The Apache Software Foundation Blog
The Apache News Round-up: week ending 22 October 2021
We're wrapping up another great week with the following activities from the Apache community:
ASF Board – management and oversight of the business affairs of the corporation in accordance with the Foundation's bylaws.- Next Board Meeting: 17 November 2021. Board calendar and minutes https://apache.org/foundation/board/calendar.html
ApacheCon™ –
the ASF's official global conference series, bringing Tomorrow's
Technology Today since 1998.
- Our 2021 events are complete: thanks to all speakers, sponsors, participants, and planners for their great turnout!
- Presentations for ApacheCon Asia and ApacheCon@Home are available on the ASF YouTube channel.
ASF Infrastructure – our distributed team on three continents keeps the ASF's infrastructure running around the clock.
-
7M+ weekly checks yield uptime at 100.00%. Performance checks across 50
different service components spread over more than 250 machines in data
centers around the world. View the Apache Infrastructure Uptime site to see the most recent averages.
Apache Code Snapshot – Over the past week, 313 Apache Committers changed 7,080,993 lines of code over 2,545 commits. Top 5 contributors, in order, are: Claus Ibsen, Gary Gregory, Jarek Potiuk, Andi Huber, Andrea Cosentino, and Tamas Cservenak.
Apache Project Announcements – the latest updates by category.
Big Data --- Apache Calcite 1.28.0 released
- Apache DataFu 1.6.1 released
- Apache XMLBeans 5.0.2 released
- Apache Flink 1.13.3 released
- Apache Storm 1.2.4, 2.1.1 and 2.2.1 released
-- CVE-2021-38294: Apache Storm: Shell Command Injection Vulnerability in Nimbus Thrift Server
-- CVE-2021-40865: Apache Storm: Unsafe Pre-Authentication Deserialization In Workers
Build Management --
- Apache Ant 1.10.12 released
- Apache Qpid Proton-J 0.33.10 and JMS 1.3.0 released
Observability --
- Apache SkyWalking CLI 0.9.0 and Eyes 0.2.0 released
- Apache Lucene 8.10.1 released
- Apache Solr 8.10.1 releasedServers --
- Apache HttpComponents Core 5.2-alpha2 released
Did You Know?
- Did you know that the ASF's 2021 multi-national Board of Directors comprises members from Australia, Germany, the Netherlands, Sweden, Switzerland, and the United States, as well as our first Board member from China?
- Did you know that Flink Forward starts next week? Sign up today and join online 26-27 October?
- Did you know that the next CloudStack Collaboration Conference will be held online 9-12 November?
Apache Community Notices
- The Apache Month in Review: September 2021 https://s.apache.org/September2021 and video highlights https://youtu.be/v3GdwUmevog
- Watch "Trillions and Trillions Served", the documentary on the ASF 1) full feature [49 min] 2) "Apache Everywhere" [6 min] 3) "Why Apache" [2.5 min] 4) “Apache Innovation” [40 min]
- ASF Annual Report: FY2021 -- Press release and Report (PDF)
- The Apache Way to Sustainable Open Source Success
- Foundation Reports and Statements
- Presentations from ApacheCon Asia are available on YouTube
- "Success at Apache" focuses on the people and processes behind why the ASF "just works."
- Inside Infra: the new interview series with members of the ASF infrastructure team --meet
Chris Thistlethwaite https://s.apache.org/InsideInfra-Chris
Drew Foulks https://s.apache.org/InsideInfra-Drew
Greg Stein Part I https://s.apache.org/InsideInfra-Greg
...Part II https://s.apache.org/InsideInfra-Greg2 and Part III https://s.apache.org/InsideInfra-Greg3
Daniel Gruno Part I https://s.apache.org/InsideInfra-Daniel1 and Part II https://s.apache.org/InsideInfra-Daniel2
Gavin McDonald Part I https://s.apache.org/InsideInfra-Gavin and Part II https://s.apache.org/InsideInfra-Gavin2
Andrew Wetmore Part I https://s.apache.org/InsideInfra-Andrew and Part II https://s.apache.org/InsideInfra-Andrew2
Chris Lambertus Part I https://s.apache.org/InsideInfra-ChrisL and Part II https://s.apache.org/InsideInfra-ChrisL2
- Follow the ASF on social media: @TheASF on Twitter and The ASF page LinkedIn.
- Follow the Apache Community on Facebook and Twitter.
