Re: [VOTE] Retire Apache James HUPA
+1 On Mon, Jul 26, 2021 at 7:38 PM Dongxu 王东旭 wrote: > +1 > > ccing Manolo, thank you. > > On Mon, Jul 26, 2021 at 10:16 AM Rene Cordier wrote: > >> +1, >> >> Rene. >> >> On 23/07/2021 16:00, btell...@apache.org wrote: >> > Hello all, >> > >> > Following a first email on the topic [1] I would like to call for a >> > formal vote on Apache James Hupa retirement. >> > >> > [1] >> https://www.mail-archive.com/server-dev@james.apache.org/msg70575.html >> > >> > Rationnals: >> > - The latest release (0.3.0) dates from 2012 which is an eternity in >> > computing. >> > - The latest tag on Github is 0.0.3 >> > - The pom references 0.0.5-SNAPSHOT suggesting that 0.0.4 release is >> > lost :-( >> > - This repository is crippled by multiple CVEs (quick dependabot >> review): >> >- CVE-2021-29425 (commons-io) >> >- GHSA-m6cp-vxjx-65j6 CVE-2017-7656 CVE-2015-2080 CVE-2017-7657 >> > CVE-2019-10241 CVE-2019-10247 (Jetty server) >> >- CVE-2020-9447 (gwtupload) >> >- GHSA-g3wg-6mcf-8jj6 (jetty-webapp) >> >- CVE-2019-17571 (log4j) >> >- CVE-2016-131 CVE-2016-3092 (commons-fileupload) >> > - Sporadic activity since 2012 >> > - Zero to no exchanges for several years on the mailing lists. >> > >> > Given that alternatives exists, given that the project is >> > likely not mature, unmaintained and unsecure, I propose to retire this >> > Apache James subproject. >> > >> > |Voting rules: - This is a majority vote as stated in [2] for procedural >> > issues. - The vote starts at Friday 23rd of July 2021, 4pm UTC+7 - The >> > vote ends at Friday 30th of July 2021, 4pm UTC+7 [2] >> > https://www.apache.org/foundation/voting.html Following this >> retirement, >> > follow up steps are to be taken as described in [3] [3] >> > https://www.mail-archive.com/server-dev@james.apache.org/msg70585.html >> | - 1. Get a formal vote on server-dev mailing list >> > - 2. Place a RETIRED_PROJECT file marker in the git >> > - 3. Add a note in the project README >> > - 4. Retire the ISSUE trackers (Project names HUPA and POSTAGE) >> > - 5. Announce it on gene...@james.apache.org and announce@apache >> > - 6. Add a notice to the Apache website, if present >> > - 7. Remove releases from downloads.apache.org >> > - 8. Add notices on the Apache release archives (example >> > https://archive.apache.org/dist/ant/antidote/ < >> https://archive.apache.org/dist/ant/antidote/>) >> > >> > Best regards, >> > >> > Benoit Tellier >> > || >> > >> > >> > - >> > To unsubscribe, e-mail: server-dev-unsubscr...@james.apache.org >> > For additional commands, e-mail: server-dev-h...@james.apache.org >> > >> > >> >> - >> To unsubscribe, e-mail: server-dev-unsubscr...@james.apache.org >> For additional commands, e-mail: server-dev-h...@james.apache.org >> >>
Re: [VOTE] Retire Apache James HUPA
+1 ccing Manolo, thank you. On Mon, Jul 26, 2021 at 10:16 AM Rene Cordier wrote: > +1, > > Rene. > > On 23/07/2021 16:00, btell...@apache.org wrote: > > Hello all, > > > > Following a first email on the topic [1] I would like to call for a > > formal vote on Apache James Hupa retirement. > > > > [1] > https://www.mail-archive.com/server-dev@james.apache.org/msg70575.html > > > > Rationnals: > > - The latest release (0.3.0) dates from 2012 which is an eternity in > > computing. > > - The latest tag on Github is 0.0.3 > > - The pom references 0.0.5-SNAPSHOT suggesting that 0.0.4 release is > > lost :-( > > - This repository is crippled by multiple CVEs (quick dependabot > review): > >- CVE-2021-29425 (commons-io) > >- GHSA-m6cp-vxjx-65j6 CVE-2017-7656 CVE-2015-2080 CVE-2017-7657 > > CVE-2019-10241 CVE-2019-10247 (Jetty server) > >- CVE-2020-9447 (gwtupload) > >- GHSA-g3wg-6mcf-8jj6 (jetty-webapp) > >- CVE-2019-17571 (log4j) > >- CVE-2016-131 CVE-2016-3092 (commons-fileupload) > > - Sporadic activity since 2012 > > - Zero to no exchanges for several years on the mailing lists. > > > > Given that alternatives exists, given that the project is > > likely not mature, unmaintained and unsecure, I propose to retire this > > Apache James subproject. > > > > |Voting rules: - This is a majority vote as stated in [2] for procedural > > issues. - The vote starts at Friday 23rd of July 2021, 4pm UTC+7 - The > > vote ends at Friday 30th of July 2021, 4pm UTC+7 [2] > > https://www.apache.org/foundation/voting.html Following this retirement, > > follow up steps are to be taken as described in [3] [3] > > https://www.mail-archive.com/server-dev@james.apache.org/msg70585.html > | - 1. Get a formal vote on server-dev mailing list > > - 2. Place a RETIRED_PROJECT file marker in the git > > - 3. Add a note in the project README > > - 4. Retire the ISSUE trackers (Project names HUPA and POSTAGE) > > - 5. Announce it on gene...@james.apache.org and announce@apache > > - 6. Add a notice to the Apache website, if present > > - 7. Remove releases from downloads.apache.org > > - 8. Add notices on the Apache release archives (example > > https://archive.apache.org/dist/ant/antidote/ < > https://archive.apache.org/dist/ant/antidote/>) > > > > Best regards, > > > > Benoit Tellier > > || > > > > > > - > > To unsubscribe, e-mail: server-dev-unsubscr...@james.apache.org > > For additional commands, e-mail: server-dev-h...@james.apache.org > > > > > > - > To unsubscribe, e-mail: server-dev-unsubscr...@james.apache.org > For additional commands, e-mail: server-dev-h...@james.apache.org > >
[jira] [Commented] (JAMES-3614) Download page wrong links
[ https://issues.apache.org/jira/browse/JAMES-3614?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17387253#comment-17387253 ] Sebb commented on JAMES-3614: - The download page ([https://james.apache.org/download.cgi)] looks OK now. However, it is very difficult to find on the main page. There is only a single reference which is buried in a long page. Given that the ASF releases source, it should be at least as easy to find as the Docker image. There should be a link to the Download page in the main menu, and a link from the beginning of the Get Started section. > Download page wrong links > - > > Key: JAMES-3614 > URL: https://issues.apache.org/jira/browse/JAMES-3614 > Project: James Server > Issue Type: Bug >Reporter: Sebb >Priority: Major > Time Spent: 20m > Remaining Estimate: 0h > > The download link for api 3.6.0 (Jar) actually points to > apache-mailet-api-3.6.0.jar.sha1 which is not a jar. > The link text for Base 3.6.0 says '(Jar)' but points to > apache-mailet-base-3.6.0-sources.zip which is not a jar either. -- This message was sent by Atlassian Jira (v8.3.4#803005) - To unsubscribe, e-mail: server-dev-unsubscr...@james.apache.org For additional commands, e-mail: server-dev-h...@james.apache.org
[BUILD-STABLE]: Job 'james/ApacheJames/master [master] [207]'
BUILD-STABLE: Job 'james/ApacheJames/master [master] [207]': Is back to normal. - To unsubscribe, e-mail: server-dev-unsubscr...@james.apache.org For additional commands, e-mail: server-dev-h...@james.apache.org
[BUILD-FAILURE]: Job 'james/ApacheJames/master [master] [206]'
BUILD-FAILURE: Job 'james/ApacheJames/master [master] [206]': Check console output at "https://ci-builds.apache.org/job/james/job/ApacheJames/job/master/206/;>james/ApacheJames/master [master] [206]" - To unsubscribe, e-mail: server-dev-unsubscr...@james.apache.org For additional commands, e-mail: server-dev-h...@james.apache.org