[this announcement is available online at https://s.apache.org/Qqx4 ]
Hello, Friday! The Apache community has been busy this week working on: Support Apache –if your employer has a matching gifts program, you can increase your contribution and help sustain the ASF's mission of providing software for the public good. Every dollar counts. http://apache.org/foundation/contributing.html ASF Board –management and oversight of the business affairs of the corporation in accordance with the Foundation's bylaws. - Next Board Meeting: 18 October. Board calendar and minutes http://apache.org/foundation/board/calendar.html - ASF Quarterly Report: Operations Summary Q1 FY2018 https://s.apache.org/cEUm ASF Infrastructure –our distributed team on three continents keeps the ASF's infrastructure running around the clock. - 7M+ weekly checks yield clever performance at 99.63% uptime http://status.apache.org/ ASF Operations Factoid –this week, 562 Committers changed 1,427,529 lines of code over 3,425 commits. Top 5 contributors, in order, are: Jian He; Carlo Curino; Dominik Stadler; Semen Boikov; and Claus Ibsen. Apache Arrow™ –a columnar in-memory analytics layer designed to accelerate Big Data. - Apache Arrow 0.7.0 released http://arrow.apache.org/ Apache BookKeeper™ DistributedLog –core library for interacting Apache BookKeeper in log streams and a proxy service for serving large number of logs, fan-in writes and fan-out reads. - Apache DistributedLog 0.5.0 released http://bookkeeper.apache.org/ Apache Commons™ BCEL –Byte Code Engineering Library (BCEL) is intended to give users a convenient way to analyze, create, and manipulate (binary) Java class files (those ending with .class). - Apache Commons BCEL 6.1 released http://commons.apache.org/ Apache Geode™ –Big Data management platform. - Apache Geode 1.2.1 released http://geode.apache.org/ Apache Geronimo™ Config –adds support for basic configuration nomenclatures based on the MicroProfile Config specification. - Apache Geronimo Config 1.0 released http://geronimo.apache.org/ Apache Gora™ –Open Source framework provides an in-memory data model and persistence for Big Data. - Apache Gora 0.8 released http://gora.apache.org/ Apache HBase™ –an Open Source, distributed, versioned, non-relational database. - Apache HBase 2.0.0-alpha-3 released http://hbase.apache.org/ Apache Ignite™ –in-memory computing platform that is durable, strongly consistent and highly available with powerful SQL, key-value and processing APIs. - Apache Ignite 2.2.0 released https://ignite.apache.org/ Apache Log4j™ –a well-known framework for logging application behavior. -Apache Log4j 2.9.1 released https://logging.apache.org/ Apache Lucene™ Solr –the popular, blazing fast, open source NoSQL search platform from the Apache Lucene project. - Apache Lucene and Solr 7.0.0 released http://lucene.apache.org/ - CVE-2017-9803: Security vulnerability in Kerberos delegation token functionality http://mail-archives.apache.org/mod_mbox/www-announce/201709.mbox/%3CCAOOKt53AOScg04zUh0%2BR_fcXD0C9s5mQ-OzdgYdnHz49u1KmXw%40mail.gmail.com%3E Apache OpenMeetings™ –provides video conferencing, instant messaging, white board, collaborative document editing and other groupware tools using API functions of the Red5 Streaming Server for Remoting and Streaming. - Apache OpenMeetings 3.3.2 released http://openmeetings.apache.org Apache OpenNLP™ –a machine learning based toolkit for the processing of natural language text. - Apache OpenNLP 1.8.2 released http://opennlp.apache.org/ Apache POI™ –well-known in the Java field as a library for reading and writing Microsoft Office file formats, such as Excel, PowerPoint, Word, Visio, Publisher and Outlook. - Apache POI 3.17 released https://poi.apache.org/ Apache Qpid™ Proton –a messaging library for the Advanced Message Queuing Protocol 1.0 (AMQP 1.0, ISO/IEC 19464, http://www.amqp.org). - Apache Qpid Proton-J 0.22.0 released http://qpid.apache.org/ Apache Storm™ –a distributed, fault-tolerant, and high-performance realtime computation system that provides strong guarantees on the processing of data. - Apache Storm 1.0.5 released http://storm.apache.org Apache Tephra (incubating)™ –a transaction engine for distributed data stores like Apache HBase. - Apache Tephra-0.13.0-incubating released http://tephra.apache.org/ Apache Tomcat™ –an Open Source software implementation of the Java Servlet, JavaServer Pages, Java Unified Expression Language, Java WebSocket and Java Authentication Service Provider Interface for Containers technologies. - CVE-2017-12615 Apache Tomcat Remote Code Execution via JSP upload