I am Generate a report of vulnerabilities that occur among dependencies when running `./gradlew :dependencyCheckUpdate`, I consistently hit
Unable to download meta file: https://nvd.nist.gov/feeds/json/cve/1.1/xxx.meta and seems the root cause is "unable to connect". Has anyone seen it in the past? -Rui On Sun, Dec 19, 2021 at 6:26 PM Rui Wang <amaliu...@apache.org> wrote: > Hi community, > > Now the main branch is locked at [1]. I will work toward RC0. > > > [1] > https://github.com/apache/calcite/commit/7a7b37fc1f4bd2121643539b0fd8e9c4f0f8ed09 > > > -Rui > > On Sun, Dec 19, 2021 at 1:19 AM Alessandro Solimando < > alessandro.solima...@gmail.com> wrote: > >> Hello everyone, >> I have merged https://github.com/apache/calcite/pull/2628 ( >> https://issues.apache.org/jira/browse/CALCITE-4917) into master. >> >> Best regards, >> Alessandro >> >> On Sat, 18 Dec 2021 at 21:21, Rui Wang <amaliu...@apache.org> wrote: >> >> > Thanks for more information Julian. Then there should not have known >> > blockers at this moment. >> > >> > Hi Alessandro, >> > >> > I will wait for another 24 hours before blocking the main branch. It >> should >> > be enough time so please feel free to merge PR once there is no >> objection. >> > >> > -Rui >> > >> > On Sat, Dec 18, 2021 at 11:45 AM Alessandro Solimando < >> > alessandro.solima...@gmail.com> wrote: >> > >> > > Hi everyone, >> > > I'd like to merge https://github.com/apache/calcite/pull/2628 ( >> > > https://issues.apache.org/jira/browse/CALCITE-4917) which is ready if >> > > there >> > > are no objections. >> > > >> > > Since it's just adding an extra test it's not urgent at all, so if it >> > > causes any troubles it can be postponed after the release. >> > > >> > > Best regards, >> > > Alessandro >> > > >> > > On Sat, 18 Dec 2021 at 19:19, Julian Hyde <jhyde.apa...@gmail.com> >> > wrote: >> > > >> > > > Ah, I see Stamatis has Log4j covered: >> > > > https://issues.apache.org/jira/browse/CALCITE-4950 < >> > > > https://issues.apache.org/jira/browse/CALCITE-4950>. >> > > > >> > > > > On Dec 18, 2021, at 10:17 AM, Julian Hyde <jhyde.apa...@gmail.com >> > >> > > > wrote: >> > > > > >> > > > > I think we should skip CALCITE-4907. There’s still discussion in >> its >> > > PR, >> > > > https://github.com/apache/calcite/pull/2620 < >> > > > https://github.com/apache/calcite/pull/2620>. I promise we’ll get >> it >> > in >> > > > soon after the release. >> > > > > >> > > > > In other news, there’s a new Log4j version, 2.17, addressing a new >> > > > CVE[1]. Let’s get that in. >> > > > > >> > > > > Julian >> > > > > >> > > > > [1] >> > > > >> > > >> > >> https://thehackernews.com/2021/12/apache-issues-3rd-patch-to-fix-new-high.html >> > > > < >> > > > >> > > >> > >> https://thehackernews.com/2021/12/apache-issues-3rd-patch-to-fix-new-high.html >> > > > > >> > > > > >> > > > >> On Dec 18, 2021, at 6:58 AM, Vladimir Ozerov <ppoze...@gmail.com >> > > > <mailto:ppoze...@gmail.com>> wrote: >> > > > >> >> > > > >> Hi Xiong, >> > > > >> >> > > > >> Thank you very much. >> > > > >> >> > > > >> Vladimir. >> > > > >> >> > > > >> Сб, 18 дек. 2021 г. в 14:32, xiong duan <nobigo...@gmail.com >> > <mailto: >> > > > nobigo...@gmail.com>>: >> > > > >> >> > > > >>> Hi Vladimir, >> > > > >>> >> > > > >>> I have merged. >> > > > >>> >> > > > >>> Vladimir Ozerov <ppoze...