• Java 8 security patching

    From James Kennard@21:1/5 to All on Wed Feb 8 18:40:01 2023
    Hi,

    I can't seem to find a definitive answer to this question. As I understand
    it, OpenJDK will continue to provide security patches for Java 8 until
    December 2030 (https://www.oracle.com/java/technologies/downloads/#java8).

    How long will Debian continue to provide a build of openjdk-8? And how long will Debian continue to apply security patches to openjdk-8?

    Thanks

    James.

    <div dir="ltr"><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div>Hi,<br><br>I can&#39;t seem to find a definitive answer to this question. As I understand it, OpenJDK will continue to provide security
    patches for Java 8 until December 2030 (<a href="https://www.oracle.com/java/technologies/downloads/#java8">https://www.oracle.com/java/technologies/downloads/#java8</a>).<br><br>How long will Debian continue to provide a build of openjdk-8? And how long
    will Debian continue to apply security patches to openjdk-8?<br><br>Thanks<br><br>James.<br><br></div></div></div></div></div>

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Thorsten Glaser@21:1/5 to James Kennard on Wed Feb 8 21:30:01 2023
    On Wed, 8 Feb 2023, James Kennard wrote:

    How long will Debian continue to provide a build of openjdk-8? And how long >will Debian continue to apply security patches to openjdk-8?

    The ELTS team is going to support openjdk-8 in jessie and stretch
    for as long as they get paid for (see the ELTS project’s pages for
    more information).

    Currently, they’re coordinating with me, I’m uploading new releases
    to unstable to take as base for the backported builds as time permits
    and sponsored by my employer (see below); however, openjdk-8 in sid
    is not officially supported in Debian and has not since 2019-07-06 if
    not earlier. For a given release, only default-jdk is supported; that
    is 11 for buster and bullseye, and 17 for bookworm; any other JDK that
    mey be available is either legacy compat or technology preview and
    completely unsupported (modulo individual volunteer effort as usual).

    If you need some level of support for openjdk-8, I suggest to contact
    Freexian (the ELTS coordinator). For uploads to unstable to continue,
    you might want to contract my employer so I can continue to do this,
    as it takes a couple of person-hours each quarter plus extra love for
    e.g. getting the tests to pass better. I also have an APT repository
    in which I publish builds of openjdk-8 for wheezy (EOL though), buster, bullseye and even bookworm (those not covered by ELTS), and a PPA at
    Launchpad in which I do the same for *buntu LTS releases; if you have
    interest in these I might also be made available via my employer. (The repositories are currently available to the public but unsupported. I
    also can only build for x86 at the moment.)

    bye,
    //mirabilos
    --
    Infrastrukturexperte • tarent solutions GmbH
    Am Dickobskreuz 10, D-53121 Bonn • http://www.tarent.de/
    Telephon +49 228 54881-393 • Fax: +49 228 54881-235
    HRB AG Bonn 5168 • USt-ID (VAT): DE122264941
    Geschäftsführer: Dr. Stefan Barth, Kai Ebenrett, Boris Esser, Alexander Steeg

    **************************************************** /⁀\ The UTF-8 Ribbon
    ╲ ╱ Campaign against Mit dem tarent-Newsletter nichts mehr verpassen:  ╳  HTML eMail! Also, https://www.tarent.de/newsletter
    ╱ ╲ header encryption!
    ****************************************************

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From James Kennard@21:1/5 to Thorsten Glaser on Fri Feb 10 10:00:01 2023
    Hi Thorsten,

    Thank you for your continued effort in keeping java 8 up-to-date for the
    Debian and Ubuntu communities.

    Is there a particular reason why you are continuing to update it as opposed
    to recommending people switch to an alternative distribution such as
    Temurin?

    All the best,

    James


    On Wed, 8 Feb 2023 at 20:29, Thorsten Glaser <t.glaser@tarent.de> wrote:

    On Wed, 8 Feb 2023, James Kennard wrote:

    How long will Debian continue to provide a build of openjdk-8? And how
    long
    will Debian continue to apply security patches to openjdk-8?

    The ELTS team is going to support openjdk-8 in jessie and stretch
    for as long as they get paid for (see the ELTS project’s pages for
    more information).

