The Apache News Round-up: week ending 21 September 2018
As another week draws to a close, let's take a look at the Apache community's activities from the past week:
ASF Board –management and oversight of the business affairs of the corporation in accordance with the Foundation's bylaws.
- The Apache Software Foundation Operations Summary: May - July 2018 https://s.apache.org/qiKn
- Next Board Meeting: 17 October. Board calendar and minutes http://apache.org/foundation/board/calendar.html
ASF Fundraising –support through donations and Sponsorship help offset the ASF's day-to-day operating expenses and keep Apache software for everyone.
- The Apache® Software Foundation Welcomes Tencent as its Newest Sponsor at the Platinum Level https://s.apache.org/KzEz
ApacheCon™ –the ASF's official global conference series, now in its 20th year.
- 24-27 September: T-3 days to Montreal. 100+ Apache project and community sessions, from CloudStack to Spark to Tomcat to Geospatial to Hackathon, BarCamp, and more. See you there! http://apachecon.com/acna18/
- Guest Post: looking forward to learning more about the wide array of projects in the Apache fold at ApacheCon https://s.apache.org/RkWd
- 4 December: Apache Roadshow DC and Open Source Job Fair. CFP open through 15 October http://www.apachecon.com/usroadshow18/
ASF Infrastructure –our distributed team on three continents keeps the ASF's infrastructure running around the clock.
- 7M+ weekly checks yield deft performance at 99.41% uptime. http://status.apache.org/
ASF Operations Factoid –this week, 504 Apache contributors changed 1,297,500 lines of code over 3,801 commits. Top 5 contributors, in order, are: Radu Cotescu, Jean-Baptiste Onofré, Carsten Ziegeler, Hervé Boutemy, and Carlos Sanchez Gonzalez.
Apache Attic –provides process and solutions to make it clear when an Apache project has reached its end of life.
- Apache Lucy has retired http://mail-archives.apache.org/mod_mbox/www-announce/201809.mbox/%3Cpony-a4cac82164ef67d9d07d379b5d5d8c4abe1e02ff-a56909df10a4d5ddf5298357d8c193a36e67aeb0%40announce.apache.org%3E
Apache Atlas™ –a scalable and extensible set of core foundational governance services.
- Apache Atlas 1.1.0 released http://atlas.apache.org/
Apache Calcite™ Avatica Go –framework for building database drivers; the Avatica Go client is a Go database/sql driver that enables Go programs to communicate with the Avatica server.
- Apache Calcite Avatica Go 3.2.0 released https://calcite.apache.org/
Apache Directory™ Studio –a complete directory tooling platform intended to be used with any LDAP server however it is particularly designed for use with ApacheDS.
- Apache Directory Studio 2.0-0-M14 released https://directory.apache.org/
Apache Flink™ –an Open Source stream processing framework for distributed, high-performing, always-available, and accurate data streaming applications.
- Apache Flink 1.5.4 and 1.6.1 released https://flink.apache.org/
Apache Jackrabbit™ –a scalable, high-performance hierarchical content repository designed for use as the foundation of modern world-class Web sites and other demanding content applications.
- Apache Jackrabbit Oak 1.6.14 released http://jackrabbit.apache.org/
Apache JMeter™ –a 100% pure Java application designed to test server applications.
- Apache JMeter 5.0 released http://jmeter.apache.org/
Apache Kylin™ –an Open Source Distributed Analytics Engine designed to provide SQL interface and multi-dimensional analysis (OLAP) on Apache Hadoop, supporting extremely large datasets.
- Apache Kylin 2.5.0 released https://kylin.apache.org/
Apache Portable Runtime™ –software libraries that provide a predictable and consistent interface to underlying platform-specific implementations.
- Apache Portable Runtime APR 1.6.5 released http://apr.apache.org/
Apache Pulsar (incubating) –a highly scalable, low latency messaging platform running on commodity hardware.
- Apache Pulsar 2.1.1-incubating released https://pulsar.incubator.apache.org/
Apache SpamAssassin™ –an extensible email filter used to identify spam.