@gmail.com <mailto:ppoze...@gmail.com >> >> >> > > > 于2021年12月18日周六 16:58写道: >> > > > >>> >> > > > >>>> Hi Xiong, >> > > > >>>> >> > > > >>>> I've just resolved the conflicts. >> > > > >>>> >> > > > >>>> Regards, >> > > > >>>> Vladimir. >> > > > >>>> >> > > > >>>> сб, 18 дек. 2021 г. в 10:48, xiong duan <nobigo...@gmail.com >> > > <mailto: >> > > > nobigo...@gmail.com>>: >> > > > >>>> >> > > > >>>>> Hi, Vladimir. >> > > > >>>>> >> > > > >>>>> The PR[https://github.com/apache/calcite/pull/2464 < >> > > > https://github.com/apache/calcite/pull/2464>] looks good. If you >> > > > >>>>> have >> > > > >>>>> free time Please resolve the conflicts. Then we can merge it. >> > > > >>>>> >> > > > >>>>> Vladimir Ozerov <ppoze...@gmail.com <mailto: >> ppoze...@gmail.com>> >> > > > 于2021年12月18日周六 15:20写道: >> > > > >>>>> >> > > > >>>>>> Hi, >> > > > >>>>>> >> > > > >>>>>> Could you please also merge >> > > > >>>>>> https://github.com/apache/calcite/pull/2464 < >> > > > https://github.com/apache/calcite/pull/2464> ? I guess it got stuck >> > > > >>>>>> somehow, >> > > > >>>>>> as all the comments are addressed. This issue forced us to >> > create >> > > a >> > > > >>>> copy >> > > > >>>>> of >> > > > >>>>>> the AggregateUnionTransposeRule in our project. >> > > > >>>>>> >> > > > >>>>>> Regards, >> > > > >>>>>> Vladimir >> > > > >>>>>> >> > > > >>>>>> Сб, 18 дек. 2021 г. в 09:51, Rui Wang <amaliu...@apache.org >> > > > <mailto:amaliu...@apache.org>>: >> > > > >>>>>> >> > > > >>>>>>> Thanks Julian! >> > > > >>>>>>> >> > > > >>>>>>> Now we will just decide whether to merge CALCITE-4907 or >> not, >> > > then >> > > > >>> I >> > > > >>>>> will >> > > > >>>>>>> lock the main branch and start the release process. >> > > > >>>>>>> >> > > > >>>>>>> >> > > > >>>>>>> -Rui >> > > > >>>>>>> >> > > > >>>>>>> On Fri, Dec 17, 2021 at 10:29 PM Julian Hyde < >> > > > >>> jhyde.apa...@gmail.com <mailto:jhyde.apa...@gmail.com> >> > > > >>>>> >> > > > >>>>>>> wrote: >> > > > >>>>>>> >> > > > >>>>>>>> Rui, I have merged CALCITE-4946. >> > > > >>>>>>>> >> > > > >>>>>>>>> On Dec 17, 2021, at 10:21 PM, Rui Wang < >> amaliu...@apache.org >> > > >> > > > >>>>> wrote: >> > > > >>>>>>>>> >> > > > >>>>>>>>> Thanks Zhe. >> > > > >>>>>>>>> >> > > > >>>>>>>>> Hi Francesco, >> > > > >>>>>>>>> >> > > > >>>>>>>>> I left a comment in your PR. Can you take a look? >> > > > >>>>>>>>> >> > > > >>>>>>>>> -Rui >> > > > >>>>>>>>> >> > > > >>>>>>>>> On Fri, Dec 17, 2021 at 3:32 PM Zhe Hu <iluff...@163.com> >> > > > >>> wrote: >> > > > >>>>>>>>> >> > > > >>>>>>>>>> Hi, Rui. >> > > > >>>>>>>>>> CALCITE-4860 will be fixed in next release, you can pass >> it >> > > > >>>>>> currently. >> > > > >>>>>>>>>> Thanks for your work! >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> Best, >> > > > >>>>>>>>>> ZheHu >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> On 12/18/2021 06:08,Francesco Gini< >> francesco.g...@gmail.com >> > > >> > > > >>>>> wrote: >> > > > >>>>>>>>>> https://issues.apache.org/jira/browse/CALCITE-4907 is in >> > > > >>>> review. >> > > > >>>>> I >> > > > >>>>>>>> believe >> > > > >>>>>>>>>> I have addressed all the comments. Let me know if I >> missed >> > > > >>>>> anything. >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> On Fri, 17 Dec 2021 at 22:42, Jacques Nadeau < >> > > > >>>> jacq...