    Currently, they’re coordinating with me, I’m uploading new releases
    to unstable to take as base for the backported builds as time permits
    and sponsored by my employer (see below); however, openjdk-8 in sid
    is not officially supported in Debian and has not since 2019-07-06 if
    not earlier. For a given release, only default-jdk is supported; that
    is 11 for buster and bullseye, and 17 for bookworm; any other JDK that
    mey be available is either legacy compat or technology preview and
    completely unsupported (modulo individual volunteer effort as usual).

    If you need some level of support for openjdk-8, I suggest to contact Freexian (the ELTS coordinator). For uploads to unstable to continue,
    you might want to contract my employer so I can continue to do this,
    as it takes a couple of person-hours each quarter plus extra love for
    e.g. getting the tests to pass better. I also have an APT repository
    in which I publish builds of openjdk-8 for wheezy (EOL though), buster, bullseye and even bookworm (those not covered by ELTS), and a PPA at Launchpad in which I do the same for *buntu LTS releases; if you have interest in these I might also be made available via my employer. (The repositories are currently available to the public but unsupported. I
    also can only build for x86 at the moment.)

    bye,
    //mirabilos
    --
    Infrastrukturexperte • tarent solutions GmbH
    Am Dickobskreuz 10, D-53121 Bonn • http://www.tarent.de/
    Telephon +49 228 54881-393 • Fax: +49 228 54881-235
    HRB AG Bonn 5168 • USt-ID (VAT): DE122264941
    Geschäftsführer: Dr. Stefan Barth, Kai Ebenrett, Boris Esser, Alexander Steeg


    ****************************************************
    /⁀\ The UTF-8 Ribbon
    ╲ ╱ Campaign against Mit dem tarent-Newsletter nichts mehr verpassen:
    ╳ HTML eMail! Also, https://www.tarent.de/newsletter
    ╱ ╲ header encryption!

    ****************************************************


    <div dir="ltr">Hi Thorsten,<div><br></div><div>Thank you for your continued effort in keeping java 8 up-to-date for the Debian and Ubuntu communities.</div><div><br></div><div>Is there a particular reason why you are continuing to update it as opposed
    to recommending people switch to an alternative distribution such as Temurin?<br clear="all"><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><br></div>All the best,<div><br></div><div>James</div></div></
    </div><br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, 8 Feb 2023 at 20:29, Thorsten Glaser &lt;<a href="mailto:t.glaser@tarent.de">t.glaser@tarent.de</a>&gt; wrote:<br></div><blockquote class="gmail_quote" style=
    "margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">On Wed, 8 Feb 2023, James Kennard wrote:<br>

    &gt;How long will Debian continue to provide a build of openjdk-8? And how long<br>
    &gt;will Debian continue to apply security patches to openjdk-8?<br>

    The ELTS team is going to support openjdk-8 in jessie and stretch<br>
    for as long as they get paid for (see the ELTS project’s pages for<br>
    more information).<br>

    Currently, they’re coordinating with me, I’m uploading new releases<br>
    to unstable to take as base for the backported builds as time permits<br>
    and sponsored by my employer (see below); however, openjdk-8 in sid<br>
    is not officially supported in Debian and has not since 2019-07-06 if<br>
    not earlier. For a given release, only default-jdk is supported; that<br>
    is 11 for buster and bullseye, and 17 for bookworm; any other JDK that<br>
    mey be available is either legacy compat or technology preview and<br> completely unsupported (modulo individual volunteer effort as usual).<br>

    If you need some level of support for openjdk-8, I suggest to contact<br> Freexian (the ELTS coordinator). For uploads to unstable to continue,<br>
    you might want to contract my employer so I can continue to do this,<br>
    as it takes a couple of person-hours each quarter plus extra love for<br>
    e.g. getting the tests to pass better. I also have an APT repository<br>
    in which I publish builds of openjdk-8 for wheezy (EOL though), buster,<br> bullseye and even bookworm (those not covered by ELTS), and a PPA at<br> Launchpad in which I do the same for *buntu LTS releases; if you have<br> interest in these I might also be made available via my employer. (The<br> repositories are currently available to the public but unsupported. I<br>
    also can only build for x86 at the moment.)<br>

    bye,<br>
    //mirabilos<br>
    -- <br>
    Infrastrukturexperte • tarent solutions GmbH<br>
    Am Dickobskreuz 10, D-53121 Bonn • <a href="http://www.tarent.de/" rel="noreferrer" target="_blank">http://www.tarent.de/</a><br>
    Telephon +49 228 54881-393 • Fax: +49 228 54881-235<br>
    HRB AG Bonn 5168 • USt-ID (VAT): DE122264941<br>
    Geschäftsführer: Dr. Stefan Barth, Kai Ebenrett, Boris Esser, Alexander Steeg<br>

