You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@avro.apache.org by Jean-Baptiste Onofré <jb...@nanthrax.net> on 2024/03/13 17:16:36 UTC
[PROPOSAL] Apache Avro 1.11.4 release
Hi folks,
Recently, we upgraded to commons-compress 1.26.0 (on main).
commons-compress 1.26.0 fixes several CVEs (CVE-2024-25710,
CVE-2024-26308, CVE-2023-42503).
Would it be possible to release Avro 1.11.4 (that will include
commons-compress update) ?
I can help on the release if there are no objections.
Thanks !
Regards
JB
Re: [PROPOSAL] Apache Avro 1.11.4 release
Posted by Jean-Baptiste Onofré <jb...@apache.org>.
Hi,
Having both is an option, but I remember that we wanted to go directly to 1.12.0.
Regards
JB
On 2024/04/06 20:28:34 Oscar Westra van Holthe - Kind wrote:
> Hi everyone,
>
> As I remember the discussion, we'd support both the last major release and
> the current one. This would mean we should release both 1.11.4 and 1.12.0.
>
> Did I remember correctly?
>
>
> Kind regards,
> Oscar
>
> --
> Oscar Westra van Holthe - Kind <op...@apache.org>
>
> Op vr 5 apr. 2024 17:20 schreef Ryan Skraba <ry...@skraba.com>:
>
> > Hello everyone! I've been away for a bit, but I also think a new
> > release would be welcome :D
> >
> > I'm willing to put in the work to do the packaging and deployment,
> > especially if I can help another future "release manager" get
> > everything in place to do the next one!
> >
> > Are we aligned on doing a 1.11.4 release or a 1.12.0 release? At one
> > point we were pretty convinced that we would continue to maintain the
> > 1.11.x branch so that we have two valid major releases[1].
> >
> > I (errrr...) haven't built Avro recently on my local machine, which is
> > currently required in order to do a release.[2] I can give that a
> > try!
> >
> > All my best, Ryan
> >
> > [1]: https://lists.apache.org/thread/d3wx977pk6gxjnjg4d1jk3583f2bfgx0
> > "[DISCUSS] Release maintenance and lifecycle"
> > [2]: https://cwiki.apache.org/confluence/display/AVRO/How+To+Release
> > "How to release"
> >
> >
> >
> >
> >
> > On Wed, Apr 3, 2024 at 11:03 AM Jean-Baptiste Onofré
> > <jb...@apache.org> wrote:
> > >
> > > Thanks Fokko !
> > >
> > > Great. Let me check #3871 also.
> > >
> > > Regards
> > > JB
> > >
> > > On 2024/04/02 15:00:04 "Driesprong, Fokko" wrote:
> > > > Sorry for the late reply JB.
> > > >
> > > > I'll do a review of #2642 <https://github.com/apache/avro/pull/2642>.
> > I
> > > > already tested this against Iceberg locally and didn't see any issues
> > > > there. I would love to get in #3871
> > > > <https://github.com/apache/avro/pull/2732> as well.
> > > >
> > > > Cheers, Fokko
> > > >
> > > > Op di 2 apr 2024 om 16:57 schreef Jean-Baptiste Onofré <
> > jbonofre@apache.org
> > > > >:
> > > >
> > > > > Hi folks,
> > > > >
> > > > > As discussed on this thread, I would like to move forward on 1.12.0
> > > > > release.
> > > > > Thoughts ?
> > > > >
> > > > > I'm doing a pass on the issues.
> > > > >
> > > > > PS: I have a weird behavior with the mailing list, I might have to
> > > > > re-subscribe.
> > > > >
> > > > > Regards
> > > > > JB
> > > > >
> > > > > On 2024/03/14 08:53:05 Jean-Baptiste Onofré wrote:
> > > > > > Hey Martin
> > > > > >
> > > > > > Awesome !
> > > > > >
> > > > > > Happy to help with 1.12.0 if needed :)
> > > > > >
> > > > > > Thanks !
> > > > > > Regards
> > > > > > JB
> > > > > >
> > > > > > On 2024/03/14 08:46:05 Martin Grigorov wrote:
> > > > > > > Hi,
> > > > > > >
> > > > > > > On Wed, Mar 13, 2024 at 7:16 PM Jean-Baptiste Onofré <
> > jb@nanthrax.net>
> > > > > > > wrote:
> > > > > > >
> > > > > > > > Hi folks,
> > > > > > > >
> > > > > > > > Recently, we upgraded to commons-compress 1.26.0 (on main).
