Thanks for catching the LICENSE issue. I found a couple more we should take a look at.
Dependency LICENSE NOTICE Caffeine GCP: Add missing attribution (PR #18218 <https://github.com/apache/iceberg/pull/18218>) No change needed CEL Java GCP, Kafka Connect main and Hive: Add attribution Verify requirements OpenTelemetry Kafka Connect main and Hive: Review missing attribution Verify requirements Apache HttpComponents 5 AWS: Confirm existing attribution covers v5 Verify upstream NOTICE requirements As a follow up, I think it's a good idea to include a check in the release process. The Caffeine addition to the GCP bundle was flagged in the original PR by the `runtime-deps.txt` file. On Wed, Sep 23, 2026 at 8:55 AM Neelesh Salian <[email protected]> wrote: > Thanks for voting and raising the issues. Addressing them one by one here: > 1. Gianluca, thank you for fixing issue #18164 > <https://github.com/apache/iceberg/issues/18164> (reading variant columns > failed for commons-lang3 < 3.13) with the resolution here: #18208 > <https://github.com/apache/iceberg/pull/18208>. This should be included > in the next RC. > 2. Szehon, the fix https://github.com/apache/iceberg/pull/18069 was in > this current RC already, so it should be included in a future RC as well. > Thanks for making the fix. > 3. Kurtis, thanks for finding and fixing the caffeine License entry. It's > worth getting that merged and would need a new RC. I'll take another pass > to see if there are additional license issues (did one before the RCs but > want to make sure nothing else was missed). > The RCK issue seems worth fixing as well. I will take a look if this was > existing or something added after 1.11.0 to assess if we need to get it in. > > All in all, we will need to cut a new Release Candidate to accommodate > these changes. > I'm closing this thread and will work with Amogh to build the new RC once > we are in the clear and open a new thread. > Thanks again for verifying this RC, everyone. > > > > > On Tue, Sep 22, 2026 at 10:25 PM <[email protected]> wrote: > >> >> -1 (non-binding) >> >> >> Disclaimer this was found after prompting my Claude to validate all the >> licenses for this RC. >> >> >> Reason: iceberg-gcp-bundle-1.12.0.jar bundles Caffeine with no entry in >> its LICENSE. Details below. Everything else checked out. >> >> >> Verified: >> >> - sha512 and GPG signature (Amogh Jahagirdar's key from KEYS) >> - source tarball matches the apache-iceberg-1.12.0-rc1 tag apart from >> the generated iceberg-build.properties and version.txt, and contains no >> compiled artifacts >> - LICENSE and NOTICE, dev/check-license (RAT) >> - staged binaries in orgapacheiceberg-1285: signatures on the 12 >> runtime and bundle jars, each jar's LICENSE and NOTICE against the source >> module, and the third-party packages inside each jar against its LICENSE >> entries >> - ./gradlew build with tests on three Linux environments: >> - Amazon Linux 2023 x86_64, Corretto 21.0.12.1 >> >> Finding: >> >> iceberg-gcp-bundle-1.12.0.jar bundles Caffeine (718 classes under >> com/github/benmanes/caffeine) and gcp-bundle/LICENSE has no entry for it. >> Caffeine arrives through com.google.cloud.gcs.analytics:common 1.5.0, >> pulled in by the gcs-analytics-core bump in #17687. The 1.2.3 version that >> 1.11.0 used did not depend on Caffeine, and gcp-bundle/LICENSE is unchanged >> since 1.11.0, so this is new in 1.12.0. Caffeine is Apache 2.0, so nothing >> is incompatible, but the bundle's LICENSE has to list what the jar ships. >> aws-bundle/LICENSE already carries the entry to copy, so the fix is a few >> lines in gcp-bundle/LICENSE. >> >> >> Issue: https://github.com/apache/iceberg/issues/18217 >> >> PR: https://github.com/apache/iceberg/pull/18218 >> >> >> Additional Non-Blocking Findings: >> >> RCK test failures with org.gradle.parallel=true and docker compose >> available, :iceberg-open-api:test can start while the kafka-connect >> integration stack holds host