                            ****************************************************<br>
    /⁀\ The UTF-8 Ribbon<br>
    ╲ ╱ Campaign against      Mit dem tarent-Newsletter nichts mehr verpassen:<br>
     ╳  HTML eMail! Also,     <a href="https://www.tarent.de/newsletter" rel="noreferrer" target="_blank">https://www.tarent.de/newsletter</a><br>
    ╱ ╲ header encryption!<br>
                            ****************************************************<br>
    </blockquote></div>

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Thorsten Glaser@21:1/5 to James Kennard on Fri Feb 10 15:10:01 2023
    On Fri, 10 Feb 2023, James Kennard wrote:

    Is there a particular reason why you are continuing to update it as opposed >to recommending people switch to an alternative distribution such as
    Temurin?

    I don’t know what Temurin even is.

    While I do recommend that people switch to default-jdk, and in fact
    we have been needing to use at least 11 in development for a while
    because Maven plugins from Central didn’t work with 8 for some time
    even when intended to, some customers still run prod on 8, so we
    need it for testing. (Or, at least, used to; I’m currently not in
    a Java project at work.) I also have been supplying a customer with
    openjdk-8 as jessie backport before it was in backports itself, then
    ELTS. (The mentioned customer is also no longer in a situation to
    receive/need these, but this gives historical context.)

    I just did not cease updating this.

    bye,
    //mirabilos
    --
    Infrastrukturexperte • tarent solutions GmbH
    Am Dickobskreuz 10, D-53121 Bonn • http://www.tarent.de/
    Telephon +49 228 54881-393 • Fax: +49 228 54881-235
    HRB AG Bonn 5168 • USt-ID (VAT): DE122264941
    Geschäftsführer: Dr. Stefan Barth, Kai Ebenrett, Boris Esser, Alexander Steeg

    **************************************************** /⁀\ The UTF-8 Ribbon
    ╲ ╱ Campaign against Mit dem tarent-Newsletter nichts mehr verpassen:  ╳  HTML eMail! Also, https://www.tarent.de/newsletter
    ╱ ╲ header encryption!
    ****************************************************

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From James Kennard@21:1/5 to Thorsten Glaser on Mon Feb 13 11:00:01 2023
    Hi Thorsten,

    Thanks again for the explanation.

    With the changes to Java licensing, alternative distributions of Java have become increasingly popular. They all have their pros and cons, https://whichjdk.com/.

    All the best,

    James


    On Fri, 10 Feb 2023 at 14:06, Thorsten Glaser <t.glaser@tarent.de> wrote:

    On Fri, 10 Feb 2023, James Kennard wrote:

    Is there a particular reason why you are continuing to update it as
    opposed
    to recommending people switch to an alternative distribution such as >Temurin?

    I don’t know what Temurin even is.

    While I do recommend that people switch to default-jdk, and in fact
    we have been needing to use at least 11 in development for a while
    because Maven plugins from Central didn’t work with 8 for some time
    even when intended to, some customers still run prod on 8, so we
    need it for testing. (Or, at least, used to; I’m currently not in
    a Java project at work.) I also have been supplying a customer with
    openjdk-8 as jessie backport before it was in backports itself, then
    ELTS. (The mentioned customer is also no longer in a situation to receive/need these, but this gives historical context.)

    I just did not cease updating this.

    bye,
    //mirabilos
    --
    Infrastrukturexperte • tarent solutions GmbH
    Am Dickobskreuz 10, D-53121 Bonn • http://www.tarent.de/
    Telephon +49 228 54881-393 • Fax: +49 228 54881-235
    HRB AG Bonn 5168 • USt-ID (VAT): DE122264941
    Geschäftsführer: Dr. Stefan Barth, Kai Ebenrett, Boris Esser, Alexander Steeg


    ****************************************************
    /⁀\ The UTF-8 Ribbon
    ╲ ╱ Campaign against Mit dem tarent-Newsletter nichts mehr verpassen:
    ╳ HTML eMail! Also, https://www.tarent.de/newsletter
    ╱ ╲ header encryption!