> > > > > > > > commons-compress 1.26.0 fixes several CVEs (CVE-2024-25710,
> > > > > > > > CVE-2024-26308, CVE-2023-42503).
> > > > > > > >
> > > > > > > > Would it be possible to release Avro 1.11.4 (that will include
> > > > > > > > commons-compress update) ?
> > > > > > > >
> > > > > > >
> > > > > > > Actually a few weeks ago there was a proposal to release 1.12.0!
> > > > > > > https://lists.apache.org/thread/b8p8jkxx8f23yrss14q0y0ptdlttnxp4
> > > > > > >
> > > > > > >
> > > > > > > >
> > > > > > > > I can help on the release if there are no objections.
> > > > > > >
> > > > > > >
> > > > > > > > Thanks !
> > > > > > > > Regards
> > > > > > > > JB
> > > > > > > >
> > > > > > >
> > > > > >
> > > > >
> > > >
> >
>
Re: [PROPOSAL] Apache Avro 1.11.4 release
Posted by Fokko Driesprong <fo...@apache.org>.
Hey Ryan,
It is great seeing you here again!
Likely it will take some work to get the release machinery up and running
again. I would say that 1.12.0 is the most important one so maybe good to
do that one first. Of course, I'm also happy to help out!
Kind regards,
Fokko
Op za 6 apr 2024 om 22:30 schreef Oscar Westra van Holthe - Kind <
opwvhk@apache.org>:
> Hi everyone,
>
> As I remember the discussion, we'd support both the last major release and
> the current one. This would mean we should release both 1.11.4 and 1.12.0.
>
> Did I remember correctly?
>
>
> Kind regards,
> Oscar
>
> --
> Oscar Westra van Holthe - Kind <op...@apache.org>
>
> Op vr 5 apr. 2024 17:20 schreef Ryan Skraba <ry...@skraba.com>:
>
> > Hello everyone! I've been away for a bit, but I also think a new
> > release would be welcome :D
> >
> > I'm willing to put in the work to do the packaging and deployment,
> > especially if I can help another future "release manager" get
> > everything in place to do the next one!
> >
> > Are we aligned on doing a 1.11.4 release or a 1.12.0 release? At one
> > point we were pretty convinced that we would continue to maintain the
> > 1.11.x branch so that we have two valid major releases[1].
> >
> > I (errrr...) haven't built Avro recently on my local machine, which is
> > currently required in order to do a release.[2] I can give that a
> > try!
> >
> > All my best, Ryan
> >
> > [1]: https://lists.apache.org/thread/d3wx977pk6gxjnjg4d1jk3583f2bfgx0
> > "[DISCUSS] Release maintenance and lifecycle"
> > [2]: https://cwiki.apache.org/confluence/display/AVRO/How+To+Release
> > "How to release"
> >
> >
> >
> >
> >
> > On Wed, Apr 3, 2024 at 11:03 AM Jean-Baptiste Onofré
> > <jb...@apache.org> wrote:
> > >
> > > Thanks Fokko !
> > >
> > > Great. Let me check #3871 also.
> > >
> > > Regards
> > > JB
> > >
> > > On 2024/04/02 15:00:04 "Driesprong, Fokko" wrote:
> > > > Sorry for the late reply JB.
> > > >
> > > > I'll do a review of #2642 <https://github.com/apache/avro/pull/2642
> >.
> > I
> > > > already tested this against Iceberg locally and didn't see any issues
> > > > there. I would love to get in #3871
> > > > <https://github.com/apache/avro/pull/2732> as well.
> > > >
> > > > Cheers, Fokko
> > > >
> > > > Op di 2 apr 2024 om 16:57 schreef Jean-Baptiste Onofré <
> > jbonofre@apache.org
> > > > >:
> > > >
> > > > > Hi folks,
> > > > >
> > > > > As discussed on this thread, I would like to move forward on 1.12.0
> > > > > release.
> > > > > Thoughts ?
> > > > >
> > > > > I'm doing a pass on the issues.
> > > > >
> > > > > PS: I have a weird behavior with the mailing list, I might have to
> > > > > re-subscribe.
> > > > >
> > > > > Regards
> > > > > JB
> > > > >
> > > > > On 2024/03/14 08:53:05 Jean-Baptiste Onofré wrote:
> > > > > > Hey Martin
> > > > > >
> > > > > > Awesome !
