Skip to content

Commit

Permalink
Disambiguate "2.0-alpha5" between the 2.0-alpha5 family in general an…
Browse files Browse the repository at this point in the history
…d 2.0.51-alpha5 in particular in security advisories and release notes.

Cosmetic.
  • Loading branch information
thibgc committed Oct 12, 2022
1 parent d488066 commit 45c99ad
Show file tree
Hide file tree
Showing 3 changed files with 77 additions and 32 deletions.
4 changes: 2 additions & 2 deletions docs/appendix/security.rst
Original file line number Diff line number Diff line change
Expand Up @@ -14,8 +14,8 @@ CVE-2021-45105 and CVE-2021-44832
.. attention::

**The LOCKSS 2.x system up to and including version 2.0-alpha5 (originally released 2021-12-17), and the custom Solr and OpenWayback containers it includes, are affected by CVE-2021-45105 and CVE-2021-44832.**
**The LOCKSS 2.x system up to and including 2.0.51-alpha5 (originally released 2021-12-17), and the custom Solr and OpenWayback containers it includes, are affected by CVE-2021-45105 and CVE-2021-44832.**

**The recommended remediation is to upgrade LOCKSS 2.x version 2.0-alpha5 (originally released 2021-12-17) or earlier to LOCKSS 2.0-alpha5b.**
**The recommended remediation is to upgrade LOCKSS 2.x version 2.0.51-alpha5 and earlier to LOCKSS 2.0.52-alpha5 or later.**

See :doc:`lockss:security/cve-2021-45105` in the LOCKSS Documentation Portal's :doc:`lockss:security/index` pages.
83 changes: 63 additions & 20 deletions docs/appendix/versions.rst
Original file line number Diff line number Diff line change
Expand Up @@ -4,15 +4,49 @@ Versions

.. COMMENT LATESTVERSION
------------------
LOCKSS 2.0-alpha5d
------------------
--------------------
LOCKSS 2.0.55-alpha5
--------------------

The LOCKSS 2.0-alpha5d system was released on 2022-01-27, to address a bug in the LOCKSS Installer. It is the most recent release of the LOCKSS 2.x system.
| Released: 2022-07-06
| Also known as: LOCKSS 2.0-alpha5e
LOCKSS 2.0.55-alpha5 (also known as LOCKSS 2.0-alpha5e) is a bug fix release and the latest version of the LOCKSS 2.0-alpha5 system. It addresses logging bugs in the LOCKSS Installer and the system's embedded Solr container.

It consists of a configurable set of the following components:

* `LOCKSS Installer <https://github.com/lockss/lockss-installer>`_ version 2.0.55-alpha5

* `LOCKSS Repository Service <https://github.com/lockss/laaws-repository-service>`_ version 2.12.3

* `LOCKSS Configuration Service <https://github.com/lockss/laaws-configservice>`_ version 2.6.2

* `LOCKSS Metadata Extraction Service <https://github.com/lockss/laaws-metadataextractor>`_ version 2.5.2

* `LOCKSS Metadata Service <https://github.com/lockss/laaws-metadataservice>`_ version 2.4.2

* `LOCKSS Poller Service <https://github.com/lockss/laaws-poller>`_ version 2.4.2

* `PostgreSQL <https://www.postgresql.org/>`_ version 9.6.12

* `Apache Solr <https://lucene.apache.org/solr/>`_ version 8.9.0 (custom version 8.9.0-slim-2)

* `Pywb <https://github.com/webrecorder/pywb>`_ version 2.4.2 (custom version 2.4.2-2)

* `OpenWayback <https://github.com/iipc/openwayback>`_ version 2.4.0 (custom version 2.4.0-4)

--------------------
LOCKSS 2.0.54-alpha5
--------------------

| Released: 2022-01-27
| Also known as: LOCKSS 2.0-alpha5d
LOCKSS 2.0.54-alpha5 (also known as LOCKSS 2.0-alpha5d) is a bug fix release of the LOCKSS 2.0-alpha5 system. It addresses a bug in the LOCKSS Installer.

It consists of a configurable set of the following components:

* `LOCKSS Installer <https://github.com/lockss/lockss-installer>`_ version 2.0-alpha5d
* `LOCKSS Installer <https://github.com/lockss/lockss-installer>`_ version 2.0.54-alpha5

* `LOCKSS Repository Service <https://github.com/lockss/laaws-repository-service>`_ version 2.12.3

Expand All @@ -32,15 +66,18 @@ It consists of a configurable set of the following components:

* `OpenWayback <https://github.com/iipc/openwayback>`_ version 2.4.0 (custom version 2.4.0-4)

------------------
LOCKSS 2.0-alpha5c
------------------
--------------------
LOCKSS 2.0.53-alpha5
--------------------

The LOCKSS 2.0-alpha5c system was released on 2022-01-24, to address a bug in the LOCKSS Repository Service.
| Released: 2022-01-24
| Also known as: LOCKSS 2.0-alpha5c
LOCKSS 2.0.53-alpha5 (also known as LOCKSS 2.0-alpha5c) is a bug fix release of the LOCKSS 2.0-alpha5 system. It addresses a bug in the LOCKSS Repository Service.

