BIOVIA Support often get questions related to security updates of third-party components used in Pipeline Pilot.
For each release, these third-party updates are listed in the Product Release Document (PRD) for that release.
Below is a list of third party updates for the recent Pipeline Pilot releases compiled from the respective PRD.
Pipeline Pilot 2022 SP1
- The OpenSSL library has been updated to version 1.1.1o.
 - Updated the Apache httpd server to version 2.4.53.
 - The embedded Tomcat server has been updated to version 8.5.78.
 - Log4j has been replaced with the reload4j logging library.
 
Pipeline Pilot 2023
- The embedded Tomcat server has been updated to the latest security-fix version.
 - Updated the Apache httpd server to version 2.4.54.
 - Updated OpenSSL to the latest 1.1.1 version.
 - The Java logging library reload4j is updated to the latest version 1.2.22
 
Pipeline Pilot 2023 SP1
- The embedded Tomcat server has been updated to the latest security-fix version.
 
Pipeline Pilot 2024
- The Java run time environment included with Pipeline Pilot is upgraded to Temurin-11.0.20+8.
 - Apache is updated to version 2.4.57. Also, the httpd dependency apr is updated to version 1.7.3.
 - Python is updated to version 3.9.16.
 - The Perl installation used for the Perl (on Server) component is updated to Perl 5.36.0. For more information, see https://www.perl.org/.
 - The ODBC drivers for Oracle, SQLServer, and MySQL are updated: Oracle is 8.00.02.2713, SQL Server is 8.00.02.1196, and MySQL is 8.00.02.218.
 - Chromium Embedded is updated to the latest version as of September 2023.
 - libssh is updated to the latest available version, 0.10.4.
 - The internal SQLite driver used for various tasks within Pipeline Pilot is updated to the latest version.
 - OpenSSL is updated to the latest 3.0 release as of September 2023.
 - The lz4 compression library is updated to the latest version as of September 2023.
 
Pipeline Pilot 2024 SP1
- The Brotli compression library is updated to 1.1.0.
 - libssh is updated to version 0.10.6.
 - Openssl is updated to 3.0.13.
 - The zlib library is updated to the latest available version (1.3.1).
 - The expat XML parser library is updated to the latest available version (2.6.0).
 - The Active MQ client library is updated to version 5.18.3.
 - The embedded Tomcat server is updated from Tomcat 8.5 to Tomcat 9.0.83.
 - Perl, which is primarily used by the Perl (on server) components, is updated to 5.36.3.
 - Apache httpd is updated to 2.4.58.
 
Pipeline Pilot 2025
- The expat XML parser library is updated to the latest available version (2.6.2).
 - The lz4 compression library is updated to the latest version as of July 2024.
 - The internal SQLite drive is now the latest version.
 - The libssh was updated to the latest available version.
 - The version of Openssl was updated to 3.0.15.
 - The expat XML parser library is updated to the latest available version (2.6.3).
 - The Highcharts library has been updated to version 11.4.8.
 - The embedded Tomcat server is updated to version 9.0.95.
 - The Java runtime environment included with Pipeline Pilot is upgraded to Java 17.
 - Python has been updated to version 3.9.19.
 - The Apache httpd server is updated to version 2.4.61.
 