http://mail-archives.apache.org/mod_mbox/www-announce/201709.mbox/%3C81e3acd3-f335-ff0d-ae89-bf44bb66fca0%40apache.org%3E - CVE-2017-12616 Apache Tomcat Information Disclosure http://mail-archives.apache.org/mod_mbox/www-announce/201709.mbox/%3C0b45dcb1-28e2-6e12-6320-5bc6d021063c%40apache.org%3E - CVE-2017-12615 Apache Tomcat Remote Code Execution via JSP upload http://mail-archives.apache.org/mod_mbox/www-announce/201709.mbox/%3C81e3acd3-f335-ff0d-ae89-bf44bb66fca0%40apache.org%3E - Apache Tomcat Possible additional RCE via JSP upload http://mail-archives.apache.org/mod_mbox/www-announce/201709.mbox/%3Caa9ea974-9acf-e0af-c3d7-46830b45d9fe%40apache.org%3E - End of life for Apache Tomcat Native 1.1.x http://mail-archives.apache.org/mod_mbox/www-announce/201709.mbox/%3Cdd2da94b-668b-4a8f-fbc3-845fe12e5907%40apache.org%3E Apache Wicket™ –an Open Source Java component oriented Web application framework. - Apache Wicket 7.9.0 released http://wicket.apache.org Apache Zeppelin™ –a collaborative data analytics and visualization tool for distributed, general-purpose data processing system such as Apache Spark, Apache Flink, etc. - Apache Zeppelin 0.7.3 released http://zeppelin.apache.org/ Did You Know? - Did you know that Reddit uses Apache Lucene Solr for its new search functionality for 300M users across 1.1M communities? http://lucene.apache.org/ - Did you know that 29,334 files in Apache NetBeans (incubating) were re-licensed to the ASF? http://netbeans.apache.org/ - Did you know that algorithmic IT operations platform StackState uses Apache Tinkerpop Gremlin for analytical queries? http://tinkerpop.apache.org/ Apache Community Notices: - "Success at Apache" focuses on the processes behind why the ASF "just works". 1) Project Independence https://s.apache.org/CE0V 2) All Carrot and No Stick https://s.apache.org/ykoG 3) Asynchronous Decision Making https://s.apache.org/PMvk4) Rule of the Makers https://s.apache.org/yFgQ 5) JFDI --the unconditional love of contributors https://s.apache.org/4pjM 6) Meritocracy and Me https://s.apache.org/tQQh 7) Learning to Build a Stronger Community https://s.apache.org/x9Be 8) Meritocracy. https://s.apache.org/DiEo 9) Lowering Barriers to Open Innovation https://s.apache.org/dAlg - Follow the ASF on social media: @TheASF on Twitter and on LinkedIn at https://www.linkedin.com/company/the-apache-software-foundation (re-tweets/shares/likes most appreciated!) - Presentations from ApacheCon https://s.apache.org/Hli7 and Apache: Big Data https://s.apache.org/tefE are available; as well as videos https://s.apache.org/AE3m and audio recordings https://feathercast.apache.org/ - Do friend and follow us on the Apache Community Facebook page https://www.facebook.com/ApacheSoftwareFoundation/and Twitter account https://twitter.com/ApacheCommunity - The list of Apache project-related MeetUps can be found at http://apache.org/events/meetups.html - TomcatCon will be held 25 September in London https://www.eventbrite.com/e/tomcatcon-london-2017-tickets-36683639754 - The Apache community will be at All Things Open --stop by the ASF booth and say hello! 23-24 October in Raleigh https://allthingsopen.org/ - Learn about Apache Atlas, AriaTosca (incubating), Hadoop YARN, Kafka, ManifoldCF, Ranger, Spot (incubating), Thrift, and more at Open Source Summit Europe + ELC Europe 2017 23-26 October in Prague https://osseu17.sched.com/ - Catch the Apache Ignite and Spark communities at the In-Memory Computing Summit 24-25 October in San Francisco https://imcsummit.org/ - ASF Annual Report is available at https://s.apache.org/FY2017AnnualReport - Find out how you can participate with Apache community/projects/activities --opportunities open with Apache HTTP Server, Avro, ComDev (community development), Directory, Incubator, OODT, POI, Polygene, Syncope, Tika, Trafodion, and more! https://helpwanted.apache.org/ - Are your software solutions Powered by Apache? Download & use our "Powered By" logos http://www.apache.org/foundation/press/kit/#poweredby = = = For real-time updates, sign up for Apache-related news by sending mail to announce-subscr...@apache.org and follow @TheASF on Twitter. For a broader spectrum from the Apache community, https://twitter.com/PlanetApache provides an aggregate of Project activities as well as the personal blogs and tweets of select ASF Committers. # # # NOTE: you are receiving this message because you are subscribed to the announce@apache.org distribution list. To unsubscribe, send email from the recipient account to announce-unsubscr...@apache.org with the word "Unsubscribe" in the subject line.