Hello,

Here is a first draft of the Apache DB quarterly board report, due October
14.
Please review the sections relevant to your project and let me know of any
corrections, omissions, or additional activity to include before submission.
Please also confirm any releases, security matters, membership changes, or
issues requiring board attention that should be reflected in the report.

Thank you,
Jeffery Painter


## Description:

The mission of the Apache DB project is to create and maintain
commercial-quality, open-source, database solutions based on software
licensed to the Foundation, for distribution at no charge to the public.

The Apache DB TLP consists of the following sub-projects:

o JDO      : focused on building the API and the TCK for compatibility
             testing of Java Data Object implementations providing data
             persistence.
o Torque   : an object-relational mapper for Java.

## Project Status:

Current project status: ongoing
Issues for the board: none

Please see the Project Activity section of our report for recent updates.

## Membership Data:

Apache DB was founded 2002-07-16 (24 years ago).
There are currently 48 committers and 46 PMC members in this project.
The Committer-to-PMC ratio is roughly 1:1.

Community changes, past quarter:

* No new PMC members. Last addition was Max Philipp Wriedt on 2024-07-03.
* No new committers. Last addition was Max Philipp Wriedt on 2023-04-15.

## Project Activity:

### Apache JDO

The JDO project continues to hold regular project meetings, with recent work
focused on review of security-related changes, compatibility considerations,
and preparation for future releases.

The community has continued work related to the Glasswing security-scan
effort and review of proposed fixes. Recent pull requests address JNDI,
service discovery, privileged-operation fallback, enhancer behavior, and
classpath handling. These proposals remain under community review.

Particular attention has been given to proposed changes involving
user-defined
object identity classes and XML document builder configuration. The community
identified potential backward compatibility concerns and is revising the
proposals to distinguish necessary fixes from changes that could restrict
existing application behavior. Testing of an object identity patch also
identified a problem in the run-once tests, prompting further work.

Release planning includes consideration of JDO 3.2.2 and JDO 3.3, with
discussion of which fixes can be included in a maintenance release and
which changes may require a release that accommodates compatibility
changes. No completed release is recorded in the supplied quarterly
activity.

The Trusted Release voting-list issue noted in the previous report was fixed
and closed during August. This resolves the reported routing problem for JDO
release votes and represents progress toward use of the Trusted Release
workflow.

Other continuing discussion and maintenance topics include:

* Raising the minimum supported Java version to JDK 11 (JDO-812), together
  with consideration of release scope and Derby dependency updates.
* Generation of SBOM files (JDO-847).
* SonarCloud code quality findings (JDO-819 and JDO-823), including cognitive
  complexity and raw type warnings.
* Dependency maintenance, including review of a Log4j API update for the TCK.

### Apache Torque

Torque activity remains relatively light, with substantive discussion during
the quarter about repository migration, integration testing, and the scope of
a future major release.

The community renewed discussion of migrating Torque from Subversion to Git.
A developer volunteered to carry out the migration, and the proposal received
support. Discussion covered repository layout, whether to separate the
integration-test module, and the implications for CI, pull requests, issue
tracking, and site deployment. The supplied discussions do not record a
completed migration.

Jenkins build failures were investigated and attributed to path-resolution
issues when running the Torque integration tests from the project root. A
proposal would simplify the build by running the database integration tests
separately, removing the Jenkins-specific profiles, and excluding the test
module from release deliverables. This would require documenting a separate
integration-test step before preparing a release. The proposal received
support, but implementation is not confirmed in the supplied activity.

Future release discussion includes a possible move to Torque 8.0 to reflect
breaking changes associated with Java Time API support (TORQUE-375) and the
retirement of Derby. The community also discussed declaring Derby unsupported
for the upcoming release and addressing CI issues alongside the repository
migration. Work on ORM generation improvements (TORQUE-376) was mentioned in
the migration discussion.

No completed Torque release is recorded in the supplied quarterly activity.

### Project-Level Updates

No project-level issues requiring board attention have been identified in the
supplied activity. The previously reported JDO Trusted Release voting-list
issue has been resolved.

## Community Health:

The Apache DB community remains engaged in maintaining its two subprojects.

JDO continues to show regular participation in project meetings and careful
review of proposed changes, with attention to release planning, security
review, and compatibility for existing users.

Torque has a lower volume of activity, but the repository migration proposal,
investigation of integration-test failures, and discussion of future release
scope show continued developer engagement.

No concerns requiring board attention have been identified in the supplied
materials.


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to