The Apache News Round-up: week ending 21 September 2018

As another week draws to a close, let’s take a look at the Apache community’s activities from the past week:

ASF Board –management and oversight of the business affairs of the corporation in accordance with the Foundation’s bylaws.
 – The Apache Software Foundation Operations Summary: May – July 2018 https://s.apache.org/qiKn
 – Next Board Meeting: 17 October. Board calendar and minutes http://apache.org/foundation/board/calendar.html

ASF Fundraising –support through donations and Sponsorship help offset the ASF’s day-to-day operating expenses and keep Apache software for everyone.
 – The Apache® Software Foundation Welcomes Tencent as its Newest Sponsor at the Platinum Level https://s.apache.org/KzEz

ApacheCon™ –the ASF’s official global conference series, now in its 20th year.
 – 24-27 September: T-3 days to Montreal. 100+ Apache project and community sessions, from CloudStack to Spark to Tomcat to Geospatial to Hackathon, BarCamp, and more. See you there! http://apachecon.com/acna18/
 – Guest Post: looking forward to learning more about the wide array of projects in the Apache fold at ApacheCon https://s.apache.org/RkWd
 – 4 December: Apache Roadshow DC and Open Source Job Fair. CFP open through 15 October http://www.apachecon.com/usroadshow18/

ASF Infrastructure –our distributed team on three continents keeps the ASF’s infrastructure running around the clock.
 – 7M+ weekly checks yield deft performance at 99.41% uptime. http://status.apache.org/

ASF Operations Factoid –this week, 504 Apache contributors changed 1,297,500 lines of code over 3,801 commits. Top 5 contributors, in order, are: Radu Cotescu, Jean-Baptiste Onofré, Carsten Ziegeler, Hervé Boutemy, and Carlos Sanchez Gonzalez.

Apache Attic –provides process and solutions to make it clear when an Apache project has reached its end of life.
 – Apache Lucy has retired http://mail-archives.apache.org/mod_mbox/www-announce/201809.mbox/%3Cpony-a4cac82164ef67d9d07d379b5d5d8c4abe1e02ff-a56909df10a4d5ddf5298357d8c193a36e67aeb0%40announce.apache.org%3E

Apache Atlas™ –a scalable and extensible set of core foundational governance services.
 –  Apache Atlas 1.1.0 released http://atlas.apache.org/

Apache Calcite™ Avatica Go –framework for building database drivers; the Avatica Go client is a Go database/sql driver that enables Go programs to communicate with the Avatica server.
 – Apache Calcite Avatica Go 3.2.0 released https://calcite.apache.org/

Apache Directory™ Studio –a complete directory tooling platform intended to be used with any LDAP server however it is particularly designed for use with ApacheDS.
 – Apache Directory Studio 2.0-0-M14 released https://directory.apache.org/

Apache Flink™ –an Open Source stream processing framework for distributed, high-performing, always-available, and accurate data streaming applications.
 – Apache Flink 1.5.4 and 1.6.1 released https://flink.apache.org/

Apache Jackrabbit™ –a scalable, high-performance hierarchical content repository designed for use as the foundation of modern world-class Web sites and other demanding content applications.
 – Apache Jackrabbit Oak 1.6.14 released http://jackrabbit.apache.org/

Apache JMeter™ –a 100% pure Java application designed to test server applications.
 – Apache JMeter 5.0 released http://jmeter.apache.org/

Apache Kylin™ –an Open Source Distributed Analytics Engine designed to provide SQL interface and multi-dimensional analysis (OLAP) on Apache Hadoop, supporting extremely large datasets.
 – Apache Kylin 2.5.0 released https://kylin.apache.org/

Apache Portable Runtime™ –software libraries that provide a predictable and consistent interface to underlying platform-specific implementations.
 – Apache Portable Runtime APR 1.6.5 released http://apr.apache.org/

Apache Pulsar (incubating) –a highly scalable, low latency messaging platform running on commodity hardware.
 – Apache Pulsar 2.1.1-incubating released https://pulsar.incubator.apache.org/

Apache SpamAssassin™ –an extensible email filter used to identify spam.
 – Apache SpamAssassin 3.4.2 released https://spamassassin.apache.org/
 – Apache SpamAssassin 3.4.2 resolves CVE-2017-15705, CVE-2016-1238, CVE-2018-11780 & CVE-2018-11781 http://mail-archives.apache.org/mod_mbox/www-announce/201809.mbox/%3CCAMMMAUH38nTHLyjMkZQdhLHh6trT%2BEzd%3DMGhS%3D%2B%3DbTuGWcYJSA%40mail.gmail.com%3E

