Re: [VOTE] Retire Apache James HUPA

2021-07-26 Thread Dongxu Wang
+1

On Mon, Jul 26, 2021 at 7:38 PM Dongxu 王东旭  wrote:

> +1
>
> ccing Manolo, thank you.
>
> On Mon, Jul 26, 2021 at 10:16 AM Rene Cordier  wrote:
>
>> +1,
>>
>> Rene.
>>
>> On 23/07/2021 16:00, btell...@apache.org wrote:
>> > Hello all,
>> >
>> > Following a first email on the topic [1] I would like to call for a
>> > formal vote on Apache James Hupa retirement.
>> >
>> > [1]
>> https://www.mail-archive.com/server-dev@james.apache.org/msg70575.html
>> >
>> > Rationnals:
>> >   - The latest release (0.3.0) dates from 2012 which is an eternity in
>> > computing.
>> >   - The latest tag on Github is 0.0.3
>> >   - The pom references 0.0.5-SNAPSHOT suggesting that 0.0.4 release is
>> > lost :-(
>> >   - This repository is crippled by multiple CVEs (quick dependabot
>> review):
>> >- CVE-2021-29425 (commons-io)
>> >- GHSA-m6cp-vxjx-65j6 CVE-2017-7656 CVE-2015-2080 CVE-2017-7657
>> > CVE-2019-10241 CVE-2019-10247 (Jetty server)
>> >- CVE-2020-9447 (gwtupload)
>> >- GHSA-g3wg-6mcf-8jj6 (jetty-webapp)
>> >- CVE-2019-17571 (log4j)
>> >- CVE-2016-131 CVE-2016-3092 (commons-fileupload)
>> >   - Sporadic activity since 2012
>> >   - Zero to no exchanges for several years on the mailing lists.
>> >
>> > Given that alternatives exists, given that the project is
>> > likely not mature, unmaintained and unsecure, I propose to retire this
>> > Apache James subproject.
>> >
>> > |Voting rules: - This is a majority vote as stated in [2] for procedural
>> > issues. - The vote starts at Friday 23rd of July 2021, 4pm UTC+7 - The
>> > vote ends at Friday 30th of July 2021, 4pm UTC+7 [2]
>> > https://www.apache.org/foundation/voting.html Following this
>> retirement,
>> > follow up steps are to be taken as described in [3] [3]
>> > https://www.mail-archive.com/server-dev@james.apache.org/msg70585.html
>> | - 1. Get a formal vote on server-dev mailing list
>> >   - 2. Place a RETIRED_PROJECT file marker in the git
>> >   - 3. Add a note in the project README
>> >   - 4. Retire the ISSUE trackers (Project names HUPA and POSTAGE)
>> >   - 5. Announce it on gene...@james.apache.org and announce@apache
>> >   - 6. Add a notice to the Apache website, if present
>> >   - 7. Remove releases from downloads.apache.org
>> >   - 8. Add notices on the Apache release archives (example
>> > https://archive.apache.org/dist/ant/antidote/ <
>> https://archive.apache.org/dist/ant/antidote/>)
>> >
>> > Best regards,
>> >
>> > Benoit Tellier
>> > ||
>> >
>> >
>> > -
>> > To unsubscribe, e-mail: server-dev-unsubscr...@james.apache.org
>> > For additional commands, e-mail: server-dev-h...@james.apache.org
>> >
>> >
>>
>> -
>> To unsubscribe, e-mail: server-dev-unsubscr...@james.apache.org
>> For additional commands, e-mail: server-dev-h...@james.apache.org
>>
>>


Re: [VOTE] Retire Apache James HUPA

2021-07-26 Thread Dongxu 王东旭
+1

ccing Manolo, thank you.

On Mon, Jul 26, 2021 at 10:16 AM Rene Cordier  wrote:

