The Apache Software Foundation Blog

Monday October 25, 2021

The Apache News Round-up: week ending 22 October 2021

We're wrapping up another great week with the following activities from the Apache community:

ASF Board – management and oversight of the business affairs of the corporation in accordance with the Foundation's bylaws.
 - Next Board Meeting: 17 November 2021. Board calendar and minutes https://apache.org/foundation/board/calendar.html

ApacheCon™ – the ASF's official global conference series, bringing Tomorrow's Technology Today since 1998.
 - Our 2021 events are complete: thanks to all speakers, sponsors, participants, and planners for their great turnout!
 - Presentations for ApacheCon Asia and ApacheCon@Home are available on the ASF YouTube channel.

ASF Infrastructure – our distributed team on three continents keeps the ASF's infrastructure running around the clock.
 - 7M+ weekly checks yield uptime at 100.00%. Performance checks across 50 different service components spread over more than 250 machines in data centers around the world. View the Apache Infrastructure Uptime site to see the most recent averages.

Apache Code Snapshot – Over the past week, 313 Apache Committers changed 7,080,993 lines of code over 2,545 commits. Top 5 contributors, in order, are: Claus Ibsen, Gary Gregory, Jarek Potiuk, Andi Huber, Andrea Cosentino, and Tamas Cservenak.

Apache Project Announcements – the latest updates by category.

Big Data --
 - Apache Calcite 1.28.0 released
 - Apache DataFu 1.6.1 released
 - Apache XMLBeans 5.0.2 released
 - Apache Flink 1.13.3 released
 - Apache Storm 1.2.4, 2.1.1 and 2.2.1 released
   -- CVE-2021-38294: Apache Storm: Shell Command Injection Vulnerability in Nimbus Thrift Server
   -- CVE-2021-40865: Apache Storm: Unsafe Pre-Authentication Deserialization In Workers

Build Management --
 - Apache Ant 1.10.12 released

Messaging --
 - Apache Qpid Proton-J 0.33.10 and JMS 1.3.0 released

Observability --
 - Apache SkyWalking CLI 0.9.0 and Eyes 0.2.0 released

Search --
 - Apache Lucene 8.10.1 released
 - Apache Solr 8.10.1 released

Servers --
 - Apache HttpComponents Core 5.2-alpha2 released


Did You Know?

 - Did you know that the ASF's 2021 multi-national Board of Directors comprises members from Australia, Germany, the Netherlands, Sweden, Switzerland, and the United States, as well as our first Board member from China?

 - Did you know that Flink Forward starts next week? Sign up today and join online 26-27 October?

 - Did you know that the next CloudStack Collaboration Conference will be held online 9-12 November?

Apache Community Notices

- The Apache Month in Review: September 2021 https://s.apache.org/September2021 and video highlights https://youtu.be/v3GdwUmevog

- Watch "Trillions and Trillions Served", the documentary on the ASF 1) full feature [49 min] 2) "Apache Everywhere" [6 min] 3) "Why Apache" [2.5 min] 4) “Apache Innovation” [40 min] 

 - ASF Annual Report: FY2021 -- Press release and Report (PDF)

 - The Apache Way to Sustainable Open Source Success 

 - Foundation Reports and Statements

 - Presentations from ApacheCon Asia are available on YouTube

 - "Success at Apache" focuses on the people and processes behind why the ASF "just works." 

 - Inside Infra: the new interview series with members of the ASF infrastructure team --meet 
    Chris Thistlethwaite https://s.apache.org/InsideInfra-Chris
    Drew Foulks https://s.apache.org/InsideInfra-Drew
    Greg Stein Part I https://s.apache.org/InsideInfra-Greg
      ...Part II https://s.apache.org/InsideInfra-Greg2 and Part III https://s.apache.org/InsideInfra-Greg3
    Daniel Gruno Part I https://s.apache.org/InsideInfra-Daniel1 and Part II https://s.apache.org/InsideInfra-Daniel2
    Gavin McDonald Part I https://s.apache.org/InsideInfra-Gavin and Part II https://s.apache.org/InsideInfra-Gavin2
    Andrew Wetmore Part I https://s.apache.org/InsideInfra-Andrew and Part II https://s.apache.org/InsideInfra-Andrew2
    Chris Lambertus Part I  https://s.apache.org/InsideInfra-ChrisL  and Part II https://s.apache.org/InsideInfra-ChrisL2

 - Follow the ASF on social media: @TheASF on Twitter and The ASF page LinkedIn

 - Follow the Apache Community on Facebook and Twitter

 - Are your software solutions Powered by Apache? Download & use our "Powered By" logos.


Stay updated about The ASF

For real-time updates, sign up for Apache-related news by sending mail to announce-subscribe@apache.org and follow @TheASF on Twitter. For a broader spectrum from the Apache community, https://twitter.com/PlanetApache provides an aggregate of Project activities as well as the personal blogs and tweets of select ASF Committers.



Monday October 18, 2021

The Apache News Round-up: week ending 15 October 2021

Happy Friday, everyone. The Apache community has had another great week. Let's review what we've been up to:

ASF Board – management and oversight of the business affairs of the corporation in accordance with the Foundation's bylaws.
 - Next Board Meeting: 20 October 2021. Board calendar and minutes https://apache.org/foundation/board/calendar.html

ApacheCon™ – the ASF's official global conference series, bringing Tomorrow's Technology Today since 1998.
 - Our 2021 events are complete: thanks to all speakers, sponsors, participants, and planners for their great turnout!
 - Presentations for ApacheCon Asia and ApacheCon@Home are available on the ASF YouTube channel.

ASF Infrastructure – our distributed team on three continents keeps the ASF's infrastructure running around the clock.
 - 7M+ weekly checks yield uptime at 100.00%. Performance checks across 50 different service components spread over more than 250 machines in data centers around the world. View the Apache Infrastructure Uptime site to see the most recent averages.

Apache Code Snapshot – Over the past week, 305 Apache Committers changed 2,145,460 lines of code over 2,767 commits. Top 5 contributors, in order, are: Claus Ibsen, Jarek Potiuk, Tilman Hausherr, Tamas Cservenak, and Jacques Le Roux.

Apache Project Announcements – the latest updates by category.

Big Data --
 - Apache Storm 1.2.4, 2.1.1 and 2.2.1 released
 - Apache Calcite Avatica 1.19.0 released
 - Apache CouchDB 3.2.0 released
 - Apache ShardingSphere ElasticJob 3.0.1 released

Business Intelligence --
 - Apache Superset CVE-2021-41971: Possible SQL Injection when template processing is enabled

Content --
 - Apache OpenOffice 4.1.11 released
   -- CVE-2021-41830: Double Certificate Attack
   -- CVE-2021-41831: Timestamp Manipulation with Signature Wrapping
   -- CVE-2021-41832: Content Manipulation with Certificate Validation Attack
 - Apache Jackrabbit 2.21.8 and Oak 1.22.9 released
 - Apache Syncope 2.1.10 released

Geospatial --
 - Apache SIS 1.1 released

Integration --
 - Apache Camel 3.11.3 (LTS) released

Observability --
 - Apache SkyWalking Client JS 0.7.0 released

Orchestration --
 - Apache Hop (Incubating) 1.0 released

Servers --
 - Apache Tomcat 8.5.72 released
   -- CVE-2021-42340: Apache Tomcat DoS
 - Apache Traffic Control 6.0.0 released
   -- CVE-2021-42009: Control Arbitrary Email Content Insertion in /deliveryservices/request

Workflow --
 - Apache Airflow 2.2.0 and Providers (Amazon 2.3.0) released

Did You Know?

