- Issued:
- 2024-12-05
- Updated:
- 2024-12-05
RHBA-2024:10676 - Bug Fix Advisory
Synopsis
Red Hat build of Quarkus 3.15.2 release
Type/Severity
Bug Fix Advisory
Topic
An update is now available for Red Hat build of Quarkus.
Description
This release of Red Hat build of Quarkus 3.15.2 includes security updates, bug fixes and enhancements. For more information, see the release notes page listed in the References section.
Solution
Before applying the update, back up your existing installation, including all
applications, configuration files, databases and database settings, and so on.
The References section of this erratum contains a download link for the update.
You must be logged in to download the update.
Affected Products
- Red Hat build of Quarkus Text-Only Advisories x86_64
Fixes
- QUARKUS-5421 - Fix Quarkus plugin syncing
- QUARKUS-5419 - Bump hibernate-orm.version from 6.6.0.Final to 6.6.1.Final, hibernate-reactive.version from 2.4.0.Final to 2.4.1.Final
- QUARKUS-5417 - Properly fail when both http and https servers started on port
- QUARKUS-5414 - Avoid SecurityContextOverrideHandler NPE when user provided custom JAX-RS security context and Quarkus Security is not present
- QUARKUS-5413 - Make media type optional for InputStream when using multipart in REST Client
- QUARKUS-5412 - WebSockets Next: ignore non-websocket connections
- QUARKUS-5411 - Support `@HEAD` and `@OPTIONS` in sub-resources
- QUARKUS-5410 - Make sure Transfer-Encoding set by a Resource is honored
- QUARKUS-5409 - Inherit defaults from Fabric8 kubernetes client defaults
- QUARKUS-5408 - Bump kubernetes-client-bom from 6.13.3 to 6.13.4
- QUARKUS-5406 - Update quarkus-spring-api to 6.1.SP4
- QUARKUS-5405 - Check whether a dependency has resolved paths before setting a component path
- QUARKUS-5404 - Quiet down logs of observability DevResources
- QUARKUS-5403 - Mailer: register default mailer beans correctly
- QUARKUS-5401 - Fixed trust all option after reload (TlsRegistry)
- QUARKUS-5400 - Disable instrumentation according with SDK config
- QUARKUS-5399 - Quarkus Update - Replace \ by / in rewriteFile path on Windows
- QUARKUS-5418 - Use `ChainedLocalRepositoryManager` to support `-Dmaven.repo.local.tail`
- QUARKUS-5397 - WebSockets Next: fix Dev UI for nested endpoint class
- QUARKUS-5389 - Properly test for existence of OtlpMeterRegistry
- QUARKUS-5350 - Fix NoClassDefFoundError when using vertx without http
- QUARKUS-5180 - Unable to run application with kafka-streams on aarch64 built using native builder image
- QUARKUS-5422 - FAQ (frequently asked questions) documentation for extensions
- QUARKUS-5420 - Using reusable workflows in Quarkiverse release process
- QUARKUS-5416 - Add Javadoc for DevMojo#jvmArgs
- QUARKUS-5415 - Use varargs for localRepositoryTail
- QUARKUS-5407 - Qute: improve docs/javadoc about value resolvers ordering
- QUARKUS-5402 - Remove deprecated RunOptions mention in the transactions docs
- QUARKUS-5398 - Add overflow-x scroll
- QUARKUS-5396 - Improve GitHub Actions cache usage
- QUARKUS-5394 - Check self-signed ID token when access token is verified
- QUARKUS-5393 - Qute: fix reload of templates backed by build item
- QUARKUS-5392 - Add note about `ExceptionMapper<ValidationException>` in validation guide
- QUARKUS-5391 - Openapi-swaggerui guide - reference MicroProfile OpenAPI Core configuration
- QUARKUS-5390 - Qute: fix generated ValueResolvers
- QUARKUS-5387 - Split Quarkiverse release into two workflows
- QUARKUS-5386 - Config Doc - Expand enums even if tooltip is not supported
- QUARKUS-5385 - Qute: fix generated ValueResolver for default methods with params
- QUARKUS-5382 - Fix faulty class loader
- QUARKUS-5381 - Add quarkus.hibernate-orm.database.version-check.enabled
- QUARKUS-5380 - Writing a Dev Service doc fixes
- QUARKUS-5379 - Add io.netty.versions.properties to native image resources
- QUARKUS-5378 - Prefer hosting-independent URL for quarkiverse docs
- QUARKUS-5377 - Properly handle Map of form params in REST Client
- QUARKUS-5375 - Adding some additional conditionals for the TLS guide
- QUARKUS-5374 - Tweaking the Datasource guide content conditionals
- QUARKUS-5373 - Update Google Cloud SQL guide
- QUARKUS-5372 - Use the correct event type CertificateUpdatedEvent in TLS Registry reference
- QUARKUS-5371 - CI - Do not populate the cache for PRs as we won't store it
- QUARKUS-5370 - Fix Class Cast Exception when using OpenTelemetry and max-connections property
- QUARKUS-5369 - Application of the QE feedback for the Datasource guide
- QUARKUS-5368 - Update appcds.adoc
- QUARKUS-5367 - Fix typo in rest-client doc
- QUARKUS-5366 - Use original query case for fast count queries
- QUARKUS-5364 - Small fixes for OIDC client guides
- QUARKUS-5363 - Fix AsciiDoc links syntax
- QUARKUS-5362 - Wording fix in HTTP reference
- QUARKUS-5361 - MultiStage Docker instructions needed "chmod ./mvnw"
- QUARKUS-5358 - Docs typo fixes - specificed, agrument
- QUARKUS-5357 - Docs typo fix - use proper SmallRye, RESTEasy and PostgreSQL names
- QUARKUS-5356 - Docs typo fixes
- QUARKUS-5355 - Fix hardcoded URL in generated codestart.yml
- QUARKUS-5354 - Jacoco doc argLine with late property evaluation
- QUARKUS-5353 - Update security-architecture.adoc
- QUARKUS-5352 - Undertow: ignore missing servlet class in web.xml
- QUARKUS-5351 - Unwrap tooltips in the downstream configuration reference docs
- QUARKUS-5349 - Missing space in code example for OpenTracing to OpenTelemetry mapping
- QUARKUS-5348 - Update security-vulnerability-detection.adoc
- QUARKUS-5347 - Update getting-started-reactive.adoc
- QUARKUS-5346 - Remove Failsafe plugin config in AWT testing
- QUARKUS-5345 - Fix Config Error Screen
- QUARKUS-5344 - Add a capability for OIDC client extension
- QUARKUS-5343 - Fix OIDC Bearer tutorial link name
- QUARKUS-5342 - Add information about 'from' in mailer docs
- QUARKUS-5340 - Add extension description for websockets next
- QUARKUS-5339 - Quartz: use a more reasonable default for quarkus.quartz.thread-count
- QUARKUS-5338 - Refactor SecurityTransformerUtils to consider repeated annotations
- QUARKUS-5337 - Dev UI Open in IDE make sure lineNumber is in quotes
- QUARKUS-5336 - [3.15 LTS] Avoid duplicated field serialization in reflection free Jackson serializers
- QUARKUS-5335 - Hibernate: Silence DB connection info logging
- QUARKUS-5223 - Several artifacts are missing from the Interstellar bom
- QUARKUS-5179 - Productize quarkus-cyclonedx-generator
- QUARKUS-5054 - Keycloak container consumes too much memory in devmode
- QUARKUS-1025 - Quarkus extensions drag in maven 3.6.x POMs
- QUARKUS-5341 - Properly apply the update recipes in version order
CVEs
(none)
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.