[ANN] Apache Tomcat 11.0.0-M21 (beta) available

2024-06-18 Thread Mark Thomas
The Apache Tomcat team announces the immediate availability of Apache Tomcat 11.0.0-M21 (beta). Apache Tomcat 11 is an open source software implementation of the Jakarta Servlet, Jakarta Server Pages, Jakarta Expression Language, Jakarta WebSocket, Jakarta Authentication and Jakarta Annotations

[ANNOUNCE] Apache Pekko Management 1.1.0-M1 released

2024-06-18 Thread PJ Fanning
The Apache Pekko Team is happy to announce the release of Apache Pekko Management 1.1.0-M1. This milestone release is aimed at previewing some of the changes in Pekko Management 1.1. This release should not be used in production. Apache Pekko is an open source toolkit and runtime simplifying the

[ANNOUNCE] Released Reactive client for Apache Pulsar, version 0.5.6

2024-06-18 Thread Chris Bono
The Apache Pulsar team is proud to announce the Reactive client for Apache Pulsar, version 0.5.6. The Reactive client for Apache Pulsar can be used together with any Reactive Streams implementation on the JVM. Examples include Project Reactor / Spring Reactive, Akka Streams, RxJava 3, Vert.x,

[ANNOUNCE] Apache StreamPipes 0.95.0

2024-06-17 Thread Dominik Riemer
The Apache StreamPipes community is pleased to announce the immediate availability of Apache StreamPipes 0.95.0. Apache StreamPipes is a self-service (Industrial) IoT toolbox to enable non-technical users to connect, analyze, and explore IoT data streams. The new release closes over 200 issues.

[ANNOUNCE] Apache James JSPF 1.0.4 released

2024-06-17 Thread Benoit TELLIER
The Apache James (https://james.apache.org) community is pleased to announce the availability of Apache James JSPF 1.0.4 library. Apache James JSPF is a library for parsing and validating SPF records (RFC-7208), written in plain Java. This release fixes DSNJava asynchronous capabilities.

[ANNOUNCE] Apache Wicket 8.16.0 released

2024-06-17 Thread Andrea Del Bene
The Apache Wicket PMC is proud to announce Apache Wicket 8.16.0! Apache Wicket is an open source Java component oriented web application framework that powers thousands of web applications and web sites for governments, stores, universities, cities, banks, email providers, and more. You can find

[ANNOUNCE] Apache Curator 5.7.0 released

2024-06-15 Thread tison
Hello, The Apache Curator team is pleased to announce the release of version 5.7.0. Apache Curator is a Java/JVM client library for Apache ZooKeeper[1], a distributed coordination service. Apache Curator includes a high-level API framework and utilities to make using Apache ZooKeeper much easier

[ANNOUNCE] Apache Daffodil 3.8.0 Released

2024-06-14 Thread Mike Beckerle
The Apache Daffodil community is pleased to announce the release of version 3.8.0. Notable changes in this release include a supported API for Daffodil layers. Layers are a Daffodil extension to the DFDL language which are small algorithmic code plugins for computing checksums/CRCs on regions of

[ANNOUNCE] Apache Jackrabbit 2.22.0 released

2024-06-14 Thread Julian Reschke
The Apache Jackrabbit community is pleased to announce the release of Apache Jackrabbit 2.22.0. The release is available for download at: http://jackrabbit.apache.org/downloads.html See the full release notes below for details about this release: Release Notes -- Apache Jackrabbit --

CVE-2024-25142: Apache Airflow: Cache Control - Storage of Sensitive Data in Browser Cache

2024-06-13 Thread Jarek Potiuk
Severity: low Affected versions: - Apache Airflow before 2.9.2 Description: Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow.  Airflow did not return "Cache-Control" header for dynamic content, which in case of some browsers could result in

CVE-2024-36265: Apache Submarine Server Core: authorization bypass

2024-06-12 Thread Arnout Engelen
Severity: important Affected versions: - Apache Submarine Server Core 0.8.0 or later Description: ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Core: from 0.8.0. As this project is retired,

CVE-2024-36264: Apache Submarine Commons Utils: default secret

2024-06-12 Thread Arnout Engelen
Severity: low Affected versions: - Apache Submarine Commons Utils 0.8.0 or later Description: ** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. This issue affects Apache Submarine Commons Utils: from 0.8.0. As this project is retired,