Stay updated about The ASF
For real-time updates, sign up for Apache-related news by sending mail to announce-subscribe@apache.org and follow @TheASF on Twitter. For a broader spectrum from the Apache community, https://twitter.com/PlanetApache provides an aggregate of Project activities as well as the personal blogs and tweets of select ASF Committers.
Posted at 12:18PM Oct 25, 2021
by Swapnil M Mane in Newsletter |
|
The Apache News Round-up: week ending 15 October 2021
Happy Friday, everyone. The Apache community has had another great week. Let's review what we've been up to:
ASF Board – management and oversight of the business affairs of the corporation in accordance with the Foundation's bylaws.- Next Board Meeting: 20 October 2021. Board calendar and minutes https://apache.org/foundation/board/calendar.html
ApacheCon™ –
the ASF's official global conference series, bringing Tomorrow's
Technology Today since 1998.
- Our 2021 events are complete: thanks to all speakers, sponsors, participants, and planners for their great turnout!
- Presentations for ApacheCon Asia and ApacheCon@Home are available on the ASF YouTube channel.
ASF Infrastructure – our distributed team on three continents keeps the ASF's infrastructure running around the clock.
-
7M+ weekly checks yield uptime at 100.00%. Performance checks across 50
different service components spread over more than 250 machines in data
centers around the world. View the Apache Infrastructure Uptime site to see the most recent averages.
Apache Code Snapshot – Over the past week, 305 Apache Committers changed 2,145,460 lines of code over 2,767 commits. Top 5 contributors, in order, are: Claus Ibsen, Jarek Potiuk, Tilman Hausherr, Tamas Cservenak, and Jacques Le Roux.
Apache Project Announcements – the latest updates by category.
Big Data --- Apache Storm 1.2.4, 2.1.1 and 2.2.1 released
- Apache Calcite Avatica 1.19.0 released
- Apache CouchDB 3.2.0 released
- Apache ShardingSphere ElasticJob 3.0.1 released
Business Intelligence --
- Apache Superset CVE-2021-41971: Possible SQL Injection when
template processing is enabled
Content --
- Apache OpenOffice 4.1.11 released
-- CVE-2021-41830: Double Certificate Attack
-- CVE-2021-41831: Timestamp Manipulation with
Signature Wrapping
-- CVE-2021-41832: Content Manipulation with
Certificate Validation Attack
- Apache Jackrabbit 2.21.8 and Oak 1.22.9 released
- Apache Syncope 2.1.10 released
Geospatial --
- Apache SIS 1.1 released
- Apache Camel 3.11.3 (LTS) released
Observability --
- Apache SkyWalking Client JS 0.7.0 released
Orchestration --
- Apache Hop (Incubating) 1.0 released
- Apache Tomcat 8.5.72 released
-- CVE-2021-42340: Apache Tomcat DoS
- Apache Traffic Control 6.0.0 released
-- CVE-2021-42009: Control Arbitrary Email Content Insertion in /deliveryservices/request
Workflow --
- Apache Airflow 2.2.0 and Providers (Amazon 2.3.0) released
Did You Know?
- Did you know that the ASF has moved to CDN distribution for software? https://blogs.apache.org/foundation/entry/apache-software-foundation-moves-to
- Did you know that Druid Summit will be held online 9-10 November? http://druid.apache.org/
- Did you know that the next 3Hx - Apache Hop (Incubating) Hot Hop Hangout will be held online 28 October? https://hop.apache.org/community/events/
Apache Community Notices
- The Apache Month in Review: September 2021 https://s.apache.org/September2021 and video highlights https://youtu.be/v3GdwUmevog
- Watch "Trillions and Trillions Served", the documentary on the ASF 1) full feature [49 min] 2) "Apache Everywhere" [6 min] 3) "Why Apache" [2.5 min] 4) “Apache Innovation” [40 min]
- ASF Annual Report: FY2021 -- Press release and Report (PDF)
- The Apache Way to Sustainable Open Source Success
- Foundation Reports and Statements
- Presentations from ApacheCon Asia are available on YouTube
- "Success at Apache" focuses on the people and processes behind why the ASF "just works."