    ****************************************************


    <div dir="ltr">Hi Thorsten,<div><br></div><div>Thanks again for the explanation.</div><div><br></div><div>With the changes to Java licensing, alternative distributions of Java have become increasingly popular. They all have their pros and cons, <a href="
    https://whichjdk.com/">https://whichjdk.com/</a>.<br clear="all"><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><br></div>All the best,<div><br></div><div>James</div></div></div></div><br></div></div><br><
    div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Fri, 10 Feb 2023 at 14:06, Thorsten Glaser &lt;<a href="mailto:t.glaser@tarent.de">t.glaser@tarent.de</a>&gt; wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;
    border-left:1px solid rgb(204,204,204);padding-left:1ex">On Fri, 10 Feb 2023, James Kennard wrote:<br>

    &gt;Is there a particular reason why you are continuing to update it as opposed<br>
    &gt;to recommending people switch to an alternative distribution such as<br> &gt;Temurin?<br>

    I don’t know what Temurin even is.<br>

    While I do recommend that people switch to default-jdk, and in fact<br>
    we have been needing to use at least 11 in development for a while<br>
    because Maven plugins from Central didn’t work with 8 for some time<br>
    even when intended to, some customers still run prod on 8, so we<br>
    need it for testing. (Or, at least, used to; I’m currently not in<br>
    a Java project at work.) I also have been supplying a customer with<br> openjdk-8 as jessie backport before it was in backports itself, then<br>
    ELTS. (The mentioned customer is also no longer in a situation to<br> receive/need these, but this gives historical context.)<br>

    I just did not cease updating this.<br>

    bye,<br>
    //mirabilos<br>
    -- <br>
    Infrastrukturexperte • tarent solutions GmbH<br>
    Am Dickobskreuz 10, D-53121 Bonn • <a href="http://www.tarent.de/" rel="noreferrer" target="_blank">http://www.tarent.de/</a><br>
    Telephon +49 228 54881-393 • Fax: +49 228 54881-235<br>
    HRB AG Bonn 5168 • USt-ID (VAT): DE122264941<br>
    Geschäftsführer: Dr. Stefan Barth, Kai Ebenrett, Boris Esser, Alexander Steeg<br>

                            ****************************************************<br>
    /⁀\ The UTF-8 Ribbon<br>
    ╲ ╱ Campaign against      Mit dem tarent-Newsletter nichts mehr verpassen:<br>
     ╳  HTML eMail! Also,     <a href="https://www.tarent.de/newsletter" rel="noreferrer" target="_blank">https://www.tarent.de/newsletter</a><br>
    ╱ ╲ header encryption!<br>
                            ****************************************************<br>
    </blockquote></div>

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Thorsten Glaser@21:1/5 to James Kennard on Mon Feb 13 15:10:01 2023
    On Mon, 13 Feb 2023, James Kennard wrote:

    With the changes to Java licensing

    What changes? It’s been GPLv2 + Classpath exception for *ages* now.

    , alternative distributions of Java have
    become increasingly popular. They all have their pros and cons,

    Perhaps, but we’re still talking about the openjdk-8 package here,
    which, you know, ships OpenJDK 8…

    bye,
    //mirabilos
    --
    Infrastrukturexperte • tarent solutions GmbH
    Am Dickobskreuz 10, D-53121 Bonn • http://www.tarent.de/
    Telephon +49 228 54881-393 • Fax: +49 228 54881-235
    HRB AG Bonn 5168 • USt-ID (VAT): DE122264941
    Geschäftsführer: Dr. Stefan Barth, Kai Ebenrett, Boris Esser, Alexander Steeg

    **************************************************** /⁀\ The UTF-8 Ribbon
    ╲ ╱ Campaign against Mit dem tarent-Newsletter nichts mehr verpassen:  ╳  HTML eMail! Also, https://www.tarent.de/newsletter
    ╱ ╲ header encryption!
    ****************************************************

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From James Kennard@21:1/5 to Thorsten Glaser on Mon Feb 13 16:50:02 2023
    Yes, it has been a long time now, but it's taken time for the alternatives
    to gain traction. I was just trying to understand the current state of play
    to help work out how and when to move away from openjdk-8.

    Thanks again for all your help.

