Re: [VOTE] Release Apache Commons BCEL 6.6.0 based on RC1

2022-10-11 Thread Gary Gregory
This vote passes with 3 +1 binding votes and 2 +1 non-binding votes: - Arturo Bernal non-binding - Bruno Kinoshita binding - Matt Sicker binding - Mark Roberts non-binding - Gary Gregory binding Gary On Tue, Oct 11, 2022 at 5:11 PM Mark Roberts wrote: > > +1 > > Tested via integration with Daik

Re: [VOTE] Release Apache Commons BCEL 6.6.0 based on RC1

2022-10-11 Thread Gary Gregory
My +1 Gary On Sat, Oct 8, 2022 at 8:35 AM Gary Gregory wrote: > > We have fixed a few bugs and added some enhancements since Apache > Commons BCEL 6.5.0 was released, so I would like to release Apache > Commons BCEL 6.6.0. > > Apache Commons BCEL 6.6.0 RC1 is available for review here: > htt

RE: [VOTE] Release Apache Commons BCEL 6.6.0 based on RC1

2022-10-11 Thread Mark Roberts
+1 Tested via integration with Daikon tool set. Passed all build and acceptance tests. Mark Roberts -Original Message- From: Gary Gregory [mailto:garydgreg...@gmail.com] Sent: Saturday, October 8, 2022 5:36 AM To: Commons Developers List Subject: [VOTE] Release Apache Commons BCEL 6.6

Re: [VOTE] Release Apache Commons BCEL 6.6.0 based on RC1

2022-10-11 Thread Matt Sicker
+1 Tested with Java versions 8.0.322-zulu, 11.0.15-zulu, and 17.0.2-zulu. Apache Maven 3.8.5 OS name: "mac os x", version: "12.6", arch: "aarch64", family: “mac" — Matt Sicker > On Oct 8, 2022, at 07:35, Gary Gregory wrote: > > We have fixed a few bugs and added some enhancements since Apache

Re: [jxpath] reported CVE and path forward

2022-10-11 Thread Mike Drob
Thanks for this outline, Mark. Some questions in line. Mike On Tue, Oct 11, 2022 at 6:13 AM Mark Thomas wrote: > Roman - don't do anything yet. > > Commons folk, I suggest the following which is based on how we have > oss-fuzz setup on Tomcat. > > 1. Create a Google account for fuzz-testing@c.a

Re: [VOTE] Release Apache Commons BCEL 6.6.0 based on RC1

2022-10-11 Thread Gary Gregory
We need more reviews, specifically from the PMC. Thank you! Gary On Sat, Oct 8, 2022, 08:35 Gary Gregory wrote: > We have fixed a few bugs and added some enhancements since Apache > Commons BCEL 6.5.0 was released, so I would like to release Apache > Commons BCEL 6.6.0. > > Apache Commons BCEL

Re: [jxpath] reported CVE and path forward

2022-10-11 Thread Mark Thomas
Roman - don't do anything yet. Commons folk, I suggest the following which is based on how we have oss-fuzz setup on Tomcat. 1. Create a Google account for fuzz-testing@c.a.o 2. Put the password for the account in the PMC private shared repo so any PMC member can access these reports. 3. Get

[ANNOUNCE] Apache Commons RNG 1.5 released

2022-10-11 Thread Alex Herbert
The Apache Commons Team is pleased to announce the availability of version 1.5 of "Apache Commons RNG". Apache Commons RNG provides Java implementations of pseudo-random numbers generators. Changes in this version include: New features: o RNG-182: Add a Bill of Materials (BOM) to aid in dependen