CVE-2024-45537: Apache Druid: Users can provide MySQL JDBC properties not on allow list

2024-09-17 Thread Karan Kumar
Severity: low Affected versions: - Apache Druid through 30.0.0 Description: Apache Druid allows users with certain permissions to read data from other database systems using JDBC. This functionality allows trusted users to set up Druid lookups or run ingestion tasks. Druid also allows adminis

CVE-2024-45384: Apache Druid: Padding oracle in druid-pac4j extension that allows an attacker to manipulate a pac4j session cookie via Padding Oracle Attack

2024-09-17 Thread Karan Kumar
Severity: low Affected versions: - Apache Druid 0.18.0 through 30.0.0 Description: Padding Oracle vulnerability in Apache Druid extension, druid-pac4j. This could allow an attacker to manipulate a pac4j session cookie. This issue affects Apache Druid versions 0.18.0 through 30.0.0. Since the d

[ANNOUNCE] Apache Druid 30.0.1 release

2024-09-17 Thread Karan Kumar
The Apache Druid team is proud to announce the release of Apache Druid 30.0.1. Druid is a high performance analytics data store for event-driven data. Apache Druid 30.0.1 contains security, doc and task monitor fixes. Source and binary distributions can be downloaded from: https://druid.apache.or

Re: [VOTE] Release Apache Druid 30.0.0 [RC3]

2024-06-13 Thread Karan Kumar
+1 (binding) src package: * verified checksum and signature * built binary distribution * ran MSQ ingestion and demo MSQ queries on the dataset (using the built binary) binary package: * verified checksum and signature * checked for LICENSE and NOTICE * ran MSQ ingestion and demo MSQ queries on t

Re: [VOTE] Release Apache Druid 30.0.0 [RC1]

2024-06-02 Thread Karan Kumar
While testing for aure support I ran into : https://github.com/apache/druid/pull/16525. I feel it is a RC blocker since Azure support is broken without the above patch.. Therefore -1 for my side. On Wed, May 29, 2024 at 10:01 AM Adarsh Sanjeev wrote: > Hi all, > > I have created a build for Apac

[ANNOUNCE] Apache Druid 29.0.1 release

2024-04-02 Thread Karan Kumar
Hi All The Apache Druid team is proud to announce the release of Apache Druid 29.0.1 . Druid is a high performance analytics data store for event-driven data. Apache Druid 29.0.1 is a patch release on top of druid 29.0.0, that contains the following patches: Bug fixes - Added type verificatio

[RESULT][VOTE] Release Apache Druid 29.0.1 [RC1]

2024-04-01 Thread Karan Kumar
Thanks to everyone who participated in the vote! The results are as follows: Karan Kumarl: +1 (binding) Laksh Singla: +1 (binding) Amatya Avadhanula: +1 (binding) The vote has passed with 3 binding +1's.

Re: [VOTE] Release Apache Druid 29.0.1 [RC1]

2024-04-01 Thread Karan Kumar
; queries and data > > binary package: > * verified checksum and signature > * checked for LICENSE and NOTICE > * ran Kafka streaming ingestion with concurrent MSQ replace, and verified > queries and data > > docker: > * verified checksum > > On 2024/03/21 12:14:50 Ka

Re: [VOTE] Release Apache Druid 29.0.0 [RC1]

2024-03-21 Thread Karan Kumar
Hi Vote thread for druid 29.0.1 is up. https://lists.apache.org/thread/6syof9fmnb7vbyjrpowrt7s73rh2bqy4 Thanks Karan On Wed, Feb 21, 2024 at 1:10 AM Vadim Ogievetsky wrote: > That sounds great to me. Thank you +1 > > On 2024/02/20 18:58:35 Laksh Singla wrote: > > Since the artifacts were alread

Re: [DISCUSS] Apache Druid Release 29.0.1

2024-03-21 Thread Karan Kumar
Hi All Just started a vote thread : https://lists.apache.org/thread/6syof9fmnb7vbyjrpowrt7s73rh2bqy4 Thanks Karan On Mon, Feb 26, 2024 at 6:10 PM Karan Kumar wrote: > > Hi folks, > > As discussed in Druid 29.0 RC thread : > https://lists.apache.org/thread/t3q3288lr0ypky8bpnmrkxo