CVE-2024-36263: Apache Submarine Server Core: SQL injection

2024-06-12 Thread Arnout Engelen
Severity: important Affected versions: - Apache Submarine Server Core: all versions Description: ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Submarine Server Core. This issue affects Apache

[ANNOUNCE] Apache Pekko Persistence JDBC 1.1.0-M1 released

2024-06-11 Thread PJ Fanning
The Apache Pekko Team is happy to announce the release of Apache Pekko Persistence JDBC 1.1.0-M1. This milestone release is aimed at previewing some of the changes in Pekko Persistence JDBC 1.1. This release should not be used in production. Apache Pekko is an open source toolkit and runtime

[ANNOUNCE] Apache Pekko gRPC 1.1.0-M1 released

2024-06-11 Thread PJ Fanning
The Apache Pekko Team is happy to announce the release of Apache Pekko gRPC 1.1.0-M1. This milestone release is aimed at previewing some of the changes in Pekko gRPC 1.1. This release should not be used in production. Apache Pekko is an open source toolkit and runtime simplifying the construction

[ANNOUNCE] Apache Commons Configuration 2.11.0

2024-06-10 Thread Gary Gregory
The Apache Commons Team is pleased to announce Commons Configuration 2.11.0. The Commons Configuration software library provides a generic configuration interface that enables an application to read configuration data from a variety of sources. Commons Configuration includes tools to assist in

[ANNOUNCE] Apache Commons Net 3.11.1

2024-06-10 Thread Gary Gregory
The Apache Commons Net team is pleased to announce the release of Apache Commons Net 3.11.1. Apache Commons Net library contains a collection of network utilities and protocol implementations. Supported protocols include Echo, Finger, FTP, NNTP, NTP, POP3(S), SMTP(S), Telnet, and Whois. This is

[ANNOUNCE] Release Apache OpenDAL 0.47.0

2024-06-10 Thread tison
Hi all, The Apache OpenDAL community is pleased to announce that Apache OpenDAL 0.47.0 has been released! OpenDAL is a data access layer that allows users to easily and efficiently retrieve data from various storage services in a unified way. The notable changes since last release include: 1.

[ANNOUNCE] Apache Allura 1.17.0 released

2024-06-10 Thread Dave Brondsema
The Apache Allura team is pleased to announce the release of Apache Allura 1.17.0 Apache Allura is an open source implementation of a software forge, a web site that manages source code repositories, bug reports, discussions, wiki pages, blogs, and more for any number of individual projects.

CVE-2024-36471: Apache Allura: sensitive information exposure via DNS rebinding

2024-06-10 Thread David Philip Brondsema
Severity: important Affected versions: - Apache Allura 1.0.1 through 1.16.0 Description: Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL.  Project administrators can run these imports, which could cause Allura to read from internal

[ANNOUNCE] Apache Airflow 2.9.2 Released

2024-06-10 Thread Utkarsh Sharma
Dear community, I'm happy to announce that Airflow 2.9.2 was just released. The released sources and packages can be downloaded via https://airflow.apache.org/docs/apache-airflow/stable/installation/installing-from-sources.html Other installation methods are described in

[ANNOUNCE] Apache Pulsar C# Client DotPulsar 3.3.0 released

2024-06-10 Thread David Jensen
The Apache Pulsar team is proud to announce DotPulsar version 3.3.0. Pulsar is a highly scalable, low-latency messaging platform running on commodity hardware. It provides simple pub-sub semantics over topics, guaranteed at least once delivery of messages, automatic cursor management for

[ANNOUNCE] Apache Airflow Providers prepared on June 07, 2024 are released

2024-06-09 Thread Elad Kalif
Dear community, I'm happy to announce that new versions of Airflow Providers packages prepared on June 07, 2024 were just released. Full list of PyPI packages released is added at the end of the message. The source release, as well as the binary releases, are available here:

[ANNOUNCE] Apache Lucene 9.11.0 released

2024-06-07 Thread Benjamin Trent
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 The Lucene PMC is pleased to announce the release of Apache Lucene 9.11.0. Apache Lucene is a high-performance, full-featured search engine library written entirely in Java. It is a technology suitable for nearly any application that requires

[ANNOUNCE] Apache ServiceComb Java Chassis version 3.1.2 Released

2024-06-06 Thread liubao
Hi All, Apache ServiceComb Team is glad to announce the release of Apache ServiceComb Java Chassis 3.1.2. ServiceComb Java Chassis is a Software Development Kit (SDK) for rapid development of microservices in Java, providing service registration, service discovery, dynamic routing, and