Apache Tika™ –a toolkit for detecting and extracting metadata and structured text content from various documents using existing parser libraries.
 – Apache Tika 1.19 released http://tika.apache.org/
 – [CVE-2018-11761] Apache Tika DoS XML Entity Expansion Vulnerability http://mail-archives.apache.org/mod_mbox/www-announce/201809.mbox/%3CCAC1dCwVx2Z1haCnvYBhH7nQRN4kYKjwkLfjsCbeFHv2tRcBonA%40mail.gmail.com%3E
 – [CVE-2018-11762] Zip Slip Vulnerability in Apache Tika’s tika-app http://mail-archives.apache.org/mod_mbox/www-announce/201809.mbox/%3CCAC1dCwV2-kTJKjNO1rV65bQrekkur7OWAu1x%2BpPRToRRYk%3DGPA%40mail.gmail.com%3E
 – [CVE-2018-8017] Apache Tika Denial of Service Vulnerability — Potential Infinite Loop in IptcAnpaParser http://mail-archives.apache.org/mod_mbox/www-announce/201809.mbox/%3CCAC1dCwVOEYsB1c4s2DYkhsafT8q3Fupt_OFugXj9J1RCZuf3UQ%40mail.gmail.com%3E

Apache Tomcat™ –an Open Source software implementation of the Java Servlet, JavaServer Pages, Java Unified Expression Language, Java WebSocket and JASPIC technologies.
– Apache Tomcat 7.0.91 released https://tomcat.apache.org/

Apache Wicket™ –an Open Source Java component oriented Web application framework that powers thousands of Web applications and Web sites for governments, stores, universities, cities, banks, email providers, and more.
 – Apache Wicket 8.1.0 released http://wicket.apache.org/

Did You Know?

 – Did you know that, according to a survey by DZone asking "What Open Source Software Do You Use?", the leading answer is "Apache"? https://projects.apache.org/

 – Did you know that Apache CouchDB provides binaries (RPMs and debs)? http://couchdb.apache.org/

 – Did you know that you can join us at BarCampApache next week during ApacheCon? https://wiki.apache.org/apachecon/BarCampApacheMontreal

Apache Community Notices:

 – ASF Annual Report for FY2018 https://s.apache.org/FY2018AnnualReport

 – The Apache Software Foundation Celebrates 19 Years of Open Source Leadership "The Apache Way" https://s.apache.org/gK4Q

 – Read "Open – For Business – At the ASF" by Merv Adrian, VP Research at Gartner https://blogs.gartner.com/merv-adrian/2018/03/27/open-for-business-at-the-asf/

 – The Apache Software Foundation 2018 Vision Statement https://s.apache.org/zqC3

 – Apache in 2017 – By The Digits https://s.apache.org/h8do

 – Foundation Statement –Apache Is Open. https://s.apache.org/PIRA

 – "Success at Apache" focuses on the processes behind why the ASF "just works". https://blogs.apache.org/foundation/category/SuccessAtApache

 – Please follow/like/re-tweet the ASF on social media: @TheASF on Twitter and on LinkedIn at https://www.linkedin.com/company/the-apache-software-foundation

 – Do friend and follow us on the Apache Community Facebook page https://www.facebook.com/ApacheSoftwareFoundation/and Twitter account https://twitter.com/ApacheCommunity

 – The list of Apache project-related MeetUps can be found at http://events.apache.org/event/meetups.html

 – ApacheCon North America will be held 24-27 September in Montreal http://apachecon.com/

 – The Apache Spark community will be presenting at In-Memory Computing Summit North America 2-3 October in San Francicso https://www.imcsummit.org/2018/us/

 – The Apache Big Data community will be at DataWorks Summit 18-21 March 2019 in Barcelona and 20-23 May 2019 in Washington DC https://dataworkssummit.com/

 – Find out how you can participate with Apache community/projects/activities –opportunities open with Apache HTTP Server, Avro, ComDev (community development), Directory, Incubator, OODT, POI, Polygene, Syncope, Tika, Trafodion, and more! https://helpwanted.apache.org/

 – Are your software solutions Powered by Apache? Download & use our "Powered By" logos http://www.apache.org/foundation/press/kit/#poweredby
= = =
For real-time updates, sign up for Apache-related news by sending mail to announce-subscribe@apache.org and follow @TheASF on Twitter. For a broader spectrum from the Apache community, https://twitter.com/PlanetApache provides an aggregate of Project activities as well as the personal blogs and tweets of select ASF Committers.

# # # 

Related Articles

As 2025 comes to a close, The ASF reflects on a year defined by steady progress across a wide range of efforts that support...

Dirk-Willem van Gulik, VP Public Affairs, Apache Software Foundation Over the last two years, The Apache Software Foundation (ASF) and many other open source...

We’re wrapping up another great week with the following activities from the Apache community: ASF Board – management and oversight of the business affairs...

Subscribe to ASF Plus One, Our Monthly Newsletter