 - Did you know that the ASF has moved to CDN distribution for software? https://blogs.apache.org/foundation/entry/apache-software-foundation-moves-to

 - Did you know that Druid Summit will be held online 9-10 November? http://druid.apache.org/

 - Did you know that the next 3Hx - Apache Hop (Incubating) Hot Hop Hangout will be held online 28 October? https://hop.apache.org/community/events/

Apache Community Notices

- The Apache Month in Review: September 2021 https://s.apache.org/September2021 and video highlights https://youtu.be/v3GdwUmevog

- Watch "Trillions and Trillions Served", the documentary on the ASF 1) full feature [49 min] 2) "Apache Everywhere" [6 min] 3) "Why Apache" [2.5 min] 4) “Apache Innovation” [40 min] 

 - ASF Annual Report: FY2021 -- Press release and Report (PDF)

 - The Apache Way to Sustainable Open Source Success 

 - Foundation Reports and Statements

 - Presentations from ApacheCon Asia are available on YouTube

 - "Success at Apache" focuses on the people and processes behind why the ASF "just works." 

 - Inside Infra: the new interview series with members of the ASF infrastructure team --meet 
    Chris Thistlethwaite https://s.apache.org/InsideInfra-Chris
    Drew Foulks https://s.apache.org/InsideInfra-Drew
    Greg Stein Part I https://s.apache.org/InsideInfra-Greg
      ...Part II https://s.apache.org/InsideInfra-Greg2 and Part III https://s.apache.org/InsideInfra-Greg3
    Daniel Gruno Part I https://s.apache.org/InsideInfra-Daniel1 and Part II https://s.apache.org/InsideInfra-Daniel2
    Gavin McDonald Part I https://s.apache.org/InsideInfra-Gavin and Part II https://s.apache.org/InsideInfra-Gavin2
    Andrew Wetmore Part I https://s.apache.org/InsideInfra-Andrew and Part II https://s.apache.org/InsideInfra-Andrew2
    Chris Lambertus Part I  https://s.apache.org/InsideInfra-ChrisL  and Part II https://s.apache.org/InsideInfra-ChrisL2

 - Follow the ASF on social media: @TheASF on Twitter and The ASF page LinkedIn

 - Follow the Apache Community on Facebook and Twitter

 - Are your software solutions Powered by Apache? Download & use our "Powered By" logos.


Stay updated about The ASF

For real-time updates, sign up for Apache-related news by sending mail to announce-subscribe@apache.org and follow @TheASF on Twitter. For a broader spectrum from the Apache community, https://twitter.com/PlanetApache provides an aggregate of Project activities as well as the personal blogs and tweets of select ASF Committers.



Monday October 11, 2021

The Apache News Round-up: week ending 8 October 2021

We're wrapping up another great week with the following activities from the Apache community:

ASF Board – management and oversight of the business affairs of the corporation in accordance with the Foundation's bylaws.
 - Next Board Meeting: 20 October 2021. Board calendar and minutes https://apache.org/foundation/board/calendar.html

ApacheCon™ – the ASF's official global conference series, bringing Tomorrow's Technology Today since 1998.
 - Our 2021 events are complete: thanks to all speakers, sponsors, participants, and planners for their great turnout!
 - Presentations for ApacheCon Asia are available on the ASF YouTube channel. ApacheCon@Home presentations will be posted shortly.

ASF Infrastructure – our distributed team on three continents keeps the ASF's infrastructure running around the clock.
 - 7M+ weekly checks yield uptime at 100.00%. Performance checks across 50 different service components spread over more than 250 machines in data centers around the world. View the Apache Infrastructure Uptime site to see the most recent averages.

Apache Code Snapshot – Over the past week, 286 Apache Committers changed 24,759,115 lines of code over 2,590 commits. Top 5 contributors, in order, are: Jean-Baptiste Onofré, Andi Huber, Alex Herbert, Gary Gregory, and Daniel Sun.

Apache Project Announcements – the latest updates by category.