[ANNOUNCE] Apache Commons JEXL 3.4.0

2024-06-06 Thread Gary Gregory
The Apache Commons team is pleased to announce Apache Commons JEXL 3.4.0. Apache Commons JEXL is a library that facilitates the implementation of scripting features in applications and frameworks written in Java. Java 8 is required. Historical list of changes:

[ANNOUNCE] Apache Jackrabbit 2.21.27-beta released

2024-06-06 Thread Julian Reschke
The Apache Jackrabbit community is pleased to announce the release of Apache Jackrabbit 2.21.27-beta. The release is available for download at: http://jackrabbit.apache.org/downloads.html See the full release notes below for details about this release: Release Notes -- Apache Jackrabbit

[ANNOUNCE] Apache Commons JEXL 3.4.0

2024-06-05 Thread Gary Gregory
The Apache Commons team is pleased to announce Apache Commons JEXL 3.4.0. Apache Commons JEXL is a library that facilitates the implementation of scripting features in applications and frameworks written in Java. Java 8 is required. Historical list of changes:

[ANNOUNCE] Apache Pulsar Helm Chart version 3.4.1 Released

2024-06-04 Thread Lari Hotari
Dear community, The Apache Pulsar team is pleased to announce the release of the Apache Pulsar Helm Chart 3.4.1. The official source release, as well as the binary Helm Chart release, are available at https://downloads.apache.org/pulsar/helm-chart/3.4.1/. The helm chart index at

[ANNOUNCE] Apache NetBeans 22 released

2024-06-04 Thread Eric Barboni
The Apache NetBeans team is pleased to announce that Apache NetBeans 22 was released on May 29, 2024. What's in the Apache NetBeans 22 release: https://github.com/apache/netbeans/releases/tag/22 With thanks to 25 contributors, including 3 who have contributed for the first time. Thank you!

[ANNOUNCE] Apache Commons JCS 3.2.1

2024-06-03 Thread Thomas Vandahl
The Apache Commons JCS team is pleased to announce the release of Apache Commons JCS 3.2.1. Apache Commons JCS is a distributed caching system written in Java. It is intended to speed up applications by providing means to manage cached data of various dynamic natures. This is a maintenance and

CVE-2024-36104: Apache OFBiz: Path traversal leading to a RCE

2024-06-03 Thread Jacques Le Roux
Severity: important Affected versions: - Apache OFBiz before 18.12.14 Description: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.14. Users are recommended to upgrade to version

[ANNOUNCE] Apache Airflow Providers prepared on May 30, 2024 are released

2024-06-03 Thread Elad Kalif
Dear community, I'm happy to announce that new versions of Airflow Providers packages prepared on May 30, 2024 were just released. Full list of PyPI packages released is added at the end of the message. The source release, as well as the binary releases, are available here:

[ANNOUNCE] Apache Kyuubi released 1.9.1

2024-06-03 Thread Cheng Pan
Hi all, The Apache Kyuubi community is pleased to announce that Apache Kyuubi 1.9.1 has been released! This release brings support for Apache Spark 4.0.0-preview1. Apache Kyuubi is a distributed and multi-tenant gateway to provide serverless SQL on data warehouses and lakehouses. Kyuubi

[ANNOUNCE] Apache FreeMarker 2.3.33 is released

2024-06-02 Thread Daniel Dekany
The Apache FreeMarker community is pleased to announce the release of Apache FreeMarker 2.3.33. Change log: https://freemarker.apache.org/docs/versions_2_3_33.html Download: https://freemarker.apache.org/freemarkerdownload.html Apache FreeMarker™ is a template engine: a Java library to generate

[ANNOUNCE] Apache Wicket 9.18.0 released

2024-06-02 Thread Andrea Del Bene
The Apache Wicket PMC is proud to announce Apache Wicket 9.18.0! Apache Wicket is an open source Java component oriented web application framework that powers thousands of web applications and web sites for governments, stores, universities, cities, banks, email providers, and more. You can find

[ANNOUNCE] Apache Wicket 10.1.0 released

2024-06-02 Thread Andrea Del Bene
The Apache Wicket PMC is proud to announce Apache Wicket 10.1.0! Apache Wicket is an open source Java component oriented web application framework that powers thousands of web applications and web sites for governments, stores, universities, cities, banks, email providers, and more. You can find

[ANNOUNCE] Apache Commons Net 3.11.0

2024-05-31 Thread Gary Gregory
The Apache Commons Net team is pleased to announce the release of Apache Commons Net 3.11.0. Apache Commons Net library contains a collection of network utilities and protocol implementations. Supported protocols include Echo, Finger, FTP, NNTP, NTP, POP3(S), SMTP(S), Telnet, and Whois.

