Thanks for catching the LICENSE issue. I found a couple more we should take
a look at.


Dependency

LICENSE

NOTICE

Caffeine

GCP: Add missing attribution (PR #18218
<https://github.com/apache/iceberg/pull/18218>)

No change needed

CEL Java

GCP, Kafka Connect main and Hive: Add attribution

Verify requirements

OpenTelemetry

Kafka Connect main and Hive: Review missing attribution

Verify requirements

Apache HttpComponents 5

AWS: Confirm existing attribution covers v5

Verify upstream NOTICE requirements

As a follow up, I think it's a good idea to include a check in the release
process. The Caffeine addition to the GCP bundle was flagged in the
original PR by the `runtime-deps.txt` file.



On Wed, Sep 23, 2026 at 8:55 AM Neelesh Salian <[email protected]>
wrote:

> Thanks for voting and raising the issues. Addressing them one by one here:
> 1. Gianluca, thank you for fixing issue #18164
> <https://github.com/apache/iceberg/issues/18164> (reading variant columns
> failed for commons-lang3 < 3.13) with the resolution here: #18208
> <https://github.com/apache/iceberg/pull/18208>. This should be included
> in the next RC.
> 2. Szehon, the fix https://github.com/apache/iceberg/pull/18069 was in
> this current RC already, so it should be included in a future RC as well.
> Thanks for making the fix.
> 3. Kurtis, thanks for finding and fixing the caffeine License entry. It's
> worth getting that merged and would need a new RC. I'll take another pass
> to see if there are additional license issues (did one before the RCs but
> want to make sure nothing else was missed).
> The RCK issue seems worth fixing as well. I will take a look if this was
> existing or something added after 1.11.0 to assess if we need to get it in.
>
> All in all, we will need to cut a new Release Candidate to accommodate
> these changes.
> I'm closing this thread and will work with Amogh to build the new RC once
> we are in the clear and open a new thread.
> Thanks again for verifying this RC, everyone.
>
>
>
>
> On Tue, Sep 22, 2026 at 10:25 PM <[email protected]> wrote:
>
>>
>> -1 (non-binding)
>>
>>
>> Disclaimer this was found after prompting my Claude to validate all the
>> licenses for this RC.
>>
>>
>> Reason: iceberg-gcp-bundle-1.12.0.jar bundles Caffeine with no entry in
>> its LICENSE. Details below. Everything else checked out.
>>
>>
>> Verified:
>>
>>    - sha512 and GPG signature (Amogh Jahagirdar's key from KEYS)
>>    - source tarball matches the apache-iceberg-1.12.0-rc1 tag apart from
>>    the generated iceberg-build.properties and version.txt, and contains no
>>    compiled artifacts
>>    - LICENSE and NOTICE, dev/check-license (RAT)
>>    - staged binaries in orgapacheiceberg-1285: signatures on the 12
>>    runtime and bundle jars, each jar's LICENSE and NOTICE against the source
>>    module, and the third-party packages inside each jar against its LICENSE
>>    entries
>>    - ./gradlew build with tests on three Linux environments:
>>       - Amazon Linux 2023 x86_64, Corretto 21.0.12.1
>>
>> Finding:
>>
>> iceberg-gcp-bundle-1.12.0.jar bundles Caffeine (718 classes under
>> com/github/benmanes/caffeine) and gcp-bundle/LICENSE has no entry for it.
>> Caffeine arrives through com.google.cloud.gcs.analytics:common 1.5.0,
>> pulled in by the gcs-analytics-core bump in #17687. The 1.2.3 version that
>> 1.11.0 used did not depend on Caffeine, and gcp-bundle/LICENSE is unchanged
>> since 1.11.0, so this is new in 1.12.0. Caffeine is Apache 2.0, so nothing
>> is incompatible, but the bundle's LICENSE has to list what the jar ships.
>> aws-bundle/LICENSE already carries the entry to copy, so the fix is a few
>> lines in gcp-bundle/LICENSE.
>>
>>
>> Issue: https://github.com/apache/iceberg/issues/18217
>>
>> PR: https://github.com/apache/iceberg/pull/18218
>>
>>
>> Additional Non-Blocking Findings:
>>
>> RCK test failures with org.gradle.parallel=true and docker compose
>> available, :iceberg-open-api:test can start while the kafka-connect