Big Data --
 - Apache CouchDB 3.1.2 released

Content
 - The Apache Software Foundation Announces Apache® OpenOffice® 4.1.11
    -- CVE-2021-33035: Buffer overflow from a crafted DBF file
    -- CVE-2021-40439: Billion Laughs

Integration --
 - Apache Camel 3.7.6 (LTS) released

Servers --
 - Apache HTTP Server 2.4.50 and 2.4.51 released
   -- CVE-2021-41524: null pointer dereference in h2 fuzzing
   -- CVE-2021-41773: Path traversal and file disclosure vulnerability
   -- CVE-2021-42013: Path Traversal and Remote Code Execution
- Apache Tomcat 9.0.54 released

Did You Know?

 - Did you know that Apache OpenOffice is now available from the Windows Store?

 - Did you know that the call for papers for TVMCon 2021 (online/free-of-charge 15-17 December) is now open?

 - Did you know that the call for papers for Ignite Summit (online/free-of-charge 16 November) closes soon?

Apache Community Notices

- The Apache Month in Review: September 2021 https://s.apache.org/September2021 and video highlights https://youtu.be/v3GdwUmevog

- Watch "Trillions and Trillions Served", the documentary on the ASF 1) full feature [49 min] 2) "Apache Everywhere" [6 min] 3) "Why Apache" [2.5 min] 4) “Apache Innovation” [40 min] 

 - ASF Annual Report: FY2021 -- Press release and Report (PDF)

 - The Apache Way to Sustainable Open Source Success 

 - Foundation Reports and Statements

 - Presentations from ApacheCon Asia are available on YouTube

 - "Success at Apache" focuses on the people and processes behind why the ASF "just works." 

 - Inside Infra: the new interview series with members of the ASF infrastructure team --meet 
    Chris Thistlethwaite https://s.apache.org/InsideInfra-Chris
    Drew Foulks https://s.apache.org/InsideInfra-Drew
    Greg Stein Part I https://s.apache.org/InsideInfra-Greg
      ...Part II https://s.apache.org/InsideInfra-Greg2 and Part III https://s.apache.org/InsideInfra-Greg3
    Daniel Gruno Part I https://s.apache.org/InsideInfra-Daniel1 and Part II https://s.apache.org/InsideInfra-Daniel2
    Gavin McDonald Part I https://s.apache.org/InsideInfra-Gavin and Part II https://s.apache.org/InsideInfra-Gavin2
    Andrew Wetmore Part I https://s.apache.org/InsideInfra-Andrew and Part II https://s.apache.org/InsideInfra-Andrew2
    Chris Lambertus Part I  https://s.apache.org/InsideInfra-ChrisL  and Part II https://s.apache.org/InsideInfra-ChrisL2

 - Follow the ASF on social media: @TheASF on Twitter and The ASF page LinkedIn

 - Follow the Apache Community on Facebook and Twitter

 - Are your software solutions Powered by Apache? Download & use our "Powered By" logos.


Stay updated about The ASF

For real-time updates, sign up for Apache-related news by sending mail to announce-subscribe@apache.org and follow @TheASF on Twitter. For a broader spectrum from the Apache community, https://twitter.com/PlanetApache provides an aggregate of Project activities as well as the personal blogs and tweets of select ASF Committers.



Monday October 04, 2021

The Apache News Round-up: week ending 1 October 2021

Welcome October --we've closed September with another great week. Here are the latest updates on the Apache community's activities:

Apache Month in Review – a round-up of our Round-ups and other newsworthy bits over the past month.
 - September Month in Review https://s.apache.org/September2021 --video highlights at https://youtu.be/v3GdwUmevog

ASF Board – management and oversight of the business affairs of the corporation in accordance with the Foundation's bylaws.
 - Next Board Meeting: 20 October 2021. Board calendar and minutes https://apache.org/foundation/board/calendar.html

ApacheCon™ – the ASF's official global conference series, bringing Tomorrow's Technology Today since 1998.
 - Our 2021 events are complete: thanks to all speakers, sponsors, participants, and planners for their great turnout!
 - Presentations for ApacheCon Asia are available on the ASF YouTube channel. ApacheCon@Home presentations will be posted shortly.