- Inside Infra: the new interview series with members of the ASF infrastructure team --meet
Chris Thistlethwaite https://s.apache.org/InsideInfra-Chris
Drew Foulks https://s.apache.org/InsideInfra-Drew
Greg Stein Part I https://s.apache.org/InsideInfra-Greg
...Part II https://s.apache.org/InsideInfra-Greg2 and Part III https://s.apache.org/InsideInfra-Greg3
Daniel Gruno Part I https://s.apache.org/InsideInfra-Daniel1 and Part II https://s.apache.org/InsideInfra-Daniel2
Gavin McDonald Part I https://s.apache.org/InsideInfra-Gavin and Part II https://s.apache.org/InsideInfra-Gavin2
Andrew Wetmore Part I https://s.apache.org/InsideInfra-Andrew and Part II https://s.apache.org/InsideInfra-Andrew2
Chris Lambertus Part I https://s.apache.org/InsideInfra-ChrisL and Part II https://s.apache.org/InsideInfra-ChrisL2
- Follow the ASF on social media: @TheASF on Twitter and The ASF page LinkedIn.
- Follow the Apache Community on Facebook and Twitter.
Stay updated about The ASF
For real-time updates, sign up for Apache-related news by sending mail to announce-subscribe@apache.org and follow @TheASF on Twitter. For a broader spectrum from the Apache community, https://twitter.com/PlanetApache provides an aggregate of Project activities as well as the personal blogs and tweets of select ASF Committers.
Posted at 01:17PM Oct 18, 2021
by Swapnil M Mane in Newsletter |
|
The Apache News Round-up: week ending 8 October 2021
We're wrapping up another great week with the following activities from the Apache community:
ASF Board – management and oversight of the business affairs of the corporation in accordance with the Foundation's bylaws.- Next Board Meeting: 20 October 2021. Board calendar and minutes https://apache.org/foundation/board/calendar.html
ApacheCon™ –
the ASF's official global conference series, bringing Tomorrow's
Technology Today since 1998.
- Our 2021 events are complete: thanks to all speakers, sponsors, participants, and planners for their great turnout!
- Presentations for ApacheCon Asia are available on the ASF YouTube channel. ApacheCon@Home presentations will be posted shortly.
ASF Infrastructure – our distributed team on three continents keeps the ASF's infrastructure running around the clock.
-
7M+ weekly checks yield uptime at 100.00%. Performance checks across 50
different service components spread over more than 250 machines in data
centers around the world. View the Apache Infrastructure Uptime site to see the most recent averages.
Apache Code Snapshot – Over the past week, 286 Apache Committers changed 24,759,115 lines of code over 2,590 commits. Top 5 contributors, in order, are: Jean-Baptiste Onofré, Andi Huber, Alex Herbert, Gary Gregory, and Daniel Sun.
Apache Project Announcements – the latest updates by category.
Big Data --- Apache CouchDB 3.1.2 released
Content
- The Apache Software Foundation Announces Apache® OpenOffice® 4.1.11
-- CVE-2021-33035: Buffer overflow from a crafted
DBF file
-- CVE-2021-40439: Billion Laughs
- Apache Camel 3.7.6 (LTS) releasedServers --
- Apache HTTP Server 2.4.50 and 2.4.51 released
-- CVE-2021-41524: null pointer dereference in h2 fuzzing
-- CVE-2021-41773: Path traversal and file disclosure vulnerability
-- CVE-2021-42013: Path Traversal and Remote Code Execution
- Apache Tomcat 9.0.54 released
Did You Know?
- Did you know that Apache OpenOffice is now available from the Windows Store?
- Did you know that the call for papers for TVMCon 2021 (online/free-of-charge 15-17 December) is now open?
- Did you know that the call for papers for Ignite Summit (online/free-of-charge 16 November) closes soon?
Apache Community Notices
- The Apache Month in Review: September 2021 https://s.apache.org/September2021 and video highlights https://youtu.be/v3GdwUmevog
- Watch "Trillions and Trillions Served", the documentary on the ASF 1) full feature [49 min] 2) "Apache Everywhere" [6 min] 3) "Why Apache" [2.5 min] 4) “Apache Innovation” [40 min]
- ASF Annual Report: FY2021 -- Press release and Report (PDF)
- The Apache Way to Sustainable Open Source Success
- Foundation Reports and Statements
- Presentations from ApacheCon Asia are available on YouTube
- "Success at Apache" focuses on the people and processes behind why the ASF "just works."