>> integration stack holds host port 8181, and the REST Compatibility Kit
>> server then fails to bind. Both use the fixed port 8181.
>>
>>
>> Issue: https://github.com/apache/iceberg/issues/18215
>>
>> PR: https://github.com/apache/iceberg/pull/18216
>>
>>
>> - Kurtis
>>
>> On Sep 22, 2026, at 16:52, Szehon Ho <[email protected]> wrote:
>>
>> 
>> +1
>>
>>
>>    - *Passed:* GPG signature, SHA-512, announced commit/tag, and
>>    license/RAT checks.
>>    - *Core tests:* 8,400 passed, 550 skipped, zero failures.
>>    - *Spark test:* passed using a Spark 4.2 built from verified RC0
>>    source.
>>    -
>>    - I'm unable to access the staged binaries at the moment, so built
>>    from source.
>>    -
>>    - Thanks
>>    - Szehon
>>
>>
>> On Tue, Sep 22, 2026 at 4:08 PM Szehon Ho <[email protected]>
>> wrote:
>>
>>> Hi
>>>
>>> If we make another RC, it'd be nice to get this one in:
>>> https://github.com/apache/iceberg/pull/18069.
>>>
>>> Like the other one, its a pre-existing issue and maybe not worth to stop
>>> this RC, but just another one to add to Gianluca's list.
>>>
>>> Thanks,
>>> Szehon
>>>
>>> On Tue, Sep 22, 2026 at 1:03 PM Neelesh Salian <[email protected]>
>>> wrote:
>>>
>>>> Thanks for raising that Gianluca.
>>>> Since the issue isn't exactly a regression and constrained to the
>>>> version of the commons-lang3, I think we can make a patch into the
>>>> respective branches.
>>>> I tried a local fix but want to make sure it can be tested well before
>>>> making it into a fix. I'll follow up after the release to see how to get a
>>>> proper fix in.
>>>>
>>>> On Tue, Sep 22, 2026 at 11:18 AM Gianluca Graziadei <
>>>> [email protected]> wrote:
>>>>
>>>>> +1 (non-binding)
>>>>>
>>>>> Verified checksums, signature, source archive vs. tag, RAT, and ran
>>>>> smoke tests with the staged Spark 4.0 runtime.
>>>>>
>>>>> Already mentioned for RC0: I hit a pre-existing NoSuchMethodError when
>>>>> reading variant columns with commons-lang3 < 3.13 on the classpath.
>>>>> iceberg-parquet uses Streams.of(Iterable) without declaring the 
>>>>> dependency.
>>>>> This is also present in 1.11.0, so it’s not a regression. The issue is
>>>>> tracked here: https://github.com/apache/iceberg/issues/18164 (PR
>>>>> ready).
>>>>> If there’s a new RC, please consider including the fix. It’s not
>>>>> impactful enough to block the release process.
>>>>>
>>>>> Cheers,
>>>>> Gianluca
>>>>>
>>>>> On 2026/09/22 03:35:41 Neelesh Salian wrote:
>>>>> > Hi Everyone,
>>>>> >
>>>>> > I propose that we release the following RC as the official Apache
>>>>> Iceberg
>>>>> > 1.12.0 release.
>>>>> >
>>>>> > The commit ID is e8d0f0f3004a608e45986cbc2f8e5baf1a8a7db9
>>>>> > * This corresponds to the tag: apache-iceberg-1.12.0-rc1
>>>>> > *
>>>>> https://github.com/apache/iceberg/commits/apache-iceberg-1.12.0-rc1
>>>>> > *
>>>>> >
>>>>> https://github.com/apache/iceberg/tree/e8d0f0f3004a608e45986cbc2f8e5baf1a8a7db9
>>>>> >
>>>>> > The release tarball, signature, and checksums are here:
>>>>> > *
>>>>> https://dist.apache.org/repos/dist/dev/iceberg/apache-iceberg-1.12.0-rc1
>>>>> >
>>>>> > You can find the KEYS file here:
>>>>> > * https://downloads.apache.org/iceberg/KEYS
>>>>> >
>>>>> > Convenience binary artifacts are staged on Nexus. The Maven
>>>>> repository URL
>>>>> > is:
>>>>> > *
>>>>> https://repository.apache.org/content/repositories/orgapacheiceberg-1285/
>>>>> >
>>>>> > Please download, verify, and test.
>>>>> >
>>>>> > Instructions for verifying a release can be found here:
>>>>> > * https://iceberg.apache.org/how-to-release/#how-to-verify-a-release
>>>>> >
>>>>> > Please vote in the next 72 hours.
>>>>> >
>>>>> > [ ] +1 Release this as Apache Iceberg 1.12.0
>>>>> > [ ] +0
>>>>> > [ ] -1 Do not release this because...
>>>>> >
>>>>> > Only PMC members have binding votes, but other community members are
>>>>> > encouraged to cast
>>>>> > non-binding votes. This vote will pass if there are 3 binding +1
>>>>> votes and
>>>>> > more binding
>>>>> > +1 votes than -1 votes.
>>>>> >
>>>>>
>>>>

Reply via email to