[ANNOUNCE] Apache OFBiz 18.12.14 released

2024-05-31 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 18.12.14". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 18.12.14" is the

[ANNOUNCE] Release Apache Hop 2.9.0

2024-05-30 Thread Bart Maertens
The Apache Hop PMC and community are pleased to announce the general availability of Apache Hop 2.9.0. This 2.9.0 release is the result of a massive effort by the Apache Hop community and contains about two months of work on more than 80 tickets. The Hop Orchestration Platform, or Apache Hop,

[ANNOUNCE] Apache Airflow Providers prepared on May 26, 2024 are released

2024-05-30 Thread Elad Kalif
Dear Airflow community, I'm happy to announce that new versions of Airflow Providers packages prepared on May 26, 2024 were just released. Full list of PyPI packages released is added at the end of the message. The source release, as well as the binary releases, are available here:

[ANNOUNCE] Apache Solr 9.6.1 released

2024-05-30 Thread Houston Putman
The Solr PMC is pleased to announce the release of Apache Solr 9.6.1. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Solr project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database

[ANNOUNCE] Apache Arrow nanoarrow 0.5.0 Released

2024-05-29 Thread Dewey Dunnington
The Apache Arrow community is pleased to announce the 0.5.0 release of Apache Arrow nanoarrow. This initial release covers 79 resolved issues from 9 contributors[1]. The release is available now from [2], release notes are available at [3], and a blog post highlighting new features and breaking

[ANNOUNCE] Apache Jackrabbit Oak 1.64.0 released

2024-05-28 Thread Julian Reschke
The Apache Jackrabbit community is pleased to announce the release of Apache Jackrabbit Oak 1.64.0. The release is available for download at: http://jackrabbit.apache.org/downloads.html See the full release notes below for details about this release: Release Notes -- Apache Jackrabbit

[ANNOUNCE] Apache Pekko HTTP 1.1.0-M1 released

2024-05-28 Thread PJ Fanning
The Apache Pekko Team is happy to announce the release of Apache Pekko HTTP 1.1.0-M1. This milestone release is aimed at previewing some of the changes in Pekko HTTP 1.1. This release should not be used in production. Apache Pekko is an open source toolkit and runtime simplifying the construction

[ANNOUNCE] Apache XMLBeans 5.2.1 release

2024-05-27 Thread PJ Fanning
The Apache POI project is pleased to announce the release of Apache XMLBeans 5.2.1. The POI team took over the ownership of XMLBeans since version 3.0.0. See the downloads page for binary and source distributions: https://xmlbeans.apache.org/download Release Notes Changes The most

[ANN] Apache Maven 3.9.7 released

2024-05-26 Thread Slawomir Jaranowski
The Apache Maven team is pleased to announce the release of the Apache Maven 3.9.7 Apache Maven is a software project management and comprehension tool. Based on the concept of a project object model (POM), Maven can manage a project's build, reporting and documentation from a central piece of

[ANNOUNCE] Apache Impala 4.4.0 release

2024-05-25 Thread Zoltán Borók-Nagy
The Apache Impala team is pleased to announce the release of Impala 4.4.0. Impala is a high-performance distributed SQL engine. The release is available at: https://impala.apache.org/downloads.html Thanks, The Apache Impala team

[ANNOUNCE] Apache HBase 2.4.18 is now available for download

2024-05-25 Thread Duo Zhang
The HBase team is happy to announce the immediate availability of HBase 2.4.18. Apache HBase™ is an open-source, distributed, versioned, non-relational database. Apache HBase gives you low latency random access to billions of rows with millions of columns atop non-specialized hardware. To learn

[ANNOUNCEMENT] Commons Daemon 1.4.0 Released

2024-05-24 Thread Mark Thomas
The Apache Commons Team is pleased to announce the availability of Apache Commons Daemon 1.4.0 The Apache Commons Daemon software library provides a generic Daemon (unix) or Service (Windows) wrapper for Java code. Version 1.4.0 raises the minimum supported version of Java to Java 8 and

