Dear Apache Geode Developer Community,

As we move toward Apache Geode 2.0.0, I would like to propose that we begin 
nominating a Release Manager (RM) to lead this milestone.
This release is particularly significant: it will be our first major version 
since the inception of the 1.x line nearly a decade ago, marking a new baseline 
for users and integrators. The 2.0.0 release introduces foundational changes 
that modernize the platform, strengthen security, and align Geode with current 
enterprise standards.


Key Proposed Changes (https://issues.apache.org/jira/browse/GEODE-10467)

Runtime and Core Dependencies

  *
Upgrade Java runtime from 1.8 to 17 LTS or 21 LTS
  *
Upgrade Spring Framework to version 6 (or potentially 7)
  *
Upgrade Spring Security to version 6
  *
Migrate from Java EE to Jakarta EE 9
  *
Upgrade Gradle for Java 17/21 toolchain support

Supply Chain Security

  *
Implement automated Software Bill of Materials (SBOM) generation for improved 
dependency transparency and compliance

Security

  *
Remediate critical vulnerabilities in third-party dependencies and Geode itself
  *
Address numerous known vulnerabilities in legacy Java 8
  *
Resolve CVEs in Spring Framework and Spring Security
  *
Establish a zero-known-vulnerability baseline for current releases

CI & build platform modernization

  *
Java 17 and modern tool chain support
  *
Improved build performance
  *
Better dependency management
  *
Enhanced security features


Delivering these changes requires careful coordination and early planning. 
Nominating an RM as soon as possible will ensure:

  *
ASF-compliant release process is managed end-to-end (branching, RCs, voting, 
signing, docs)
  *
Infrastructure and permissions (Jira transitions, CI, website updates) are 
ready before RC work begins
  *
Cross-cutting changes (Java baseline, Jakarta migration, security hardening) 
are aligned across modules and documentation

This is a landmark release for Apache Geode, and early leadership will help us 
deliver it with confidence and quality.
Looking forward to the community’s engagement on this important step.


Best regards,

Jinwoo Hwang (he/him/his)



SAS® Research and Development

http://JinwooHwang.com<http://jinwoohwang.com/>


Reply via email to