ASF Infrastructure – our distributed team on three continents keeps the ASF's infrastructure running around the clock.
 - 7M+ weekly checks yield uptime at 99.78%. Performance checks across 50 different service components spread over more than 250 machines in data centers around the world. View the Apache Infrastructure Uptime site to see the most recent averages.

Apache Code Snapshot – Over the past week, 298 Apache Committers changed 11,412,487 lines of code over 2,739 commits. Top 5 contributors, in order, are: Jean-Baptiste Onofré, Andi Huber, Mark Thomas, Gary Gregory, and Claus Ibsen.

Apache Project Announcements – the latest updates by category.

APIs --
 - Apache APISIX 2.10.0 released

Big Data --
 - Apache Storm 2.3.0 released
 - Apache Flink 1.14.0 released

Database --
 -
Apache DB DdlUtils CVE-2021-41616: 1.0 readobject vulnerability

Integration --
 - Apache Camel 3.12.0 released

Libraries --
 - Apache Log4cxx 0.12.1 released

Mail --
 - Apache James MIME4J 0.8.6 released

Messaging --
 - Apache Qpid JMS 1.2.0 released

Observability --
 - Apache SkyWalking 8.8.0 and 8.8.1 released

Search --
 - Apache Lucene 8.10.0 released
 - Apache Solr 8.10.0 released

Servers --
 - Apache HttpComponents Core 5.1.2 GA released


Did You Know?

 - Did you know that the following Apache Projects are celebrating Top-level Project (TLP) anniversaries this month? Congratulations to the Apache Incubator (19 years); Xalan and XML Graphics (17 years); MINA and Velocity (15 years); PDFBox (12 years); Thrift (11 years); JMeter (10 years); Cordova, Isis, and OpenOffice (9 years); jclouds (8 years); Calcite (6 years); Juneau and Kibble (4 years); Joshua and ServiceComb (3 years); SINGA and Submarine (2 years); Ozone (1 year)! https://projects.apache.org/committees.html?date

 - Did you know that the latest Feathercast interview features Apache NLPCraft (incubating)?

 - Did you know that Druid Summit will be held 9-10 November 2021?

Apache Community Notices

- Watch "Trillions and Trillions Served", the documentary on the ASF 1) full feature [49 min] 2) "Apache Everywhere" [6 min] 3) "Why Apache" [2.5 min] 4) “Apache Innovation” [40 min] 

 - ASF Annual Report: FY2021 -- Press release and Report (PDF)

 - The Apache Way to Sustainable Open Source Success 

 - Foundation Reports and Statements

 - Presentations from ApacheCon Asia are available on YouTube

 - "Success at Apache" focuses on the people and processes behind why the ASF "just works." 

 - Inside Infra: the new interview series with members of the ASF infrastructure team --meet 
    Chris Thistlethwaite https://s.apache.org/InsideInfra-Chris
    Drew Foulks https://s.apache.org/InsideInfra-Drew
    Greg Stein Part I https://s.apache.org/InsideInfra-Greg
      ...Part II https://s.apache.org/InsideInfra-Greg2 and Part III https://s.apache.org/InsideInfra-Greg3
    Daniel Gruno Part I https://s.apache.org/InsideInfra-Daniel1 and Part II https://s.apache.org/InsideInfra-Daniel2
    Gavin McDonald Part I https://s.apache.org/InsideInfra-Gavin and Part II https://s.apache.org/InsideInfra-Gavin2
    Andrew Wetmore Part I https://s.apache.org/InsideInfra-Andrew and Part II https://s.apache.org/InsideInfra-Andrew2
    Chris Lambertus Part I  https://s.apache.org/InsideInfra-ChrisL  and Part II https://s.apache.org/InsideInfra-ChrisL2

 - Follow the ASF on social media: @TheASF on Twitter and The ASF page LinkedIn

 - Follow the Apache Community on Facebook and Twitter

 - Are your software solutions Powered by Apache? Download & use our "Powered By" logos.