port 8181, and the REST Compatibility Kit >> server then fails to bind. Both use the fixed port 8181. >> >> >> Issue: https://github.com/apache/iceberg/issues/18215 >> >> PR: https://github.com/apache/iceberg/pull/18216 >> >> >> - Kurtis >> >> On Sep 22, 2026, at 16:52, Szehon Ho <[email protected]> wrote: >> >> >> +1 >> >> >> - *Passed:* GPG signature, SHA-512, announced commit/tag, and >> license/RAT checks. >> - *Core tests:* 8,400 passed, 550 skipped, zero failures. >> - *Spark test:* passed using a Spark 4.2 built from verified RC0 >> source. >> - >> - I'm unable to access the staged binaries at the moment, so built >> from source. >> - >> - Thanks >> - Szehon >> >> >> On Tue, Sep 22, 2026 at 4:08 PM Szehon Ho <[email protected]> >> wrote: >> >>> Hi >>> >>> If we make another RC, it'd be nice to get this one in: >>> https://github.com/apache/iceberg/pull/18069. >>> >>> Like the other one, its a pre-existing issue and maybe not worth to stop >>> this RC, but just another one to add to Gianluca's list. >>> >>> Thanks, >>> Szehon >>> >>> On Tue, Sep 22, 2026 at 1:03 PM Neelesh Salian <[email protected]> >>> wrote: >>> >>>> Thanks for raising that Gianluca. >>>> Since the issue isn't exactly a regression and constrained to the >>>> version of the commons-lang3, I think we can make a patch into the >>>> respective branches. >>>> I tried a local fix but want to make sure it can be tested well before >>>> making it into a fix. I'll follow up after the release to see how to get a >>>> proper fix in. >>>> >>>> On Tue, Sep 22, 2026 at 11:18 AM Gianluca Graziadei < >>>> [email protected]> wrote: >>>> >>>>> +1 (non-binding) >>>>> >>>>> Verified checksums, signature, source archive vs. tag, RAT, and ran >>>>> smoke tests with the staged Spark 4.0 runtime. >>>>> >>>>> Already mentioned for RC0: I hit a pre-existing NoSuchMethodError when >>>>> reading variant columns with commons-lang3 < 3.13 on the classpath. >>>>> iceberg-parquet uses Streams.of(Iterable) without declaring the >>>>> dependency. >>>>> This is also present in 1.11.0, so it’s not a regression. The issue is >>>>> tracked here: https://github.com/apache/iceberg/issues/18164 (PR >>>>> ready). >>>>> If there’s a new RC, please consider including the fix. It’s not >>>>> impactful enough to block the release process. >>>>> >>>>> Cheers, >>>>> Gianluca >>>>> >>>>> On 2026/09/22 03:35:41 Neelesh Salian wrote: >>>>> > Hi Everyone, >>>>> > >>>>> > I propose that we release the following RC as the official Apache >>>>> Iceberg >>>>> > 1.12.0 release. >>>>> > >>>>> > The commit ID is e8d0f0f3004a608e45986cbc2f8e5baf1a8a7db9 >>>>> > * This corresponds to the tag: apache-iceberg-1.12.0-rc1 >>>>> > * >>>>> https://github.com/apache/iceberg/commits/apache-iceberg-1.12.0-rc1 >>>>> > * >>>>> > >>>>> https://github.com/apache/iceberg/tree/e8d0f0f3004a608e45986cbc2f8e5baf1a8a7db9 >>>>> > >>>>> > The release tarball, signature, and checksums are here: >>>>> > * >>>>> https://dist.apache.org/repos/dist/dev/iceberg/apache-iceberg-1.12.0-rc1 >>>>> > >>>>> > You can find the KEYS file here: >>>>> > * https://downloads.apache.org/iceberg/KEYS >>>>> > >>>>> > Convenience binary artifacts are staged on Nexus. The Maven >>>>> repository URL >>>>> > is: >>>>> > * >>>>> https://repository.apache.org/content/repositories/orgapacheiceberg-1285/ >>>>> > >>>>> > Please download, verify, and test. >>>>> > >>>>> > Instructions for verifying a release can be found here: >>>>> > * https://iceberg.apache.org/how-to-release/#how-to-verify-a-release >>>>> > >>>>> > Please vote in the next 72 hours. >>>>> > >>>>> > [ ] +1 Release this as Apache Iceberg 1.12.0 >>>>> > [ ] +0 >>>>> > [ ] -1 Do not release this because... >>>>> > >>>>> > Only PMC members have binding votes, but other community members are >>>>> > encouraged to cast >>>>> > non-binding votes. This vote will pass if there are 3 binding +1 >>>>> votes and >>>>> > more binding >>>>> > +1 votes than -1 votes. >>>>> > >>>>> >>>>