> > > > > >
> > > > > > Happy to help with 1.12.0 if needed :)
> > > > > >
> > > > > > Thanks !
> > > > > > Regards
> > > > > > JB
> > > > > >
> > > > > > On 2024/03/14 08:46:05 Martin Grigorov wrote:
> > > > > > > Hi,
> > > > > > >
> > > > > > > On Wed, Mar 13, 2024 at 7:16 PM Jean-Baptiste Onofré <
> > jb@nanthrax.net>
> > > > > > > wrote:
> > > > > > >
> > > > > > > > Hi folks,
> > > > > > > >
> > > > > > > > Recently, we upgraded to commons-compress 1.26.0 (on main).
> > > > > > > > commons-compress 1.26.0 fixes several CVEs (CVE-2024-25710,
> > > > > > > > CVE-2024-26308, CVE-2023-42503).
> > > > > > > >
> > > > > > > > Would it be possible to release Avro 1.11.4 (that will
> include
> > > > > > > > commons-compress update) ?
> > > > > > > >
> > > > > > >
> > > > > > > Actually a few weeks ago there was a proposal to release
> 1.12.0!
> > > > > > >
> https://lists.apache.org/thread/b8p8jkxx8f23yrss14q0y0ptdlttnxp4
> > > > > > >
> > > > > > >
> > > > > > > >
> > > > > > > > I can help on the release if there are no objections.
> > > > > > >
> > > > > > >
> > > > > > > > Thanks !
> > > > > > > > Regards
> > > > > > > > JB
> > > > > > > >
> > > > > > >
> > > > > >
> > > > >
> > > >
> >
>
Re: [PROPOSAL] Apache Avro 1.11.4 release
Posted by Oscar Westra van Holthe - Kind <op...@apache.org>.
Hi everyone,
As I remember the discussion, we'd support both the last major release and
the current one. This would mean we should release both 1.11.4 and 1.12.0.
Did I remember correctly?
Kind regards,
Oscar
--
Oscar Westra van Holthe - Kind <op...@apache.org>
Op vr 5 apr. 2024 17:20 schreef Ryan Skraba <ry...@skraba.com>:
> Hello everyone! I've been away for a bit, but I also think a new
> release would be welcome :D
>
> I'm willing to put in the work to do the packaging and deployment,
> especially if I can help another future "release manager" get
> everything in place to do the next one!
>
> Are we aligned on doing a 1.11.4 release or a 1.12.0 release? At one
> point we were pretty convinced that we would continue to maintain the
> 1.11.x branch so that we have two valid major releases[1].
>
> I (errrr...) haven't built Avro recently on my local machine, which is
> currently required in order to do a release.[2] I can give that a
> try!
>
> All my best, Ryan
>
> [1]: https://lists.apache.org/thread/d3wx977pk6gxjnjg4d1jk3583f2bfgx0
> "[DISCUSS] Release maintenance and lifecycle"
> [2]: https://cwiki.apache.org/confluence/display/AVRO/How+To+Release
> "How to release"
>
>
>
>
>
> On Wed, Apr 3, 2024 at 11:03 AM Jean-Baptiste Onofré
> <jb...@apache.org> wrote:
> >
> > Thanks Fokko !
> >
> > Great. Let me check #3871 also.
> >
> > Regards
> > JB
> >
> > On 2024/04/02 15:00:04 "Driesprong, Fokko" wrote:
> > > Sorry for the late reply JB.
> > >
> > > I'll do a review of #2642 <https://github.com/apache/avro/pull/2642>.
> I
> > > already tested this against Iceberg locally and didn't see any issues
> > > there. I would love to get in #3871
> > > <https://github.com/apache/avro/pull/2732> as well.
> > >
> > > Cheers, Fokko
> > >
> > > Op di 2 apr 2024 om 16:57 schreef Jean-Baptiste Onofré <
> jbonofre@apache.org
> > > >:
> > >
> > > > Hi folks,
> > > >
> > > > As discussed on this thread, I would like to move forward on 1.12.0
> > > > release.
> > > > Thoughts ?
> > > >
> > > > I'm doing a pass on the issues.
> > > >
> > > > PS: I have a weird behavior with the mailing list, I might have to
> > > > re-subscribe.
> > > >
> > > > Regards
> > > > JB
> > > >
> > > > On 2024/03/14 08:53:05 Jean-Baptiste Onofré wrote:
> > > > > Hey Martin
> > > > >
> > > > > Awesome !