[ANNOUNCE] Apache Commons CLI Version 1.8.0

2024-05-23 Thread Gary Gregory
The Apache Commons Team is pleased to announce Apache Commons CLI Version 1.8.0. Apache Commons CLI provides a simple API for presenting, processing, and validating a Command Line Interface. This release contains new features and bug fixes and requires Java 8 or above. New Features

[ANN] Apache Syncope 3.0.7

2024-05-23 Thread Francesco Chicchiriccò
The Apache Syncope team is pleased to announce the release of Syncope 3.0.7 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . Syncope 3.0 Maggiore is now a full-fledged IAM system covering provisioning,

[ANNOUNCE] Apache YuniKorn v1.5.1 released

2024-05-23 Thread Wilfred Spiegelenburg
The Apache YuniKorn community is pleased to announce the general availability of Apache YuniKorn v1.5.1 Apache YuniKorn is a standalone resource scheduler responsible for scheduling batch jobs and long-running services on large scale distributed systems running in on-premises environments as well

[ANNOUNCE] Apache Arrow ADBC 12 released

2024-05-21 Thread David Li
The Apache Arrow community is pleased to announce the 12th release of the Apache Arrow ADBC libraries. It includes 56 resolved GitHub issues ([1]). Individual components are versioned separately: some packages are on version 0.12.0 and others are now version 1.0.0, with the release as a whole

[ANNOUNCE] Hive 2.x EOL

2024-05-20 Thread Ayush Saxena
Hi All, The Apache Hive Community has voted to declare the 2.x release line as End of Life. This means no further updates or releases will be made for this release line. We urge all Hive 2.x users to upgrade to the latest versions promptly to benefit from new features and ongoing support. -Ayush

[ANNOUNCE] Apache Arrow 16.1.0 released

2024-05-19 Thread Raúl Cumplido
The Apache Arrow community is pleased to announce the 16.1.0 release. It includes 34 resolved issues ([1]) since the 16.0.0 release. The release is available now from our website and [2]: http://arrow.apache.org/install/ Read about what's new in the release

[ANNOUNCE] Apache Pekko 1.1.0-M1 released

2024-05-19 Thread PJ Fanning
The Apache Pekko Team is happy to announce the release of Apache Pekko 1.1.0-M1. This milestone release is aimed at previewing some of the changes in Pekko 1.1. This release should not be used in production. Apache Pekko is an open source toolkit and runtime simplifying the construction of

[ANNOUNCE] Apache NiFi MiNiFi C++ 0.99.0 release

2024-05-18 Thread Gábor Gyimesi
Hello The Apache NiFi team would like to announce the release of Apache NiFi MiNiFi C++ 0.99.0. New features in this release: Added support for using NiFi 2.0 Python processors in MiNiFi C++ Added new python based multiplatform bootstrap script Added encryption support for sensitive properties

[ANNOUNCE] Apache Sedona 1.6.0 released

2024-05-18 Thread Jia Yu
Dear all, We are happy to report that we have released Apache Sedona 1.6.0. Thank you again for your help. Apache Sedona is a cluster computing system for processing large-scale spatial data. Vote thread (Permalink from https://lists.apache.org/list.html):

[ANNOUNCE] Apache Airflow Providers prepared on May 12, 2024 are released

2024-05-17 Thread Elad Kalif
Dear community, I'm happy to announce that new versions of Airflow Providers packages prepared on May 12, 2024 were just released. Full list of PyPI packages released is added at the end of the message. The source release, as well as the binary releases, are available here:

[ANNOUNCE] Apache Pulsar 3.2.3 released

2024-05-17 Thread Lari Hotari
The Apache Pulsar team is proud to announce Apache Pulsar version 3.2.3. Pulsar is a highly scalable, low latency messaging platform running on commodity hardware. It provides simple pub-sub semantics over topics, guaranteed at-least-once delivery of messages, automatic cursor management for

[ANNOUNCE] Apache Pulsar 3.0.5 released

2024-05-17 Thread Lari Hotari
The Apache Pulsar team is proud to announce Apache Pulsar version 3.0.5. Pulsar is a highly scalable, low latency messaging platform running on commodity hardware. It provides simple pub-sub semantics over topics, guaranteed at-least-once delivery of messages, automatic cursor management for

[ANNOUNCE] Apache Flink CDC 3.1.0 released

2024-05-17 Thread Qingsheng Ren
The Apache Flink community is very happy to announce the release of Apache Flink CDC 3.1.0. Apache Flink CDC is a distributed data integration tool for real time data and batch data, bringing the simplicity and elegance of data integration via YAML to describe the data movement and transformation

[ANNOUNCE] Apache NiFi 2.0.0-M3 Released

2024-05-17 Thread David Handermann
The Apache NiFi Team is pleased to announce the release of Apache NiFi 2.0.0-M3. Apache NiFi is an easy to use, powerful, and reliable system to process and distribute data. https://nifi.apache.org The release artifacts can be downloaded from the project website.

