Hi Matthias, I agree it's indeed a blocker for 3.5.2 to address CVE in RocksDB. Please let me know when the test is completed.
Thank you. Luke On Sat, Oct 21, 2023 at 2:12 AM Matthias J. Sax <mj...@apache.org> wrote: > Thanks for the info Luke. > > We did backport all but one PR in the mean time. The missing PR is a > RocksDB version bump. We want to consider it for 3.5.2, because it > addresses a CVE. > > Cf https://github.com/apache/kafka/pull/14216 > > However, RocksDB versions bumps are a little bit more tricky, and we > would like to test this properly on 3.5 branch, what would take at least > one week; we could do the cherry-pick on Monday and start testing. > > Please let us know if such a delay for 3.5.2 is acceptable or not. > > Thanks. > > -Matthias > > > On 10/20/23 5:44 AM, Luke Chen wrote: > > Hi Ryan, > > > > OK, I've backported it to 3.5 branch. > > I'll be included in v3.5.2. > > > > Thanks. > > Luke > > > > On Fri, Oct 20, 2023 at 7:43 AM Ryan Leslie (BLP/ NEW YORK (REMOT) < > > rles...@bloomberg.net> wrote: > > > >> Hi Luke, > >> > >> Hope you are well. Can you please include > >> https://issues.apache.org/jira/browse/KAFKA-15106 in 3.5.2? > >> > >> Thanks, > >> > >> Ryan > >> > >> From: dev@kafka.apache.org At: 10/17/23 05:05:24 UTC-4:00 > >> To: dev@kafka.apache.org > >> Subject: Re: [DISCUSS] Apache Kafka 3.5.2 release > >> > >> Thanks Luke for volunteering for 3.5.2 release. > >> > >> On Tue, 17 Oct 2023 at 11:58, Josep Prat <josep.p...@aiven.io.invalid> > >> wrote: > >>> > >>> