BIOVIA Support often get questions related to security updates of third-party components used in Pipeline Pilot.
For each release, these third-party updates are listed in the Product Release Document (PRD) for that release.
Below is a list of third party updates for the recent Pipeline Pilot releases compiled from the PRDs.
Pipeline Pilot 2022 SP1
- The OpenSSL library has been updated to version 1.1.1o
- Updated the Apache httpd server to version 2.4.53
- The embedded Tomcat server has been updated to version 8.5.78
- Log4j has been replaced with the reload4j logging library.
Pipeline Pilot 2023
- The embedded Tomcat server has been updated to the latest security-fix version.
- Updated the Apache httpd server to version 2.4.54.
- Updated OpenSSL to the latest 1.1.1 version.
- The Java logging library reload4j is updated to the latest version 1.2.22
Pipeline Pilot 2023 SP1
- The embedded Tomcat server has been updated to the latest security-fix version.
Pipeline Pilot 2024
- The Java run time environment included with Pipeline Pilot is upgraded to Temurin-11.0.20+8.
- Apache is updated to version 2.4.57. Also, the httpd dependency apr is updated to version 1.7.3.
- Python is updated to version 3.9.16.
- The Perl installation used for the Perl (on Server) component is updated to Perl 5.36.0. For more information, see https://www.perl.org/.
- The ODBC drivers for Oracle, SQLServer, and MySQL are updated: Oracle is 8.00.02.2713, SQL Server is 8.00.02.1196, and MySQL is 8.00.02.218.
- Chromium Embedded is updated to the latest version as of September 2023.
- libssh is updated to the latest available version, 0.10.4.
- The internal SQLite driver used for various tasks within Pipeline Pilot is updated to the latest version.
- OpenSSL is updated to the latest 3.0 release as of September 2023.
- The lz4 compression library is updated to the latest version as of September 2023.
Pipeline Pilot 2024 SP1
- The Brotli compression library is updated to 1.1.0.
- libssh is updated to version 0.10.6. PPC: Third Party
- Openssl is updated to 3.0.13. PPC: Third Party
- The zlib library is updated to the latest available version (1.3.1).
- The expat XML parser library is updated to the latest available version (2.6.0).
- The Active MQ client library is updated to version 5.18.3.
- The embedded Tomcat server is updated from Tomcat 8.5 to Tomcat 9.
- Perl, which is primarily used by the Perl (on server) components, is updated to 5.36.3.
- Apache httpd is updated to 2.4.58.
