Re: using cocoon 2.1 in the long-term, security concerns

gelo1234 <[email protected]> Mon, 19 Jul 2021 15:17:54 +0200
Newsgroups gmane.text.xml.cocoon.user
Message-ID <CAPJaKUquZprtoB6y0pmcu+9RePmrD0VfPE6tg5-ZKN1iCm-30A@mail.gmail.com>
--00000000000089ede205c779c418
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hello Vincent,

It depends on your future Strategy. Cocoon is very flexible. We've been
running Cocoon 3.0-beta in production with Tomcat9/10, Quarkus and even
Kubernetes 1.20 etc. No problems at all :)
with Java 8 :) We cannot switch to Java 11, because it's not compatible
with Cocoon libraries anymore :( That's the only obstacle.
Maybe someone could "update" cocoon stack to use Java 11 LTS JVM? Or now 17
LTS? :)

As long as it does its job, Cocoon is fine! Although the amount of
pipelines that are still in use in our Cocoon deployments decreased in
time.
We switched to Vue.js framework as frontend and Spring-Boot 2 as backend
technologies, all running on Kubernetes multi-clusters.
Both Vue and Spring-Boot 2 are very lightweight and suit our needs better
(to build Web-Portals) than Cocoon. Even though we still use Cocoon for
some integration stuff and fast
proxy/gateway to many "old" services or database access.

Greetings,
Greg


pon., 19 lip 2021 o 14:03 Vincent Neyt <[email protected]> napisa=C5=
=82(a):

> Hi Cocoon users,
>
> I'd like to ask your opinion on the long-term security risks of running
> Cocoon on a server. The colleague responsible for the servers at my
> university is inquiring if the software I'm using for my website is up to
> date and is concerned that I'm using outdated software that could in the
> future pose a security risk.
>
> I'm using cocoon 2.1.11, which I could probably upgrade to 2.1.13 without
> many problems. But I'm concerned about the long-term, and wondering if it
> would perhaps be better to reprogram the website I've been working on for
> 10 years into eXist DB (which would be a huge time investment). I like
> cocoon very much and would love to continue using it if it's possible.
>
> I'm curious to hear your thoughts about using Cocoon 2.1 for the long
> term: will it still work well inside future versions of servlet container=
s
> like Tomcat? What about the java dependencies? And will cocoon 2.1 contin=
ue
> to put out updates when security risks are identified?
>
> thanks very much,
> Vincent
>

--00000000000089ede205c779c418
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_default" style=3D"font-size:small">Hel=
lo Vincent,</div><div class=3D"gmail_default" style=3D"font-size:small"><br=
></div><div class=3D"gmail_default" style=3D"font-size:small">It depends on=
 your future Strategy. Cocoon is very flexible. We&#39;ve been running Coco=
on 3.0-beta in production with Tomcat9/10, Quarkus and even Kubernetes 1.20=
 etc. No problems at all :)</div><div class=3D"gmail_default" style=3D"font=
-size:small">with Java 8 :) We cannot switch to Java 11, because it&#39;s n=
ot compatible with Cocoon libraries anymore :( That&#39;s the only obstacle=
.<br></div><div class=3D"gmail_default" style=3D"font-size:small">Maybe som=
eone could &quot;update&quot; cocoon stack to use Java 11 LTS JVM? Or now 1=
7 LTS? :)</div><div class=3D"gmail_default" style=3D"font-size:small"><br><=
/div><div class=3D"gmail_default" style=3D"font-size:small">As long as it d=
oes its job, Cocoon is fine! Although the amount of pipelines that are stil=
l in use in our Cocoon deployments decreased in time. <br></div><div class=
=3D"gmail_default" style=3D"font-size:small">We switched to Vue.js framewor=
k as frontend and Spring-Boot 2 as backend technologies, all running on Kub=
ernetes multi-clusters.<br></div><div class=3D"gmail_default" style=3D"font=
-size:small">Both Vue and Spring-Boot 2 are very lightweight and suit our n=
eeds better (to build Web-Portals) than Cocoon. Even though we still use Co=
coon for some integration stuff and fast <br></div><div class=3D"gmail_defa=
ult" style=3D"font-size:small">proxy/gateway to many &quot;old&quot; servic=
es or database access.</div><div class=3D"gmail_default" style=3D"font-size=
:small"><br></div><div class=3D"gmail_default" style=3D"font-size:small">Gr=
eetings,</div><div class=3D"gmail_default" style=3D"font-size:small">Greg<b=
r></div><div class=3D"gmail_default" style=3D"font-size:small"><br></div></=
div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">po=
n., 19 lip 2021 o 14:03=C2=A0Vincent Neyt &lt;<a href=3D"mailto:vincent.ney=
[email protected]">[email protected]</a>&gt; napisa=C5=82(a):<br></div><bloc=
kquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:=
1px solid rgb(204,204,204);padding-left:1ex"><div dir=3D"ltr">Hi Cocoon use=
rs,<div><br></div><div>I&#39;d like to ask your opinion on the long-term se=
curity risks of running Cocoon on a server. The colleague responsible for t=
he servers at my university is inquiring if the software I&#39;m using for =
my website is up to date and is concerned that I&#39;m using outdated softw=
are that could in the future pose a security risk.<br><div><br></div><div>I=
&#39;m using cocoon 2.1.11, which I could probably upgrade to 2.1.13 withou=
t many problems. But I&#39;m concerned about the long-term, and wondering i=
f it would perhaps be better to reprogram the website I&#39;ve been working=
 on for 10 years into eXist DB (which would be a huge time investment). I l=
ike cocoon very=C2=A0much and would love to continue using it if it&#39;s p=
ossible.</div></div><div><br></div><div>I&#39;m curious to hear your though=
ts about using Cocoon 2.1 for the long term: will it still work well inside=
 future versions of servlet containers like Tomcat? What about the java dep=
endencies? And will cocoon 2.1 continue to put out updates when security ri=
sks are identified?</div><div><br></div><div>thanks very much,</div><div>Vi=
ncent=C2=A0</div></div>
</blockquote></div>

--00000000000089ede205c779c418--