> > > > >
> > > > > Happy to help with 1.12.0 if needed :)
> > > > >
> > > > > Thanks !
> > > > > Regards
> > > > > JB
> > > > >
> > > > > On 2024/03/14 08:46:05 Martin Grigorov wrote:
> > > > > > Hi,
> > > > > >
> > > > > > On Wed, Mar 13, 2024 at 7:16 PM Jean-Baptiste Onofré <
> jb@nanthrax.net>
> > > > > > wrote:
> > > > > >
> > > > > > > Hi folks,
> > > > > > >
> > > > > > > Recently, we upgraded to commons-compress 1.26.0 (on main).
> > > > > > > commons-compress 1.26.0 fixes several CVEs (CVE-2024-25710,
> > > > > > > CVE-2024-26308, CVE-2023-42503).
> > > > > > >
> > > > > > > Would it be possible to release Avro 1.11.4 (that will include
> > > > > > > commons-compress update) ?
> > > > > > >
> > > > > >
> > > > > > Actually a few weeks ago there was a proposal to release 1.12.0!
> > > > > > https://lists.apache.org/thread/b8p8jkxx8f23yrss14q0y0ptdlttnxp4
> > > > > >
> > > > > >
> > > > > > >
> > > > > > > I can help on the release if there are no objections.
> > > > > >
> > > > > >
> > > > > > > Thanks !
> > > > > > > Regards
> > > > > > > JB
> > > > > > >
> > > > > >
> > > > >
> > > >
> > >
>
Re: [PROPOSAL] Apache Avro 1.11.4 release
Posted by Ryan Skraba <ry...@skraba.com>.
Hello everyone! I've been away for a bit, but I also think a new
release would be welcome :D
I'm willing to put in the work to do the packaging and deployment,
especially if I can help another future "release manager" get
everything in place to do the next one!
Are we aligned on doing a 1.11.4 release or a 1.12.0 release? At one
point we were pretty convinced that we would continue to maintain the
1.11.x branch so that we have two valid major releases[1].
I (errrr...) haven't built Avro recently on my local machine, which is
currently required in order to do a release.[2] I can give that a
try!
All my best, Ryan
[1]: https://lists.apache.org/thread/d3wx977pk6gxjnjg4d1jk3583f2bfgx0
"[DISCUSS] Release maintenance and lifecycle"
[2]: https://cwiki.apache.org/confluence/display/AVRO/How+To+Release
"How to release"
On Wed, Apr 3, 2024 at 11:03 AM Jean-Baptiste Onofré
<jb...@apache.org> wrote:
>
> Thanks Fokko !
>
> Great. Let me check #3871 also.
>
> Regards
> JB
>
> On 2024/04/02 15:00:04 "Driesprong, Fokko" wrote:
> > Sorry for the late reply JB.
> >
> > I'll do a review of #2642 <https://github.com/apache/avro/pull/2642>. I
> > already tested this against Iceberg locally and didn't see any issues
> > there. I would love to get in #3871
> > <https://github.com/apache/avro/pull/2732> as well.
> >
> > Cheers, Fokko
> >
> > Op di 2 apr 2024 om 16:57 schreef Jean-Baptiste Onofré <jbonofre@apache.org
> > >:
> >
> > > Hi folks,
> > >
> > > As discussed on this thread, I would like to move forward on 1.12.0
> > > release.
> > > Thoughts ?
> > >
> > > I'm doing a pass on the issues.
> > >
> > > PS: I have a weird behavior with the mailing list, I might have to
> > > re-subscribe.
> > >
> > > Regards
> > > JB
> > >
> > > On 2024/03/14 08:53:05 Jean-Baptiste Onofré wrote:
> > > > Hey Martin
> > > >
> > > > Awesome !
> > > >
> > > > Happy to help with 1.12.0 if needed :)
> > > >
> > > > Thanks !
> > > > Regards
> > > > JB
> > > >
> > > > On 2024/03/14 08:46:05 Martin Grigorov wrote:
> > > > > Hi,
> > > > >
> > > > > On Wed, Mar 13, 2024 at 7:16 PM Jean-Baptiste Onofré <jb...@nanthrax.net>
> > > > > wrote:
> > > > >
> > > > > > Hi folks,
> > > > > >
> > > > > > Recently, we upgraded to commons-compress 1.26.0 (on main).
> > > > > > commons-compress 1.26.0 fixes several CVEs (CVE-2024-25710,
> > > > > > CVE-2024-26308, CVE-2023-42503).
