Re: Topics for our January report to the board?

2023-01-10 Thread Craig Russell
Hi Bryan,

Thanks for the reminder. 

No JDO releases since 3.2.1 last quarter.

The JDO project is working on improving code quality via feedback solicited 
from a code analysis tool called SonarCloud. SonarCloud itself is not open 
source but is free to analyze open source projects. A number of issues reported 
by the tool have been merged to the main branch and several others are 
currently being worked.

The JDO project has a dependency on Derby to run the Technology Compatibility 
Kit and we have analyzed the recent Derby security vulnerability. We have 
determined that our use of Derby does not expose the project to any attacks and 
thus we have no immediate plans to update our dependency.

We are discussing whether to continue to support JDK 8 as the lowest level or 
move to JDK 11. This would be a breaking change so we are not considering it 
prior to a significant release: 3.3.

Best,
Craig

> On Jan 10, 2023, at 04:45, Bryan Pendleton  wrote:
> 
> Apparently, during the holiday season, I forgot about our reporting
> schedule, and our quarterly report to the board is due tomorrow.
> 
> Please let me know of any topics we should include in our January report.
> 
> thanks,
> 
> bryan

Craig L Russell
c...@apache.org



Topics for our January report to the board?

2023-01-10 Thread Bryan Pendleton
Apparently, during the holiday season, I forgot about our reporting
schedule, and our quarterly report to the board is due tomorrow.

Please let me know of any topics we should include in our January report.

thanks,

bryan