It consists of a configurable set of the following components:

* `LOCKSS Installer <https://github.com/lockss/lockss-installer>`_ version 2.0-alpha5c
* `LOCKSS Installer <https://github.com/lockss/lockss-installer>`_ version 2.0.53-alpha5

* `LOCKSS Repository Service <https://github.com/lockss/laaws-repository-service>`_ version 2.12.3

Expand All @@ -60,15 +97,18 @@ It consists of a configurable set of the following components:

* `OpenWayback <https://github.com/iipc/openwayback>`_ version 2.4.0 (custom version 2.4.0-4)

------------------
LOCKSS 2.0-alpha5b
------------------
--------------------
LOCKSS 2.0.52-alpha5
--------------------

| Released: 2022-01-02
| Also known as: LOCKSS 2.0-alpha5b
The LOCKSS 2.0-alpha5b system was released on 2022-01-02, to address security vulnerabilities in Apache Log4j 2.x. See :ref:`CVE-2021-45105 and CVE-2021-44832` in our :doc:`security`.
LOCKSS 2.0.52-alpha5 (also known as LOCKSS 2.0-alpha5b) is a security release of the LOCKSS 2.0-alpha5 system. It addresses security vulnerabilities in Apache Log4j 2.x. See :ref:`CVE-2021-45105 and CVE-2021-44832` in our :doc:`security`.

It consists of a configurable set of the following components:

* `LOCKSS Installer <https://github.com/lockss/lockss-installer>`_ version 2.0-alpha5b
* `LOCKSS Installer <https://github.com/lockss/lockss-installer>`_ version 2.0.52-alpha5

* `LOCKSS Repository Service <https://github.com/lockss/laaws-repository-service>`_ version 2.12.2

Expand All @@ -88,15 +128,18 @@ It consists of a configurable set of the following components:

* `OpenWayback <https://github.com/iipc/openwayback>`_ version 2.4.0 (custom version 2.4.0-4)

-----------------
LOCKSS 2.0-alpha5
-----------------
--------------------
LOCKSS 2.0.51-alpha5
--------------------

| Released: 2021-12-17
| Also known as: LOCKSS 2.0-alpha5a
The LOCKSS 2.0-alpha5 system was released on 2021-12-17.
LOCKSS 2.0.51-alpha5 (also known as LOCKSS 2.0-alpha5a) is the first release of the LOCKSS 2.0-alpha5 system.

It consists of a configurable set of the following components:

* `LOCKSS Installer <https://github.com/lockss/lockss-installer>`_ version 2.0-alpha5
* `LOCKSS Installer <https://github.com/lockss/lockss-installer>`_ version 2.0.51-alpha5

* `LOCKSS Repository Service <https://github.com/lockss/laaws-repository-service>`_ version 2.12.0

Expand Down
22 changes: 12 additions & 10 deletions docs/index.rst
Original file line number Diff line number Diff line change
Expand Up @@ -13,39 +13,41 @@ LOCKSS 2.0-alpha5 System Manual

**Security advisories: CVE-2021-45105, CVE-2021-44832**

**LOCKSS 2.0-alpha5 (originally released 2021-12-17) and the custom Solr and OpenWayback containers it includes are affected.** See :ref:`CVE-2021-45105 and CVE-2021-44832`.
**LOCKSS 2.0.51-alpha5 (originally released 2021-12-17) and the custom Solr and OpenWayback containers it includes are affected.** See :ref:`CVE-2021-45105 and CVE-2021-44832`.

.. _release-notes:

-----------
What's New?
-----------

What's New in 2.0-alpha5e?
==========================
What's New in 2.0.55-alpha5?
============================

* Fix Solr logging and increase heap size.

* Bug fixes in the LOCKSS Installer.

What's New in 2.0-alpha5d?
==========================
What's New in 2.0.54-alpha5?
============================

* Bug fixes in the LOCKSS Installer.

What's New in 2.0-alpha5c?
==========================
What's New in 2.0.53-alpha5?
============================

* Bug fixes in the LOCKSS Repository Service.

What's New in 2.0-alpha5b?
==========================
What's New in 2.0.52-alpha5?
============================

* Include only Apache Log4j 2.17.1 to address :ref:`CVE-2021-45105 and CVE-2021-44832`. See :doc:`/appendix/security`.

What's New Since 2.0-alpha4?
============================

LOCKSS 2.0.51-alpha5 features:

* Numerous bug fixes and substantial performance improvements in the LOCKSS Repository Service, in support of reliability, scalability, and LOCKSS 1.x to 2.x migration.

* Improved LOCKSS Installer distributed without requiring Git, rolling up most individual installation steps into a single script.
Expand Down Expand Up @@ -87,7 +89,7 @@ LOCKSS 2.0-alpha5 System Manual
---------------------

Is LOCKSS 2.0-alpha5 vulnerable to CVE-2021-44228 ("Log4Shell")?
No, **but** it is affected by additional Log4j 2.x vulnerabilities discovered after the original 2021-12-17 release of LOCKSS 2.0-alpha5. See :doc:`/appendix/security`.
No, **but** it is affected by additional Log4j 2.x vulnerabilities discovered after the original 2021-12-17 release of LOCKSS 2.0.51-alpha5. See :doc:`/appendix/security`.

I have an existing classic LOCKSS system (version 1.x). Can I upgrade to LOCKSS 2.0-alpha5?
The LOCKSS 2.0-alpha5 release is a technology preview which we are excited to share with the community for testing purposes. It is not yet possible to convert from a classic LOCKSS system (e.g. version 1.75.8) to a LOCKSS 2.0 system for production purposes.
Expand Down

0 comments on commit 45c99ad

Please sign in to comment.