Apache CXF 3.6.7 Release Notes

1. Overview

The 3.6.x versions of Apache CXF is a significant new version of CXF
that provides several new features and enhancements.  

New features include:
* Support for Spring Boot 2.7 and Spring Security 5.8
* Many updated dependencies.  We've updated to the latest versions of most
  dependencies.  Some may be incompatible with previous versions.
  Some notables that may impact applications include:
    * Jetty upgraded to 10.x
    * Haxelcast to 5.2.x
    * Apache HttpClient 5.2.x support (Asynchronous Client HTTP Transport)
    * HTTP/2 support, new HttpClient based conduit for client side
    * JUnit 5 support

Important notes:
* 3.6 no longer supports Java 8.  Java11+ is required.

Users are encouraged to review the migration guide at:
http://cxf.apache.org/docs/36-migration-guide.html
for further information and requirements for upgrading from earlier
versions of CXF.

3.6.7 fixes over 10 issues/tasks reported by users.


2. Installation Prerequisites 

Before installing Apache CXF, make sure the following products,
with the specified versions, are installed on your system:

    * Java 11 Development Kit
    * Apache Maven 3.x to build the samples


3.  Integrating CXF Into Your Application

If you use Maven to build your application, you need merely add
appropriate dependencies. See the pom.xml files in the samples.

If you don't use Maven, you'll need to add one or more jars to your
classpath. The file lib/WHICH_JARS should help you decide which 
jars you need.

4. Building the Samples

Building the samples included in the binary distribution is easy. Change to
the samples directory and follow the build instructions in the README.txt file 
included with each sample.

5. Reporting Problems

If you have any problems or want to send feedback of any kind, please e-mail the
CXF dev list, dev@cxf.apache.org.  You can also file issues in JIRA at:

http://issues.apache.org/jira/browse/CXF

6. Migration notes:

See the migration guide at:
http://cxf.apache.org/docs/36-migration-guide.html
for caveats when upgrading.

7. Release Notes

** Bug
    * [CXF-8985] - headers masking implementation not replaceable
    * [CXF-9100] - HttpClient-1-Worker-* thread leak when throwing exception in LoggingOutInterceptor and sending large SOAP message
    * [CXF-9115] - Race Condition in HttpClientHttpConduit Causes Writing Thread to Hang Forever
    * [CXF-9117] - cxf-rt-ws-security fails if JCache is not on the classpath
    * [CXF-9118] - DelayedCachedOutputStreamCleaner may expire streams prematurely
    * [CXF-9121] - LEAK: ByteBuf.release() was not called before it's garbage-collected
    * [CXF-9124] - TransportURIResolver prints stack trace to stderr when using HTTP Authentication
    * [CXF-9128] - swaref does not use "cid:" reference scheme
    * [CXF-9132] - HttpClientHTTPConduit releases the client while there are connection(s) still using it




** Improvement
    * [CXF-9134] - When sending Multipart request do not wrap Attachment into another Attachment
