CVE-2022-33140: Apache NiFi, Apache NiFi Registry: Improper Neutralization of Command Elements in Shell User Group Provider

2022-06-15 Thread David Handermann
Severity: high Description: The optional ShellUserGroupProvider in Apache NiFi 1.10.0 to 1.16.2 and Apache NiFi Registry 0.6.0 to 1.16.2 does not neutralize arguments for group resolution commands, allowing injection of operating system commands on Linux and macOS platforms. The

Re: [DISCUSS] Strategy for Dropping Java 8 Support in NiFi 2.0

2022-06-15 Thread David Handermann
Thanks for the replies Kevin and Pierre! Various JDK vendors have different timelines for Java 11 support, some planning to end active support in September 2023 and others in October 2024. Either way, I agree that moving to Java 11 as the minimum version should be a shorter duration, with the

Re: [DISCUSS] Strategy for Dropping Java 8 Support in NiFi 2.0

2022-06-15 Thread Kevin Doran
Pierre and David, I agree with this project goals: - a 2.x release that drops support for Java 8 (requires at least Java 11) by EOY - a 3.x release that drops support for Java 11 (requires at least Java 17) in the not-to-distant future, perhaps 2023/24 This would also mean we could

[DISCUSS] Strategy for Dropping Java 8 Support in NiFi 2.0

2022-06-15 Thread David Handermann
Team, With multiple major projects in the process of sunsetting support for Java 8, we should also prepare a timeline for removing Java 8 support from Apache NiFi and subprojects. BACKGROUND The Jetty project announced the end of community support for version 9 as of 2022-06-01 [1]. Although

Re: [DISCUSS] Strategy for Dropping Java 8 Support in NiFi 2.0

2022-06-15 Thread Kevin Doran
Thanks for reviving this discussion David. In light of those core dependencies dropping support for Java 8, this plan seems necessary for NiFi. I support the proposal. Thanks, Kevin On Jun 15, 2022 at 11:48:05, David Handermann wrote: > Team, > > With multiple major projects in the process of

[DISCUSS] Release for NAR Maven Plugin

2022-06-15 Thread Kevin Doran
All, If there are no objections, I would like to put out a maintenance release (1.3.4) of the NAR Maven plugin, which has had some recent bug fixes and improvements: 1. https://issues.apache.org/jira/browse/NIFI-10011 2. https://issues.apache.org/jira/browse/NIFI-9856 3.

Re: [DISCUSS] Release for NAR Maven Plugin

2022-06-15 Thread Joe Witt
+1 On Wed, Jun 15, 2022 at 9:41 AM Kevin Doran wrote: > All, > > If there are no objections, I would like to put out a maintenance release > (1.3.4) of the NAR Maven plugin, which has had some recent bug fixes and > improvements: > > >1. https://issues.apache.org/jira/browse/NIFI-10011 >

Re: [DISCUSS] Release for NAR Maven Plugin

2022-06-15 Thread David Handermann
Thanks Kevin, +1 for preparing a release of the NAR Maven plugin. Regards, David Handermann On Wed, Jun 15, 2022 at 11:58 AM Joe Witt wrote: > +1 > > On Wed, Jun 15, 2022 at 9:41 AM Kevin Doran wrote: > > > All, > > > > If there are no objections, I would like to put out a maintenance release

Re: [DISCUSS] Strategy for Dropping Java 8 Support in NiFi 2.0

2022-06-15 Thread Pierre Villard
I'd even love to go straight to Java 17 since it's the new LTS version... but this may be quite a big jump for our community and users. I guess we can envision a "short" 2.x release line and consider Java 17 for 3.x. Definitely approve the proposal! Le mer. 15 juin 2022 à 18:50, Kevin Doran a

[DISCUSS] Distributed tracing using OpenTelemetry

2022-06-15 Thread Brian Putt
Hello Apache NiFi, I'd like to discuss implementing NIFI-10110 which adds OpenTelemetry integration into NiFi. Tracing will provide a way to identify bottlenecks within various flows and propagate trace information to downstream systems (whether they're another NiFi cluster or otherwise). I

DATA Pill - knowledge-sharing project

2022-06-15 Thread Sylwia Kołpuć
Hi, As we are a community focused around Apache NiFi I thought I would send you some information about the new DATA Pill project. I hope you will be interested because it covers our area and the project is focused on highly selected content for specialists. It is also a community-driven