[ANNOUNCE] Released Reactive client for Apache Pulsar, version 0.5.5

2024-05-16 Thread Chris Bono
The Apache Pulsar team is proud to announce the Reactive client for Apache Pulsar, version 0.5.5. The Reactive client for Apache Pulsar can be used together with any Reactive Streams implementation on the JVM. Examples include Project Reactor / Spring Reactive, Akka Streams, RxJava 3, Vert.x,

[ANNOUNCE] Apache StormCrawler (Incubating) 3.0 released

2024-05-16 Thread Richard Zowalla
The Apache StormCrawler (Incubating) team is pleased to announce the release of version 3.0 of Apache StormCrawler (Incubating). StormCrawler is a collection of resources for building low-latency, customisable and scalable web crawlers on Apache Storm. Apache StormCrawler (Incubating) 3.0

[ANNOUNCE] Apache Commons Logging 1.3.2

2024-05-15 Thread Gary Gregory
The Apache Commons Logging team is pleased to announce the release of Apache Commons Logging 1.3.2. Apache Commons Logging is a thin adapter allowing configurable bridging to other, well-known logging systems. This is a feature and maintenance release. Java 8 or later is required. Historical

[ANNOUNCE] Apache ServiceComb Java Chassis version 3.1.1 Released

2024-05-14 Thread liubao
Hi All, Apache ServiceComb Team is glad to announce the release of Apache ServiceComb Java Chassis 3.1.1. ServiceComb Java Chassis is a Software Development Kit (SDK) for rapid development of microservices in Java, providing service registration, service discovery, dynamic routing, and

CVE-2024-32077: Apache Airflow: XSS vulnerability in Task Instance Log/Log Details

2024-05-14 Thread Ephraim Anierobi
Severity: moderate Affected versions: - Apache Airflow 2.9.0 before 2.9.1 Description: Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs.  Users are recommended to upgrade to version 2.9.1, which fixes

[ANN] Apache Tomcat 10.1.24 Available

2024-05-13 Thread Christopher Schultz
The Apache Tomcat team announces the immediate availability of Apache Tomcat 10.1.24. Apache Tomcat 10 is an open source software implementation of the Jakarta Servlet, Jakarta Server Pages, Jakarta Expression Language, Jakarta WebSocket, Jakarta Authentication and Jakarta Annotations

[ANNOUNCEMENT] Apache SkyWalking BanyanDB 0.6.0 Released

2024-05-13 Thread Hongtao Gao
Hi the SkyWalking Community On behalf of the SkyWalking Team, I’m glad to announce that SkyWalking BanyanDB 0.6.0 is now released. SkyWalking BanyanDB: An observability database, aims to ingest, analyze and store Metrics, Tracing and Logging data. SkyWalking: APM (application

[ANNOUNCE] Apache SkyWalking 10.0.0 released

2024-05-13 Thread Sheng Wu
Hi all, Apache SkyWalking Team is glad to announce the first release of Apache SkyWalking 10.0.0. SkyWalking: APM (application performance monitor) tool for distributed systems, especially designed for microservices, cloud native and container-based architectures. This release contains a number

[ANNOUNCE] Apache Jackrabbit 2.20.16 released

2024-05-13 Thread Julian Reschke
The Apache Jackrabbit community is pleased to announce the release of Apache Jackrabbit 2.20.16. The release is available for download at: http://jackrabbit.apache.org/downloads.html See the full release notes below for details about this release: Release Notes -- Apache Jackrabbit --

[ANNOUNCE] Apache Camel 4.6.0 Released

2024-05-10 Thread Gregor Zurowski
The Camel PMC is pleased to announce the release of Apache Camel 4.6.0. Apache Camel is an open source integration framework that empowers you to quickly and easily integrate various systems consuming or producing data. This release contains 108 new features and improvements. The release is

[ANNOUNCE] Apache Sedona 1.5.3 released

2024-05-10 Thread Jia Yu
Dear all, We are happy to report that we have released Apache Sedona 1.5.3. Thank you again for your help. Apache Sedona is a cluster computing system for processing large-scale spatial data. Vote thread (Permalink from https://lists.apache.org/list.html):

CVE-2024-34365: Apache Karaf Cave: Cave SSRF and arbitrary file access

2024-05-09 Thread Arnout Engelen
Severity: important Affected versions: - Apache Karaf Cave or later Description: ** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Karaf Cave.This issue affects all versions of Apache Karaf Cave. As this project is retired, we do not plan to release a version

CVE-2024-26579: Apache Inlong JDBC Vulnerability

2024-05-08 Thread Charles Zhang
Severity: important Affected versions: - Apache InLong 1.7.0 through 1.10 Description: Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.11.0,  the attackers can bypass using malicious parameters. Users are advised to

CVE-2024-32113: Apache OFBiz: Path traversal leading to RCE

2024-05-08 Thread Jacques Le Roux
Severity: important Affected versions: - Apache OFBiz before 18.12.13 Description: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version

[ANN] Apache Tomcat 11.0.0-M20 (alpha) available

2024-05-08 Thread Mark Thomas
The Apache Tomcat team announces the immediate availability of Apache Tomcat 11.0.0-M20 (alpha). Apache Tomcat 11 is an open source software implementation of the Jakarta Servlet, Jakarta Server Pages, Jakarta Expression Language, Jakarta WebSocket, Jakarta Authentication and Jakarta Annotations

[ANNOUNCE] Apache Sedona 1.5.2 released

2024-05-08 Thread Jia Yu
Dear all, We are happy to report that we have released Apache Sedona 1.5.2. Thank you again for your help. Apache Sedona is a cluster computing system for processing large-scale spatial data. Vote thread (Permalink from https://lists.apache.org/list.html):

[ANN] Apache Tomcat 9.0.89 available

2024-05-07 Thread Rémy Maucherat
The Apache Tomcat team announces the immediate availability of Apache Tomcat 9.0.89. Apache Tomcat 9 is an open source software implementation of the Java Servlet, JavaServer Pages, Java Unified Expression Language, Java WebSocket and JASPIC technologies. Apache Tomcat 9.0.89 is a bugfix and

[ANNOUNCE] Apache SkyWalking BanyanDB Java Client 0.6.0 released

2024-05-07 Thread Hongtao Gao
Hi all, On behalf of the SkyWalking BanyanDB Team, I'm glad to announce that SkyWalking BanyanDB Java Client 0.6.0 is now released. SkyWalking BanyanDB - Java Client: The client implementation for SkyWalking BanyanDB in Java SkyWalking BanyanDB: An observability database aims to ingest, analyze

[ANNOUNCE] Apache OFBiz 18.12.13 released

2024-05-07 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 18.12.13". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 18.12.13" is the

CVE-2024-28148: Apache Superset: Incorrect datasource authorization on explore REST API

2024-05-07 Thread Daniel Gaspar
Affected versions: - Apache Superset before 4.0.0 Description: An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request.This issue affects Apache Superset: before 4.0.0. Users are recommended to upgrade

[ANNOUNCE] Apache Calcite 1.37.0 released

2024-05-07 Thread Sergey Nuyanzin
The Apache Calcite team is pleased to announce the release of Apache Calcite 1.37.0. Calcite is a dynamic data management framework. Its cost-based optimizer converts queries, represented in relational algebra, into executable plans. Calcite supports many front-end languages and back-end data

[ANNOUNCE] Apache Geronimo BatchEE 2.0.0

2024-05-06 Thread fpapon
The Apache Geronimo team is pleased to announce the release of Apache Geronimo BatchEE 2.0.0. Apache BatchEE is a project providing an implementation of JBatch (aka jsr-352) and a set of useful extension for this specification. This is a feature release for the major 2.x. This release

[ANNOUNCE] Apache Camel 3.22.2 (LTS) Released

2024-05-06 Thread Gregor Zurowski
The Camel PMC is pleased to announce the release of Apache Camel 3.22.2 (LTS). Apache Camel is an open source integration framework that empowers you to quickly and easily integrate various systems consuming or producing data. This release contains 19 new features and improvements. The release

[ANNOUNCE] Apache Airflow 2.9.1 Released

2024-05-06 Thread Ephraim Anierobi
Dear community, I'm happy to announce that Airflow 2.9.1 was just released. The released sources and packages can be downloaded via https://airflow.apache.org/docs/apache-airflow/stable/installation/installing-from-sources.html Other installation methods are described in