Stay updated about The ASF

For real-time updates, sign up for Apache-related news by sending mail to announce-subscribe@apache.org and follow @TheASF on Twitter. For a broader spectrum from the Apache community, https://twitter.com/PlanetApache provides an aggregate of Project activities as well as the personal blogs and tweets of select ASF Committers.


Friday October 01, 2021

Apache Month in Review: September 2021

Welcome to the latest monthly overview of events from the Apache community. Here's a summary of what happened in September [video highlights available] :

New this month --

- Success at Apache - This series focuses on the people and processes behind why the ASF "just works." The most recent entry is "From Mentee to PMC" by Ephraim Anierobi.

- The Apache Drill Project Announces Apache® DrillTM v1.19 Milestone Release

- Apache Ranger response to incorrect analyst report on Cloud data security

- Apache Month in Review: August 2021


Important Dates --

- Next Board Meeting: 20 October 2021. Board calendar and minutes http://apache.org/foundation/board/calendar.html


Infrastructure --

Our seven-member Infrastructure team on three continents oversees our highly-reliable, distributed network under the leadership of VP Infrastructure David Nalley and Infrastructure Administrator Greg Stein. ASF Infrastructure supports 300+ Apache projects and their communities across ~200 individual machines, 1,400+ repositories, 5-6PB in traffic annually, ~75M downloads per month, and 2-3M daily emails on 2,000+ lists. ASF Infra performs 7M+ weekly checks to ensure services are available around the clock. The average uptime in September was 99.87%. http://www.apache.org/uptime/


Committer Activity --

In September, 692 Apache Committers changed 31,529,765 lines of code over 13,104 commits. The Committers with the top 5 highest contributions, in order, were: Mark Thomas, Andrea Cosentino, Andi Huber, Harikrishna Patnala, and Daniel Gruno.


Project Releases and Updates --

New releases from Apache Airflow (Big Data); Any23 (Content); APISIX (API); Camel (Integration); Commons DBCP (Libraries); Commons RNG (Libraries); DolphinScheduler (Workflow); Drill (Big Data); Druid (Big Data); Geode (Database); Geronimo (Application Servers); Groovy (Programming Languages); HttpComponents (Servers); Hudi (Big Data); Ignite (Big Data); IoTDB (IoT); Jackrabbit (Content); jclouds (Cloud); Jena (Libraries); Kafka (Big Data); Karaf (Application Servers/Middleware); Log4j (Libraries); NetBeans (Integrated Development Environment); PDFBox (Content); Pulsar (Messaging); Qpid (Messaging); Shiro (Security Framework); Skywalking (Application Performance Management); Solr (Search); Tika (Big Data); Tomcat (Servers);  Wicket (Web Frameworks); Zeppelin (Big Data).

Apache Project Anniversaries in September: ServiceMix (14 years); Hive, Pig, and Shiro (11 years); Airavata, Bigtop, and SIS (9 years); Curator (8 years); Storm (7 years); Yetus (6 years); RocketMQ and Royale (4 years); Pulsar (3 years); Rya (2 years); IoTDB (1 year). Many happy returns!

The Apache Incubator is the primary entry path for projects wishing to become an official part of the ASF. More than three dozen projects are currently undergoing development in the Apache Incubator; new to the Incubator this month is Apache Linkis (computation middleware).

# # #

To see our Weekly News Round-ups (published every Friday), visit https://blogs.apache.org/foundation/ and click on the calendar or hop directly to https://blogs.apache.org/foundation/category/Newsletter . For real-time updates, sign up for Apache-related news by sending mail to announce-subscribe@apache.org and follow @TheASF on Twitter. We appreciate your support!

Calendar

Search

Hot Blogs (today's hits)

Tag Cloud

Categories

Feeds

Links

Navigation