> > > > > >
> > > > > > Would it be possible to release Avro 1.11.4 (that will include
> > > > > > commons-compress update) ?
> > > > > >
> > > > >
> > > > > Actually a few weeks ago there was a proposal to release 1.12.0!
> > > > > https://lists.apache.org/thread/b8p8jkxx8f23yrss14q0y0ptdlttnxp4
> > > > >
> > > > >
> > > > > >
> > > > > > I can help on the release if there are no objections.
> > > > >
> > > > >
> > > > > > Thanks !
> > > > > > Regards
> > > > > > JB
> > > > > >
> > > > >
> > > >
> > >
> >
Re: [PROPOSAL] Apache Avro 1.11.4 release
Posted by Jean-Baptiste Onofré <jb...@apache.org>.
Thanks Fokko !
Great. Let me check #3871 also.
Regards
JB
On 2024/04/02 15:00:04 "Driesprong, Fokko" wrote:
> Sorry for the late reply JB.
>
> I'll do a review of #2642 <https://github.com/apache/avro/pull/2642>. I
> already tested this against Iceberg locally and didn't see any issues
> there. I would love to get in #3871
> <https://github.com/apache/avro/pull/2732> as well.
>
> Cheers, Fokko
>
> Op di 2 apr 2024 om 16:57 schreef Jean-Baptiste Onofré <jbonofre@apache.org
> >:
>
> > Hi folks,
> >
> > As discussed on this thread, I would like to move forward on 1.12.0
> > release.
> > Thoughts ?
> >
> > I'm doing a pass on the issues.
> >
> > PS: I have a weird behavior with the mailing list, I might have to
> > re-subscribe.
> >
> > Regards
> > JB
> >
> > On 2024/03/14 08:53:05 Jean-Baptiste Onofré wrote:
> > > Hey Martin
> > >
> > > Awesome !
> > >
> > > Happy to help with 1.12.0 if needed :)
> > >
> > > Thanks !
> > > Regards
> > > JB
> > >
> > > On 2024/03/14 08:46:05 Martin Grigorov wrote:
> > > > Hi,
> > > >
> > > > On Wed, Mar 13, 2024 at 7:16 PM Jean-Baptiste Onofré <jb...@nanthrax.net>
> > > > wrote:
> > > >
> > > > > Hi folks,
> > > > >
> > > > > Recently, we upgraded to commons-compress 1.26.0 (on main).
> > > > > commons-compress 1.26.0 fixes several CVEs (CVE-2024-25710,
> > > > > CVE-2024-26308, CVE-2023-42503).
> > > > >
> > > > > Would it be possible to release Avro 1.11.4 (that will include
> > > > > commons-compress update) ?
> > > > >
> > > >
> > > > Actually a few weeks ago there was a proposal to release 1.12.0!
> > > > https://lists.apache.org/thread/b8p8jkxx8f23yrss14q0y0ptdlttnxp4
> > > >
> > > >
> > > > >
> > > > > I can help on the release if there are no objections.
> > > >
> > > >
> > > > > Thanks !
> > > > > Regards
> > > > > JB
> > > > >
> > > >
> > >
> >
>
Re: [PROPOSAL] Apache Avro 1.11.4 release
Posted by "Driesprong, Fokko" <fo...@driesprong.frl>.
Sorry for the late reply JB.
I'll do a review of #2642 <https://github.com/apache/avro/pull/2642>. I
already tested this against Iceberg locally and didn't see any issues
there. I would love to get in #3871
<https://github.com/apache/avro/pull/2732> as well.
Cheers, Fokko
Op di 2 apr 2024 om 16:57 schreef Jean-Baptiste Onofré <jbonofre@apache.org
>:
> Hi folks,
>
> As discussed on this thread, I would like to move forward on 1.12.0
> release.
> Thoughts ?
>
> I'm doing a pass on the issues.
>
> PS: I have a weird behavior with the mailing list, I might have to
> re-subscribe.
>
> Regards
> JB
>
> On 2024/03/14 08:53:05 Jean-Baptiste Onofré wrote:
> > Hey Martin
> >
> > Awesome !
> >
> > Happy to help with 1.12.0 if needed :)
> >
> > Thanks !
> > Regards
> > JB
> >
> > On 2024/03/14 08:46:05 Martin Grigorov wrote:
> > > Hi,
> > >
> > > On Wed, Mar 13, 2024 at 7:16 PM Jean-Baptiste Onofré <jb...@nanthrax.net>
> > > wrote:
> > >
> > > > Hi folks,
> > > >
> > > > Recently, we upgraded to commons-compress 1.26.0 (on main).