[ANNOUNCE] Apache Airflow Providers prepared on May 01, 2024 are released

2024-05-06 Thread Elad Kalif
Dear community, I'm happy to announce that new versions of Airflow Providers packages prepared on May 01, 2024 were just released. Full list of PyPI packages released is added at the end of the message. The source release, as well as the binary releases, are available here:

Apache Archiva is now retired

2024-05-05 Thread Hervé Boutemy
Announcing that the Apache Archiva committers have voted to retire the project due to inactivity. Archiva mission was the creation and maintenance of software related to Build Artifact Repository Manager. Retiring a project is not as simple as turning everything off, as existing users need to

CVE-2023-35701: Apache Hive: Arbitrary command execution via JDBC driver

2024-05-03 Thread Stamatis Zampetakis
Severity: moderate Affected versions: - Apache Hive 4.0.0-alpha-1 before 4.0.0 Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Hive. The vulnerability affects the Hive JDBC driver component and it can potentially lead to arbitrary code

Apache Bahir is now retired

2024-05-02 Thread Hervé Boutemy
Announcing that the Apache Bahir committers have voted to retire the project due to inactivity. Bahir mission was to provide extensions to distributed analytic platforms such as Apache Spark. Retiring a project is not as simple as turning everything off, as existing users need to both know that

CVE-2024-32114: Apache ActiveMQ: Jolokia and REST API were not secured with default configuration

2024-05-01 Thread Jean-Baptiste Onofré
Severity: low Affected versions: - Apache ActiveMQ 6.0.0 through 6.1.1 Description: In Apache ActiveMQ 6.x, the default configuration doesn't secure the API web context (where the Jolokia JMX REST API and the Message REST API are located). It means that anyone can use these layers without any

[ANNOUNCE] Apache Nutch 1.20 Release

2024-04-30 Thread lewis john mcgibbney
The Apache Nutch Project Management Committee is pleased to announce the release of Apache Nutch v1.20. We strongly encourage users to upgrade to this release. Nutch is a well matured, production ready Web crawler. Nutch 1.x enables fine grained configuration, relying on Apache Hadoop™ data

[ANNOUNCE] Apache Arrow 16.0.0 released

2024-04-29 Thread Raúl Cumplido
The Apache Arrow community is pleased to announce the 16.0.0 release. It includes 385 resolved issues ([1]) since the 15.0.2 release. The release is available now from our website and [2]: http://arrow.apache.org/install/ Read about what's new in the release

[ANNOUNCE] Apache APISIX 3.9.1 has been released

2024-04-29 Thread Xin Rong
Hi folks, The Apache APISIX community is glad to announce that Apache APISIX 3.9.1 has been released. Apache APISIX is a cloud-native microservices API gateway, delivering the ultimate performance, security, open-source and scalable platform for all your APIs and microservices. Apache APISIX is

[ANNOUNCE] Apache APISIX 3.8.1 has been released

2024-04-29 Thread Xin Rong
Hi folks, The Apache APISIX community is glad to announce that Apache APISIX 3.8.1 has been released. Apache APISIX is a cloud-native microservices API gateway, delivering the ultimate performance, security, open-source and scalable platform for all your APIs and microservices. Apache APISIX is

[ANN] Apache ActiveMQ Classic 6.1.2 has been released!

2024-04-29 Thread Jean-Baptiste Onofré
The Apache ActiveMQ team is pleased to announce Apache ActiveMQ Classic 6.1.2 release. It's a maintenance release on the ActiveMQ 6.1.x series, bringing: - secure Jolokia and REST Message API by default - fix on runtimeConfigurationPlugin JMX MBean reload operation - fix when consuming empty

[ANNOUNCE] Apache Solr 9.6.0 released

2024-04-28 Thread Gus Heck
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 The Solr PMC is pleased to announce the release of Apache Solr 9.6.0. Solr is the popular, blazing fast, open source NoSQL search platform from the Apache Solr project. Its major features include powerful full-text search, hit highlighting, faceted

[ANNOUNCE] Apache Commons Codec 1.17.0

2024-04-27 Thread Gary Gregory
The Apache Commons Team is pleased to announce Apache Commons Codec 1.17.0. The Apache Commons Codec component contains encoder and decoders for various formats such as Base16, Base32, Base64, digest, and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also

  1   2   3   4   5   6   7   8   9   10   >