All,

I'm closing this vote in order to get this critical PR CVE-2020-25649:
bumping jackson to patched version
<https://github.com/apache/kafka/pull/9702>  merged into 2.7.

Once we merge the PR, I'll push out a new RC.

Thanks to all who voted for this RC.

Bill

On Tue, Dec 15, 2020 at 1:16 PM Kowshik Prakasam <kpraka...@confluent.io>
wrote:

> Hi Bill,
>
> Just a heads up that KAFKA-9393 that was previously marked as fixed in
> 2.7.0 has now been changed to 2.8.0. The corresponding PR is not present in
> 2.7.0 commit history. Please could you regenerate the release notes to help
> pick up this change?
>
>
> Cheers,
> Kowshik
>
>
> On Tue, Dec 15, 2020 at 9:20 AM Bill Bejeck <b...@confluent.io> wrote:
>
> > Thanks for voting John, I'm cc'ing the dev list as well.
> >
> > On Mon, Dec 14, 2020 at 8:35 PM John Roesler <vvcep...@apache.org>
> wrote:
> >
> > > Thanks for this release, Bill,
> > >
> > > I ran though the quickstart (just the zk, broker, and
> > > console clients part), verified the signatures, and also
> > > built and ran the tests.
> > >
> > > I'm +1 (binding).
> > >
> > > Thanks,
> > > -John
> > >
> > > On Mon, 2020-12-14 at 14:58 -0800, Guozhang Wang wrote:
> > > > I checked the docs and ran unit tests, no red flags found. +1.
> > > >
> > > > On Fri, Dec 11, 2020 at 5:45 AM Bill Bejeck <bbej...@gmail.com>
> wrote:
> > > >
> > > > > Updated with link to successful Jenkins build.
> > > > >
> > > > > * Successful Jenkins builds for the 2.7 branch:
> > > > >      Unit/integration tests:
> > > > >
> > > > >
> > >
> >
> https://ci-builds.apache.org/blue/organizations/jenkins/Kafka%2Fkafka-2.7-jdk8/detail/kafka-2.7-jdk8/78/
> > > > >
> > > > > On Thu, Dec 10, 2020 at 5:17 PM Bill Bejeck <bbej...@gmail.com>
> > wrote:
> > > > >
> > > > > > Hello Kafka users, developers and client-developers,
> > > > > >
> > > > > > This is the sixth candidate for release of Apache Kafka 2.7.0.
> > > > > >
> > > > > > * Configurable TCP connection timeout and improve the initial
> > > metadata
> > > > > > fetch
> > > > > > * Enforce broker-wide and per-listener connection creation rate
> > > (KIP-612,
> > > > > > part 1)
> > > > > > * Throttle Create Topic, Create Partition and Delete Topic
> > Operations
> > > > > > * Add TRACE-level end-to-end latency metrics to Streams
> > > > > > * Add Broker-side SCRAM Config API
> > > > > > * Support PEM format for SSL certificates and private key
> > > > > > * Add RocksDB Memory Consumption to RocksDB Metrics
> > > > > > * Add Sliding-Window support for Aggregations
> > > > > >
> > > > > > This release also includes a few other features, 53 improvements,
> > > and 84
> > > > > > bug fixes.
> > > > > >
> > > > > > Release notes for the 2.7.0 release:
> > > > > >
> > https://home.apache.org/~bbejeck/kafka-2.7.0-rc5/RELEASE_NOTES.html
> > > > > >
> > > > > > *** Please download, test and vote by Friday, December 18, 12 PM
> ET
> > > ***
> > > > > >
> > > > > > Kafka's KEYS file containing PGP keys we use to sign the release:
> > > > > > https://kafka.apache.org/KEYS
> > > > > >
> > > > > > * Release artifacts to be voted upon (source and binary):
> > > > > > https://home.apache.org/~bbejeck/kafka-2.7.0-rc5/
> > > > > >
> > > > > > * Maven artifacts to be voted upon:
> > > > > >
> > > https://repository.apache.org/content/groups/staging/org/apache/kafka/
> > > > > >
> > > > > > * Javadoc:
> > > > > > https://home.apache.org/~bbejeck/kafka-2.7.0-rc5/javadoc/
> > > > > >
> > > > > > * Tag to be voted upon (off 2.7 branch) is the 2.7.0 tag:
> > > > > > https://github.com/apache/kafka/releases/tag/2.7.0-rc5
> > > > > >
> > > > > > * Documentation:
> > > > > > https://kafka.apache.org/27/documentation.html
> > > > > >
> > > > > > * Protocol:
> > > > > > https://kafka.apache.org/27/protocol.html
> > > > > >
> > > > > > * Successful Jenkins builds for the 2.7 branch:
> > > > > > Unit/integration tests: Link to follow
> > > > > >
> > > > > > Thanks,
> > > > > > Bill
> > > > > >
> > > > >
> > > >
> > > >
> > >
> > >
> > >
> >
>

Reply via email to