[VOTE] Release Apache Druid 29.0.1 [RC1]

2024-03-21 Thread Karan Kumar
Hi all, I have created a build for Apache Druid 29.0.1, release candidate 1. Thanks to everyone who has helped contribute to the release! You can read the proposed release notes here: https://github.com/apache/druid/issues/16183 The release candidate has been tagged in GitHub as druid-29.0.1-rc1

[DISCUSS] Apache Druid Release 29.0.1

2024-02-26 Thread Karan Kumar
Hi folks, As discussed in Druid 29.0 RC thread : https://lists.apache.org/thread/t3q3288lr0ypky8bpnmrkxowl36305vo a new druid 29.0.1 release is neded. I volunteer to shepherd the process. I have marked relevant PR with the druid 29.0.1 milestone here : https://github.com/apache/druid/pulls?q=is%3A

Re: [VOTE] Release Apache Druid 29.0.0 [RC1]

2024-02-15 Thread Karan Kumar
+1 (binding) src package: - verified checksum and signature - LICENSE and NOTICE present - built binary distribution, ran MSQ quickstart binary package: - verified checksum and signature - LICENSE and NOTICE present - ran MSQ quickstart docker: - verified checksum On Thu, Feb 15, 2024 at 5:41 A

[Discuss] Druid 29.0.0 release

2024-01-12 Thread Karan Kumar
Hello all, I am starting a discussion for the Druid 29.0.0 release. I am volunteering to be the release manager for the same. The branch for Druid 28.0.0 was cut on 9th October 2023, and since we do quarterly releases, we should cut the branch for Druid 29.0.0 on 15th January 2024 (Monday). Please

Re: [VOTE] Release Apache Druid 28.0.1 [RC1]

2023-12-16 Thread Karan Kumar
+1 (Binding) src package: - verified checksum and signature - check for LICENSE and NOTICE - built binary distribution, ran MSQ quickstart, ran some queries, tested rolling overlord patch for new TaskActions. binary package: - verified checksum and signature - check for LICENSE and NOTICE - ran na

Re: [VOTE] Release Apache Druid 28.0.0 [RC1]

2023-11-11 Thread Karan Kumar
+ 1 Binding src package: - verified signature/checksum - LICENSE/NOTICE present - built binary distribution, - Loaded all sample MSQ queries queries - Tested query from deep storage binary package: - verified signature/checksum - LICENSE/NOTICE present - ran single server quick start

Re: New committer: Rahul Gidwani

2023-09-01 Thread Karan Kumar
Congratulations!! On Tue, Aug 29, 2023 at 9:59 PM Atul Mohan wrote: > Congratulations Rahul! > > On Mon, Aug 28, 2023 at 10:35 PM suneet Saldanha > wrote: > > > The Project Management Committee (PMC) for Apache Druid > > has invited Rahul Gidwani and we are pleased to announce that > > he has a

New Committer : Soumyava Das

2023-08-21 Thread Karan Kumar
Hello everyone, The Project Management Committee (PMC) for Apache Druid has invited Soumyava to become a committer and we are pleased to announce that Soumyava has accepted. Soumyava has been a consistent contributor for over a year now. He has over 29 commits in druid. His majority commits are i

New Committer : Adarsh Sanjeev

2023-08-21 Thread Karan Kumar
Hello everyone, The Project Management Committee (PMC) for Apache Druid has invited Adarsh to become a committer and we are pleased to announce that Adarsh has accepted. Adarsh has been a consistent contributor for over a year now. He has over 49 commits in druid. His majority commits are in the

Re: [VOTE] Release Apache Druid 27.0.0 [RC1]

2023-08-08 Thread Karan Kumar
+1 (binding) src package: - verified signature/checksum - Build druid on (m1 based chipset) - Ran druid cluster and tested - All MSQ demo q's - Tested query from deep storage with results written out to s3. - Ran q's against segment's not loaded on the historicals

Re: [DISCUSS] Druid 28 dropping support for Hadoop 2

2023-06-27 Thread Karan Kumar
In favour of dropping hadoop 2 support . Another point is the lack of security and vulnerability fixes in hadoop2. On Wed, Jun 28, 2023 at 12:17 PM Clint Wylie wrote: > obvious +1 from me > > On Tue, Jun 27, 2023 at 11:42 PM Gian Merlino wrote: > > > > I'd like to propose dropping support for