- Inside Infra: the new interview series with members of the ASF infrastructure team --meet
Chris Thistlethwaite https://s.apache.org/InsideInfra-Chris
Drew Foulks https://s.apache.org/InsideInfra-Drew
Greg Stein Part I https://s.apache.org/InsideInfra-Greg
...Part II https://s.apache.org/InsideInfra-Greg2 and Part III https://s.apache.org/InsideInfra-Greg3
Daniel Gruno Part I https://s.apache.org/InsideInfra-Daniel1 and Part II https://s.apache.org/InsideInfra-Daniel2
Gavin McDonald Part I https://s.apache.org/InsideInfra-Gavin and Part II https://s.apache.org/InsideInfra-Gavin2
Andrew Wetmore Part I https://s.apache.org/InsideInfra-Andrew and Part II https://s.apache.org/InsideInfra-Andrew2
Chris Lambertus Part I https://s.apache.org/InsideInfra-ChrisL and Part II https://s.apache.org/InsideInfra-ChrisL2
- Follow the ASF on social media: @TheASF on Twitter and The ASF page LinkedIn.
- Follow the Apache Community on Facebook and Twitter.
Stay updated about The ASF
For real-time updates, sign up for Apache-related news by sending mail to announce-subscribe@apache.org and follow @TheASF on Twitter. For a broader spectrum from the Apache community, https://twitter.com/PlanetApache provides an aggregate of Project activities as well as the personal blogs and tweets of select ASF Committers.
Posted at 08:08PM Oct 11, 2021
by Swapnil M Mane in Newsletter |
|
The Apache News Round-up: week ending 1 October 2021
Welcome October --we've closed September with another great week. Here are the latest updates on the Apache community's activities:
Apache Month in Review – a round-up of our Round-ups and other newsworthy bits over the past month.
- September Month in Review https://s.apache.org/September2021 --video highlights at https://youtu.be/v3GdwUmevog
- Next Board Meeting: 20 October 2021. Board calendar and minutes https://apache.org/foundation/board/calendar.html
ApacheCon™ –
the ASF's official global conference series, bringing Tomorrow's
Technology Today since 1998.
- Our 2021 events are complete: thanks to all speakers, sponsors, participants, and planners for their great turnout!
- Presentations for ApacheCon Asia are available on the ASF YouTube channel. ApacheCon@Home presentations will be posted shortly.
ASF Infrastructure – our distributed team on three continents keeps the ASF's infrastructure running around the clock.
-
7M+ weekly checks yield uptime at 99.78%. Performance checks across 50
different service components spread over more than 250 machines in data
centers around the world. View the Apache Infrastructure Uptime site to see the most recent averages.
Apache Code Snapshot – Over the past week, 298 Apache Committers changed 11,412,487 lines of code over 2,739 commits. Top 5 contributors, in order, are: Jean-Baptiste Onofré, Andi Huber, Mark Thomas, Gary Gregory, and Claus Ibsen.
Apache Project Announcements – the latest updates by category.
APIs --
- Apache APISIX 2.10.0 released
- Apache Storm 2.3.0 released
- Apache Flink 1.14.0 released
Database --
- Apache DB DdlUtils CVE-2021-41616: 1.0 readobject vulnerability
- Apache Camel 3.12.0 released
Libraries --
- Apache Log4cxx 0.12.1 released
Mail --
- Apache James MIME4J 0.8.6 released
Messaging --
- Apache Qpid JMS 1.2.0 released
Observability --
- Apache SkyWalking 8.8.0 and 8.8.1 released
Search --
- Apache Lucene 8.10.0 released
- Apache Solr 8.10.0 released
Servers --
- Apache HttpComponents Core 5.1.2 GA released
Did You Know?
- Did you know that the following Apache Projects are celebrating Top-level Project (TLP) anniversaries this month? Congratulations to the Apache Incubator (19 years); Xalan and XML Graphics (17 years); MINA and Velocity (15 years); PDFBox (12 years); Thrift (11 years); JMeter (10 years); Cordova, Isis, and OpenOffice (9 years); jclouds (8 years); Calcite (6 years); Juneau and Kibble (4 years); Joshua and ServiceComb (3 years); SINGA and Submarine (2 years); Ozone (1 year)! https://projects.apache.org/committees.html?date
- Did you know that the latest Feathercast interview features Apache NLPCraft (incubating)?
- Did you know that Druid Summit will be held 9-10 November 2021?
Apache Community Notices
- Watch "Trillions and Trillions Served", the documentary on the ASF 1) full feature [49 min] 2) "Apache Everywhere" [6 min] 3) "Why Apache" [2.5 min] 4) “Apache Innovation” [40 min]
- ASF Annual Report: FY2021 -- Press release and Report (PDF)
- The Apache Way to Sustainable Open Source Success
- Foundation Reports and Statements
- Presentations from ApacheCon Asia are available on YouTube
- "Success at Apache" focuses on the people and processes behind why the ASF "just works."