- Apache SpamAssassin 3.4.2 released https://spamassassin.apache.org/
- Apache SpamAssassin 3.4.2 resolves CVE-2017-15705, CVE-2016-1238, CVE-2018-11780 & CVE-2018-11781 http://mail-archives.apache.org/mod_mbox/www-announce/201809.mbox/%3CCAMMMAUH38nTHLyjMkZQdhLHh6trT%2BEzd%3DMGhS%3D%2B%3DbTuGWcYJSA%40mail.gmail.com%3E
Apache Tika™ –a toolkit for detecting and extracting metadata and structured text content from various documents using existing parser libraries.
- Apache Tika 1.19 released http://tika.apache.org/
- [CVE-2018-11761] Apache Tika DoS XML Entity Expansion Vulnerability http://mail-archives.apache.org/mod_mbox/www-announce/201809.mbox/%3CCAC1dCwVx2Z1haCnvYBhH7nQRN4kYKjwkLfjsCbeFHv2tRcBonA%40mail.gmail.com%3E
- [CVE-2018-11762] Zip Slip Vulnerability in Apache Tika's tika-app http://mail-archives.apache.org/mod_mbox/www-announce/201809.mbox/%3CCAC1dCwV2-kTJKjNO1rV65bQrekkur7OWAu1x%2BpPRToRRYk%3DGPA%40mail.gmail.com%3E
- [CVE-2018-8017] Apache Tika Denial of Service Vulnerability -- Potential Infinite Loop in IptcAnpaParser http://mail-archives.apache.org/mod_mbox/www-announce/201809.mbox/%3CCAC1dCwVOEYsB1c4s2DYkhsafT8q3Fupt_OFugXj9J1RCZuf3UQ%40mail.gmail.com%3E
Apache Tomcat™ –an Open Source software implementation of the Java Servlet, JavaServer Pages, Java Unified Expression Language, Java WebSocket and JASPIC technologies.
- Apache Tomcat 7.0.91 released https://tomcat.apache.org/
Apache Wicket™ –an Open Source Java component oriented Web application framework that powers thousands of Web applications and Web sites for governments, stores, universities, cities, banks, email providers, and more.
- Apache Wicket 8.1.0 released http://wicket.apache.org/
Did You Know?
- Did you know that, according to a survey by DZone asking "What Open Source Software Do You Use?", the leading answer is "Apache"? https://projects.apache.org/
- Did you know that Apache CouchDB provides binaries (RPMs and debs)? http://couchdb.apache.org/
- Did you know that you can join us at BarCampApache next week during ApacheCon? https://wiki.apache.org/apachecon/BarCampApacheMontreal
Apache Community Notices:
- ASF Annual Report for FY2018 https://s.apache.org/FY2018AnnualReport
- The Apache Software Foundation Celebrates 19 Years of Open Source Leadership "The Apache Way" https://s.apache.org/gK4Q
- Read "Open – For Business – At the ASF" by Merv Adrian, VP Research at Gartner https://blogs.gartner.com/merv-adrian/2018/03/27/open-for-business-at-the-asf/
- The Apache Software Foundation 2018 Vision Statement https://s.apache.org/zqC3
- Apache in 2017 - By The Digits https://s.apache.org/h8do
- Foundation Statement –Apache Is Open. https://s.apache.org/PIRA
- "Success at Apache" focuses on the processes behind why the ASF "just works". https://blogs.apache.org/foundation/category/SuccessAtApache
- Please follow/like/re-tweet the ASF on social media: @TheASF on Twitter and on LinkedIn at https://www.linkedin.com/company/the-apache-software-foundation
- Do friend and follow us on the Apache Community Facebook page https://www.facebook.com/ApacheSoftwareFoundation/and Twitter account https://twitter.com/ApacheCommunity
- The list of Apache project-related MeetUps can be found at http://events.apache.org/event/meetups.html
- ApacheCon North America will be held 24-27 September in Montreal http://apachecon.com/
- The Apache Spark community will be presenting at In-Memory Computing Summit North America 2-3 October in San Francicso https://www.imcsummit.org/2018/us/
- The Apache Big Data community will be at DataWorks Summit 18-21 March 2019 in Barcelona and 20-23 May 2019 in Washington DC https://dataworkssummit.com/
- Find out how you can participate with Apache community/projects/activities --opportunities open with Apache HTTP Server, Avro, ComDev (community development), Directory, Incubator, OODT, POI, Polygene, Syncope, Tika, Trafodion, and more! https://helpwanted.apache.org/
# # #