Re: New Committer : Didip Kerabat

2023-05-03 Thread Karan Kumar
Congratulations!! On Wed, May 3, 2023 at 9:33 PM Rohan Garg wrote: > Congratulations Didip! > > On Wed, May 3, 2023 at 7:48 AM Kashif Faraz wrote: > > > Congratulations, Didip!! > > > > On Tue, May 2, 2023 at 3:43 AM Sergio Ferragut > > wrote: > > > > > Congratulations on becoming a committer

Re: New Committer : Jason Koch

2023-04-17 Thread Karan Kumar
Congratulations Jason !!! On Tue, 18 Apr, 2023, 5:11 am Jason Koch, wrote: > Thank you!! > > On Mon, Apr 17, 2023 at 10:28 AM Maytas Monsereenusorn > > wrote: > > > Hello everyone, > > > > The Project Management Committee (PMC) for Apache Druid has invited > > Jason to become a committer and we

Re: New Committer : Laksh Singla

2023-04-10 Thread Karan Kumar
Congratulations Laksh!! On Mon, 10 Apr, 2023, 7:37 pm Kashif Faraz, wrote: > Congrats, Laksh!! > > On Mon, Apr 10, 2023 at 2:20 PM Rohan Garg > wrote: > > > Congratulations Laksh! > > > > On Mon, Apr 10, 2023 at 11:38 AM Frank Chen > wrote: > > > > > Congratulations to Laksh > > > > > > On Mon

Re: New Committer : Tejaswini Bandlamudi

2023-04-10 Thread Karan Kumar
Congratulations Tejaswini!! On Mon, 10 Apr, 2023, 7:37 pm Kashif Faraz, wrote: > Congrats, Tejaswini! > > On Mon, Apr 10, 2023 at 2:20 PM Rohan Garg > wrote: > > > Congratulations Tejaswini! > > > > On Mon, Apr 10, 2023 at 11:37 AM Frank Chen > wrote: > > > > > Congratulation to Tejaswini > >

Re: CI requiring approval for external contributors

2023-03-29 Thread Karan Kumar
+1 Pasting some of the examples that I shared on slack: - PR : https://github.com/apache/druid/pull/13934 which is raised by Soumyava Das who contributes regularly to druid should not block on a committer to approve CI runs. - PR : https://github.com/apache/druid/pull/13909 by Adarsh S

Re: [Discuss] S3 buckets or IT tests

2023-03-14 Thread Karan Kumar
> also > > makes them harder to debug. Setting up minio using GHA seems > > straightforward (https://github.com/mozilla/sccache/pull/1513/files). > > > > On Mon, Mar 6, 2023 at 7:01 AM Karan Kumar > > wrote: > > > > > Oh yes, https://issues.apache.

Re: [Discuss] S3 buckets or IT tests

2023-03-05 Thread Karan Kumar
s. If Infra is willing to provide a > bucket for this purpose then we would certainly be able to use that. I bet > we could also use Minio (https://min.io/) or something similar. > > Gian > > On 2023/02/15 21:38:47 Karan Kumar wrote: > > Hey Folks > > S3 read write test

[Discuss] S3 buckets or IT tests

2023-02-15 Thread Karan Kumar
Hey Folks S3 read write tests currently are not executed in github actions since we do not have public creds to read/write from s3. Have raised an ASF infra ticket https://apachedruidworkspace.slack.com/archives/C030CMF6B70/p1675916945323839 so that they can give us a bucket. They require a PMC app

Re: [E] Re: Apache Druid Slack

2022-11-07 Thread Karan Kumar
Hey I fully support having our slack history indexed on google and I think we should do it sooner rather than later as there are a lot of good threads on slack that are getting purged out. On Wed, Oct 19, 2022 at 9:47 AM Abhishek Agarwal wrote: > I recently learned about Apache Flink making sla