    On Mon, 13 Feb 2023 at 14:05, Thorsten Glaser <t.glaser@tarent.de> wrote:

    On Mon, 13 Feb 2023, James Kennard wrote:

    With the changes to Java licensing

    What changes? It’s been GPLv2 + Classpath exception for *ages* now.

    , alternative distributions of Java have
    become increasingly popular. They all have their pros and cons,

    Perhaps, but we’re still talking about the openjdk-8 package here,
    which, you know, ships OpenJDK 8…

    bye,
    //mirabilos
    --
    Infrastrukturexperte • tarent solutions GmbH
    Am Dickobskreuz 10, D-53121 Bonn • http://www.tarent.de/
    Telephon +49 228 54881-393 • Fax: +49 228 54881-235
    HRB AG Bonn 5168 • USt-ID (VAT): DE122264941
    Geschäftsführer: Dr. Stefan Barth, Kai Ebenrett, Boris Esser, Alexander Steeg


    ****************************************************
    /⁀\ The UTF-8 Ribbon
    ╲ ╱ Campaign against Mit dem tarent-Newsletter nichts mehr verpassen:
    ╳ HTML eMail! Also, https://www.tarent.de/newsletter
    ╱ ╲ header encryption!

    ****************************************************


    <div dir="ltr"><br>Yes, it has been a long time now, but it&#39;s taken time for the alternatives to gain traction. I was just trying to understand the current state of play to help work out how and when to move away from openjdk-8.<div><br></div><div>
    Thanks again for all your help.</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Mon, 13 Feb 2023 at 14:05, Thorsten Glaser &lt;<a href="mailto:t.glaser@tarent.de">t.glaser@tarent.de</a>&gt; wrote:<br></div><blockquote class="
    gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">On Mon, 13 Feb 2023, James Kennard wrote:<br>

    &gt;With the changes to Java licensing<br>

    What changes? It’s been GPLv2 + Classpath exception for *ages* now.<br>

    &gt;, alternative distributions of Java have<br>
    &gt;become increasingly popular. They all have their pros and cons,<br>

    Perhaps, but we’re still talking about the openjdk-8 package here,<br>
    which, you know, ships OpenJDK 8…<br>

    bye,<br>
    //mirabilos<br>
    -- <br>
    Infrastrukturexperte • tarent solutions GmbH<br>
    Am Dickobskreuz 10, D-53121 Bonn • <a href="http://www.tarent.de/" rel="noreferrer" target="_blank">http://www.tarent.de/</a><br>
    Telephon +49 228 54881-393 • Fax: +49 228 54881-235<br>
    HRB AG Bonn 5168 • USt-ID (VAT): DE122264941<br>
    Geschäftsführer: Dr. Stefan Barth, Kai Ebenrett, Boris Esser, Alexander Steeg<br>

                            ****************************************************<br>
    /⁀\ The UTF-8 Ribbon<br>
    ╲ ╱ Campaign against      Mit dem tarent-Newsletter nichts mehr verpassen:<br>
     ╳  HTML eMail! Also,     <a href="https://www.tarent.de/newsletter" rel="noreferrer" target="_blank">https://www.tarent.de/newsletter</a><br>
    ╱ ╲ header encryption!<br>
                            ****************************************************<br>
    </blockquote></div>

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Thorsten Glaser@21:1/5 to James Kennard on Mon Feb 13 17:50:01 2023
    On Mon, 13 Feb 2023, James Kennard wrote:

    Yes, it has been a long time now, but it's taken time for the alternatives
    to gain traction. I was just trying to understand the current state of play >to help work out how and when to move away from openjdk-8.

    We’ve already moved, as a whole, to openjdk-11 and even 17 in places.

    bye,
    //mirabilos
    --
    Infrastrukturexperte • tarent solutions GmbH
    Am Dickobskreuz 10, D-53121 Bonn • http://www.tarent.de/
    Telephon +49 228 54881-393 • Fax: +49 228 54881-235
    HRB AG Bonn 5168 • USt-ID (VAT): DE122264941
    Geschäftsführer: Dr. Stefan Barth, Kai Ebenrett, Boris Esser, Alexander Steeg

    **************************************************** /⁀\ The UTF-8 Ribbon
    ╲ ╱ Campaign against Mit dem tarent-Newsletter nichts mehr verpassen:  ╳  HTML eMail! Also, https://www.tarent.de/newsletter
    ╱ ╲ header encryption!
    ****************************************************

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)