> > > > commons-compress 1.26.0 fixes several CVEs (CVE-2024-25710,
> > > > CVE-2024-26308, CVE-2023-42503).
> > > >
> > > > Would it be possible to release Avro 1.11.4 (that will include
> > > > commons-compress update) ?
> > > >
> > >
> > > Actually a few weeks ago there was a proposal to release 1.12.0!
> > > https://lists.apache.org/thread/b8p8jkxx8f23yrss14q0y0ptdlttnxp4
> > >
> > >
> > > >
> > > > I can help on the release if there are no objections.
> > >
> > >
> > > > Thanks !
> > > > Regards
> > > > JB
> > > >
> > >
> >
>
Re: [PROPOSAL] Apache Avro 1.11.4 release
Posted by Jean-Baptiste Onofré <jb...@apache.org>.
Hi folks,
As discussed on this thread, I would like to move forward on 1.12.0 release.
Thoughts ?
I'm doing a pass on the issues.
PS: I have a weird behavior with the mailing list, I might have to re-subscribe.
Regards
JB
On 2024/03/14 08:53:05 Jean-Baptiste Onofré wrote:
> Hey Martin
>
> Awesome !
>
> Happy to help with 1.12.0 if needed :)
>
> Thanks !
> Regards
> JB
>
> On 2024/03/14 08:46:05 Martin Grigorov wrote:
> > Hi,
> >
> > On Wed, Mar 13, 2024 at 7:16 PM Jean-Baptiste Onofré <jb...@nanthrax.net>
> > wrote:
> >
> > > Hi folks,
> > >
> > > Recently, we upgraded to commons-compress 1.26.0 (on main).
> > > commons-compress 1.26.0 fixes several CVEs (CVE-2024-25710,
> > > CVE-2024-26308, CVE-2023-42503).
> > >
> > > Would it be possible to release Avro 1.11.4 (that will include
> > > commons-compress update) ?
> > >
> >
> > Actually a few weeks ago there was a proposal to release 1.12.0!
> > https://lists.apache.org/thread/b8p8jkxx8f23yrss14q0y0ptdlttnxp4
> >
> >
> > >
> > > I can help on the release if there are no objections.
> >
> >
> > > Thanks !
> > > Regards
> > > JB
> > >
> >
>
Re: [PROPOSAL] Apache Avro 1.11.4 release
Posted by Jean-Baptiste Onofré <jb...@apache.org>.
Hey Martin
Awesome !
Happy to help with 1.12.0 if needed :)
Thanks !
Regards
JB
On 2024/03/14 08:46:05 Martin Grigorov wrote:
> Hi,
>
> On Wed, Mar 13, 2024 at 7:16 PM Jean-Baptiste Onofré <jb...@nanthrax.net>
> wrote:
>
> > Hi folks,
> >
> > Recently, we upgraded to commons-compress 1.26.0 (on main).
> > commons-compress 1.26.0 fixes several CVEs (CVE-2024-25710,
> > CVE-2024-26308, CVE-2023-42503).
> >
> > Would it be possible to release Avro 1.11.4 (that will include
> > commons-compress update) ?
> >
>
> Actually a few weeks ago there was a proposal to release 1.12.0!
> https://lists.apache.org/thread/b8p8jkxx8f23yrss14q0y0ptdlttnxp4
>
>
> >
> > I can help on the release if there are no objections.
>
>
> > Thanks !
> > Regards
> > JB
> >
>
Re: [PROPOSAL] Apache Avro 1.11.4 release
Posted by Martin Grigorov <mg...@apache.org>.
Hi,
On Wed, Mar 13, 2024 at 7:16 PM Jean-Baptiste Onofré <jb...@nanthrax.net>
wrote:
> Hi folks,
>
> Recently, we upgraded to commons-compress 1.26.0 (on main).
> commons-compress 1.26.0 fixes several CVEs (CVE-2024-25710,
> CVE-2024-26308, CVE-2023-42503).
>
> Would it be possible to release Avro 1.11.4 (that will include
> commons-compress update) ?
>
Actually a few weeks ago there was a proposal to release 1.12.0!
https://lists.apache.org/thread/b8p8jkxx8f23yrss14q0y0ptdlttnxp4
>
> I can help on the release if there are no objections.
> Thanks !
> Regards
> JB
>