- Inside Infra: the new interview series with members of the ASF infrastructure team --meet
Chris Thistlethwaite https://s.apache.org/InsideInfra-Chris
Drew Foulks https://s.apache.org/InsideInfra-Drew
Greg Stein Part I https://s.apache.org/InsideInfra-Greg
...Part II https://s.apache.org/InsideInfra-Greg2 and Part III https://s.apache.org/InsideInfra-Greg3
Daniel Gruno Part I https://s.apache.org/InsideInfra-Daniel1 and Part II https://s.apache.org/InsideInfra-Daniel2
Gavin McDonald Part I https://s.apache.org/InsideInfra-Gavin and Part II https://s.apache.org/InsideInfra-Gavin2
Andrew Wetmore Part I https://s.apache.org/InsideInfra-Andrew and Part II https://s.apache.org/InsideInfra-Andrew2
Chris Lambertus Part I https://s.apache.org/InsideInfra-ChrisL and Part II https://s.apache.org/InsideInfra-ChrisL2
- Follow the ASF on social media: @TheASF on Twitter and The ASF page LinkedIn.
- Follow the Apache Community on Facebook and Twitter.
Stay updated about The ASF
For real-time updates, sign up for Apache-related news by sending mail to announce-subscribe@apache.org and follow @TheASF on Twitter. For a broader spectrum from the Apache community, https://twitter.com/PlanetApache provides an aggregate of Project activities as well as the personal blogs and tweets of select ASF Committers.
Posted at 05:02PM Oct 04, 2021
by Swapnil M Mane in Newsletter |
|
Apache Month in Review: September 2021
Welcome to the latest monthly overview of events from the Apache community. Here's a summary of what happened in September [video highlights available] :
New this month --
- Success at Apache - This series focuses on the people and processes behind why the ASF "just works." The most recent entry is "From Mentee to PMC" by Ephraim Anierobi.
- The Apache Drill Project Announces Apache® DrillTM v1.19 Milestone Release
- Apache Ranger response to incorrect analyst report on Cloud data security
- Apache Month in Review: August 2021
Important Dates --
- Next Board Meeting: 20 October 2021. Board calendar and minutes http://apache.org/foundation/board/calendar.html
Infrastructure --
Committer Activity --
In September, 692 Apache Committers changed 31,529,765 lines of code over 13,104 commits. The Committers with the top 5 highest contributions, in order, were: Mark Thomas, Andrea Cosentino, Andi Huber, Harikrishna Patnala, and Daniel Gruno.
Project Releases and Updates --
New releases from Apache Airflow (Big Data); Any23 (Content); APISIX (API); Camel (Integration); Commons DBCP (Libraries); Commons RNG (Libraries); DolphinScheduler (Workflow); Drill (Big Data); Druid (Big Data); Geode (Database); Geronimo (Application Servers); Groovy (Programming Languages); HttpComponents (Servers); Hudi (Big Data); Ignite (Big Data); IoTDB (IoT); Jackrabbit (Content); jclouds (Cloud); Jena (Libraries); Kafka (Big Data); Karaf (Application Servers/Middleware); Log4j (Libraries); NetBeans (Integrated Development Environment); PDFBox (Content); Pulsar (Messaging); Qpid (Messaging); Shiro (Security Framework); Skywalking (Application Performance Management); Solr (Search); Tika (Big Data); Tomcat (Servers); Wicket (Web Frameworks); Zeppelin (Big Data).
Apache Project Anniversaries in September: ServiceMix (14 years); Hive, Pig, and Shiro (11 years); Airavata, Bigtop, and SIS (9 years); Curator (8 years); Storm (7 years); Yetus (6 years); RocketMQ and Royale (4 years); Pulsar (3 years); Rya (2 years); IoTDB (1 year). Many happy returns!
The Apache Incubator is the primary entry path for projects wishing to become an official part of the ASF. More than three dozen projects are currently undergoing development in the Apache Incubator; new to the Incubator this month is Apache Linkis (computation middleware).
# # #
To see our Weekly News Round-ups (published every Friday), visit https://blogs.apache.org/foundation/ and click on the calendar or hop directly to https://blogs.apache.org/foundation/category/Newsletter . For real-time updates, sign up for Apache-related news by sending mail to announce-subscribe@apache.org and follow @TheASF on Twitter. We appreciate your support!
Posted at 06:19PM Oct 01, 2021
by Swapnil M Mane in Newsletter |
|