BIOVIA Support often get questions related to security updates of third-party components used in Pipeline Pilot.
For each release, these third-party updates are listed in the Product Release Document (PRD) for that release.
Below is a list of third party updates for the recent Pipeline Pilot releases compiled from the respective PRD.
Pipeline Pilot 2022 SP1
- The OpenSSL library has been updated to version 1.1.1o.
- Updated the Apache httpd server to version 2.4.53.
- The embedded Tomcat server has been updated to version 8.5.78.
- Log4j has been replaced with the reload4j logging library.
Pipeline Pilot 2023
- The embedded Tomcat server has been updated to the latest security-fix version.
- Updated the Apache httpd server to version 2.4.54.
- Updated OpenSSL to the latest 1.1.1 version.
- The Java logging library reload4j is updated to the latest version 1.2.22
Pipeline Pilot 2023 SP1
- The embedded Tomcat server has been updated to the latest security-fix version.
Pipeline Pilot 2024
- The Java run time environment included with Pipeline Pilot is upgraded to Temurin-11.0.20+8.
- Apache is updated to version 2.4.57. Also, the httpd dependency apr is updated to version 1.7.3.
- Python is updated to version 3.9.16.
- The Perl installation used for the Perl (on Server) component is updated to Perl 5.36.0. For more information, see https://www.perl.org/.
- The ODBC drivers for Oracle, SQLServer, and MySQL are updated: Oracle is 8.00.02.2713, SQL Server is 8.00.02.1196, and MySQL is 8.00.02.218.
- Chromium Embedded is updated to the latest version as of September 2023.
- libssh is updated to the latest available version, 0.10.4.
- The internal SQLite driver used for various tasks within Pipeline Pilot is updated to the latest version.
- OpenSSL is updated to the latest 3.0 release as of September 2023.
- The lz4 compression library is updated to the latest version as of September 2023.
Pipeline Pilot 2024 SP1
- The Brotli compression library is updated to 1.1.0.
- libssh is updated to version 0.10.6.
- Openssl is updated to 3.0.13.
- The zlib library is updated to the latest available version (1.3.1).
- The expat XML parser library is updated to the latest available version (2.6.0).
- The Active MQ client library is updated to version 5.18.3.
- The embedded Tomcat server is updated from Tomcat 8.5 to Tomcat 9.0.83.
- Perl, which is primarily used by the Perl (on server) components, is updated to 5.36.3.
- Apache httpd is updated to 2.4.58.
Pipeline Pilot 2025
- The expat XML parser library is updated to the latest available version (2.6.2).
- The lz4 compression library is updated to the latest version as of July 2024.
- The internal SQLite drive is now the latest version.
- The libssh was updated to the latest available version.
- The version of Openssl was updated to 3.0.15.
- The expat XML parser library is updated to the latest available version (2.6.3).
- The Highcharts library has been updated to version 11.4.8.
- The embedded Tomcat server is updated to version 9.0.95.
- The Java runtime environment included with Pipeline Pilot is upgraded to Java 17.
- Python has been updated to version 3.9.19.
- The Apache httpd server is updated to version 2.4.61.