properly. You said that none of the issues