> +1,
>
> Rene.
>
> On 23/07/2021 16:00, btell...@apache.org wrote:
> > Hello all,
> >
> > Following a first email on the topic [1] I would like to call for a
> > formal vote on Apache James Hupa retirement.
> >
> > [1]
> https://www.mail-archive.com/server-dev@james.apache.org/msg70575.html
> >
> > Rationnals:
> >   - The latest release (0.3.0) dates from 2012 which is an eternity in
> > computing.
> >   - The latest tag on Github is 0.0.3
> >   - The pom references 0.0.5-SNAPSHOT suggesting that 0.0.4 release is
> > lost :-(
> >   - This repository is crippled by multiple CVEs (quick dependabot
> review):
> >- CVE-2021-29425 (commons-io)
> >- GHSA-m6cp-vxjx-65j6 CVE-2017-7656 CVE-2015-2080 CVE-2017-7657
> > CVE-2019-10241 CVE-2019-10247 (Jetty server)
> >- CVE-2020-9447 (gwtupload)
> >- GHSA-g3wg-6mcf-8jj6 (jetty-webapp)
> >- CVE-2019-17571 (log4j)
> >- CVE-2016-131 CVE-2016-3092 (commons-fileupload)
> >   - Sporadic activity since 2012
> >   - Zero to no exchanges for several years on the mailing lists.
> >
> > Given that alternatives exists, given that the project is
> > likely not mature, unmaintained and unsecure, I propose to retire this
> > Apache James subproject.
> >
> > |Voting rules: - This is a majority vote as stated in [2] for procedural
> > issues. - The vote starts at Friday 23rd of July 2021, 4pm UTC+7 - The
> > vote ends at Friday 30th of July 2021, 4pm UTC+7 [2]
> > https://www.apache.org/foundation/voting.html Following this retirement,
> > follow up steps are to be taken as described in [3] [3]
> > https://www.mail-archive.com/server-dev@james.apache.org/msg70585.html
> | - 1. Get a formal vote on server-dev mailing list
> >   - 2. Place a RETIRED_PROJECT file marker in the git
> >   - 3. Add a note in the project README
> >   - 4. Retire the ISSUE trackers (Project names HUPA and POSTAGE)
> >   - 5. Announce it on gene...@james.apache.org and announce@apache
> >   - 6. Add a notice to the Apache website, if present
> >   - 7. Remove releases from downloads.apache.org
> >   - 8. Add notices on the Apache release archives (example
> > https://archive.apache.org/dist/ant/antidote/ <
> https://archive.apache.org/dist/ant/antidote/>)
> >
> > Best regards,
> >
> > Benoit Tellier
> > ||
> >
> >
> > -
> > To unsubscribe, e-mail: server-dev-unsubscr...@james.apache.org
> > For additional commands, e-mail: server-dev-h...@james.apache.org
> >
> >
>
> -
> To unsubscribe, e-mail: server-dev-unsubscr...@james.apache.org
> For additional commands, e-mail: server-dev-h...@james.apache.org
>
>


[jira] [Commented] (JAMES-3614) Download page wrong links

2021-07-26 Thread Sebb (Jira)


[ 
https://issues.apache.org/jira/browse/JAMES-3614?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17387253#comment-17387253
 ] 

Sebb commented on JAMES-3614:
-

The download page ([https://james.apache.org/download.cgi)] looks OK now.

However, it is very difficult to find on the main page.

There is only a single reference which is buried in a long page.

Given that the ASF releases source, it should be at least as easy to find as 
the Docker image.

There should be a link to the Download page in the main menu, and a link from 
the beginning of the Get Started section.

 

> Download page wrong links
> -
>
> Key: JAMES-3614
> URL: https://issues.apache.org/jira/browse/JAMES-3614
> Project: James Server
>  Issue Type: Bug
>Reporter: Sebb
>Priority: Major
>  Time Spent: 20m
>  Remaining Estimate: 0h
>
> The download link for api 3.6.0 (Jar) actually points to 
> apache-mailet-api-3.6.0.jar.sha1 which is not a jar.
> The link text for Base 3.6.0 says '(Jar)' but points to 
> apache-mailet-base-3.6.0-sources.zip which is not a jar either.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

-
To unsubscribe, e-mail: server-dev-unsubscr...@james.apache.org
For additional commands, e-mail: server-dev-h...@james.apache.org



[BUILD-STABLE]: Job 'james/ApacheJames/master [master] [207]'

2021-07-26 Thread Apache Jenkins Server
BUILD-STABLE: Job 'james/ApacheJames/master [master] [207]':
Is back to normal.

-
To unsubscribe, e-mail: server-dev-unsubscr...@james.apache.org
For additional commands, e-mail: server-dev-h...@james.apache.org

[BUILD-FAILURE]: Job 'james/ApacheJames/master [master] [206]'

2021-07-26 Thread Apache Jenkins Server
BUILD-FAILURE: Job 'james/ApacheJames/master [master] [206]':
Check console output at "https://ci-builds.apache.org/job/james/job/ApacheJames/job/master/206/;>james/ApacheJames/master
 [master] [206]"

-
To unsubscribe, e-mail: server-dev-unsubscr...@james.apache.org
For additional commands, e-mail: server-dev-h...@james.apache.org