Re: New Committer : Karan Kumar

2022-11-03 Thread Karan Kumar
ohan Garg > wrote: > > >> > > >>> Congratulations Karan! > > >>> > > >>> On Mon, Oct 31, 2022 at 3:33 PM Abhishek Agarwal < > abhis...@apache.org> > > >>> wrote: > > >>> > > >>>>

Re: New Committer : Paul Rogers

2022-09-28 Thread Karan Kumar
Congratulations Paul!! On Wed, Sep 28, 2022 at 10:17 PM Abhishek Agarwal wrote: > Hello everyone, > > The Project Management Committee (PMC) for Apache Druid has invited Paul > Rogers to become a committer and we are pleased to announce that Paul has > accepted. > > Paul has been very active in

Re: New Committer : Amatya Avadhanula

2022-09-28 Thread Karan Kumar
Congratulations Amatya!! On Wed, Sep 28, 2022 at 10:17 PM Abhishek Agarwal wrote: > Hello everyone, > > The Project Management Committee (PMC) for Apache Druid has invited Amatya > Avadhanula to become a committer and we are pleased to announce that Amatya > has accepted. > > Amatya has been mak

Re: New Committer : Rohan Garg

2022-07-26 Thread Karan Kumar
Congrats Rohan !! On Tue, Jul 26, 2022 at 12:20 PM Abhishek Agarwal wrote: > Hello everyone, > > The Project Management Committee (PMC) for Apache Druid has invited Rohan > Garg to become a committer and we are pleased to announce that Rohan has > accepted. > > Rohan has been an active contribut

Re: New PMC member: Abhishek Agarwal

2022-06-07 Thread Karan Kumar
Congratulations Abhishek! On Wed, Jun 8, 2022 at 8:42 AM Tijo Thomas wrote: > Congratulations... > > > On Wed, Jun 8, 2022 at 6:48 AM Frank Chen wrote: > > > Congratulations. > > > > > > On Wed, Jun 8, 2022 at 7:44 AM Furkan KAMACI > > wrote: > > > > > Hi, > > > > > > Congrats and welcome on b

Re: new committer: Kashif Faraz

2022-01-16 Thread Karan Kumar
Congratulations Kashif!! On Mon, Jan 17, 2022 at 10:43 AM Tijo Thomas wrote: > Congratulations Kashif !! > > On Fri, Jan 14, 2022 at 8:40 AM Kashif Faraz > wrote: > > > Thanks a lot, Suneet, Abhishek! > > > > I am really grateful for the recognition and for the community's active > > feedback o

Re: New PMC member: Atul Mohan

2021-11-01 Thread Karan Kumar
Congrats Atul!! On Tue, Nov 2, 2021 at 11:35 AM Abhishek Agarwal wrote: > Congratulations Atul. > > On Tue, Nov 2, 2021 at 2:43 AM Jihoon Son wrote: > > > Hey Druids, > > > > The Druid PMC has invited Atul Mohan (@a2l007 on github) to become a > > PMC member and we are pleased to announce that

Re: New PMC member: Frank Chen

2021-11-01 Thread Karan Kumar
Congrats Frank!! On Tue, Nov 2, 2021 at 11:36 AM Abhishek Agarwal wrote: > Congratulations Frank. > > On Tue, Nov 2, 2021 at 2:44 AM Jihoon Son wrote: > > > Hey Druids, > > > > The Druid PMC has invited Frank Chen (@FrankChen021 on github) to > > become a PMC member and we are pleased to announ

Re: New committer: Agustin Gonzalez Tuchmann

2021-11-01 Thread Karan Kumar
Congrats Agustin !! On Tue, Nov 2, 2021 at 11:35 AM Abhishek Agarwal wrote: > Congratulations Agustin. Keep up the good work. > > On Tue, Nov 2, 2021 at 2:42 AM Jihoon Son wrote: > > > Hey Druids, > > > > The Druid PMC has invited Agustin Gonzalez Tuchmann (@loquisgon on > > github) to become a

Re: [E] [DISCUSS] Hadoop 3, dropping support for Hadoop 2.x

2021-10-11 Thread Karan Kumar
Hello We can also use maven profiles. We keep hadoop2 support by default and add a new maven profile with hadoop3. This will allow the user to choose the profile which is best suited for the use case. Agreed, it will not help in the Hadoop dependency problems but does enable our users to use d