@apache.org> >> > > > >>>>>>>> wrote: >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> I've merged CALCITE-4948 to mitigate the concerns around >> > > > >>>>>> CALCITE-4898 >> > > > >>>>>>>> and >> > > > >>>>>>>>>> maven repositories and category x licenses. >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> On Fri, Dec 17, 2021 at 1:02 PM Rui Wang < >> > > > >>> amaliu...@apache.org> >> > > > >>>>>>> wrote: >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> For the list of 1.29 fix Jira, several Jira have been >> marked >> > > > >>> as >> > > > >>>>>>> resolved >> > > > >>>>>>>>>> since this Monday. I will do another pass today but >> probably >> > > > >>> not >> > > > >>>>> all >> > > > >>>>>>>>>> those >> > > > >>>>>>>>>> will make the 1.29.0 release. >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> -Rui >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> On Fri, Dec 17, 2021 at 11:57 AM Ruben Q L < >> > rube...@gmail.com >> > > > >>>> >> > > > >>>>>> wrote: >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> Hello, >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> FYI https://issues.apache.org/jira/browse/CALCITE-4737 >> has >> > > > >>> been >> > > > >>>>>>>>>> merged. >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> Regards, >> > > > >>>>>>>>>> Ruben >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> On Fri, Dec 17, 2021 at 7:40 PM Julian Hyde < >> > > > >>>>> jhyde.apa...@gmail.com >> > > > >>>>>>> >> > > > >>>>>>>>>> wrote: >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> Rui, >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> Even though >> > > > >>> https://issues.apache.org/jira/browse/CALCITE-4898 >> > > > >>>> < >> > > > >>>>>>>>>> https://issues.apache.org/jira/browse/CALCITE-4898> is >> > marked >> > > > >>>>>> fixed, >> > > > >>>>>>>>>> there’s some fallout regarding maven repositories and >> > category >> > > > >>>> X. >> > > > >>>>>>>>>> That >> > > > >>>>>>>>>> needs to be sorted out before RC0. See [1]. >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> I’m working on getting >> > > > >>>>>>>>>> https://issues.apache.org/jira/browse/CALCITE-4946 >> > > > >>>>>>>>>> <https://issues.apache.org/jira/browse/CALCITE-4946> >> done >> > > > >>>> today. >> > > > >>>>>>>>>> Please >> > > > >>>>>>>>>> wait for that. >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> https://issues.apache.org/jira/browse/CALCITE-4885 < >> > > > >>>>>>>>>> https://issues.apache.org/jira/browse/CALCITE-4885> is a >> > big >> > > > >>>>>>>>>> refactoring >> > > > >>>>>>>>>> and, though I’d love to get it in before the release, it >> > isn’t >> > > > >>>>> going >> > > > >>>>>>>>>> to >> > > > >>>>>>>>>> happen. Don’t wait for it. >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> I also see the following as open or in progress and >> > > > >>> fix-in-1.29: >> > > > >>>>>>>>>> * https://issues.apache.org/jira/browse/CALCITE-4872 < >> > > > >>>>>>>>>> https://issues.apache.org/jira/browse/CALCITE-4872> >> (Will >> > > > >>>> Noble) >> > > > >>>>>>>>>> * https://issues.apache.org/jira/browse/CALCITE-4908 < >> > > > >>>>>>>>>> https://issues.apache.org/jira/browse/CALCITE-4908> >> > (Woonsan >> > > > >>>> Koo) >> > > > >>>>>>>>>> * https://issues.apache.org/jira/browse/CALCITE-4704 < >> > > > >>>>>>>>>> https://issues.apache.org/jira/browse/CALCITE-4704> >> > > > >>> (Stamatis) >> > > > >>>>>>>>>> * https://issues.apache.org/jira/browse/CALCITE-4737 < >> > > > >>>>>>>>>> https://issues.apache.org/jira/browse/CALCITE-4737> >> (Thomas >> > > > >>>>> Rebele) >> > > > >>>>>>>>>> * https://issues.apache.org/jira/browse/CALCITE-4860 < >> > > > >>>>>>>>>> https://issues.apache.org/jira/browse/CALCITE-4860> (Zhe >> > Hu / >> > > > >>>>> Duan >> > > > >>>>>>>>>> Xiong) >> > > > >>>>>>>>>> * https://issues.apache.org/jira/browse/CALCITE-4907 < >> > > > >>>>>>>>>> https://issues.apache.org/jira/browse/CALCITE-4907> >> > > > >>> (Francesco >> > > > >>>>>> Gini) >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> What’s the status on those? >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> Julian >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> [1] https://github.com/apache/calcite/pull/2622 < >> > > > >>>>>>>>>> https://github.com/apache/calcite/pull/2622> >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> PS It feels churlish to bring this up, but in >> time-honored >> > > > >>>>> tradition >> > > > >>>>>>>>>> the >> > > > >>>>>>>>>> email subject has been ‘[DISCUSS] Towards Calcite x.y.z’. >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> On Dec 14, 2021, at 10:37 AM, Rui Wang < >> > amaliu...@apache.org> >> > > > >>>>>>>>>> wrote: >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> Hi community, >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> To prepare for Calcite 1.29.0 release, I will start to >> check >> > > > >>> the >> > > > >>>>>>>>>> JIRA >> > > > >>>>>>>>>> list >> > > > >>>>>>>>>> [1] which marks its fix version as 1.29.0 (9 JIRA as of >> now >> > > > >>>>> remains >> > > > >>>>>>>>>> open/in >> > > > >>>>>>>>>> progress) and also the pending PRs which looks promising >> to >> > be >> > > > >>>>>>>>>> merged. >> > > > >>>>>>>>>> Please help resolve/review/merge JIRA/PRs if you want >> some >> > > > >>> fixes >> > > > >>>>> to >> > > > >>>>>>>>>> be >> > > > >>>>>>>>>> released. >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> My current goal is to start freezing the main branch of >> > > > >>> Calcite >> > > > >>>> by >> > > > >>>>>>>>>> the >> > > > >>>>>>>>>> end >> > > > >>>>>>>>>> of this week. >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> Please let me know if you have any questions. >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> [1]: >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> >> > > > >>>>>>>> >> > > > >>>>>>> >> > > > >>>>>> >> > > > >>>>> >> > > > >>>> >> > > > >>> >> > > > >> > > >> > >> https://issues.apache.org/jira/browse/CALCITE-4941?jql=project%20%3D%20CALCITE%20AND%20status%20in%20(Open%2C%20%22In%20Progress%22)%20AND%20fixVersion%20%3D%201.29.0 >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> -Rui >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> >> > > > >>>>>>>>>> -- >> > > > >>>>>>>>>> Francesco Gini >> > > > >>>>>>>>>> >> > > > >>>>>>>> >> > > > >>>>>>>> >> > > > >>>>>>> >> > > > >>>>>> >> > > > >>>>> >> > > > >>>> >> > > > >>> >> > > > > >> > > > >> > > > >> > > >> > >> >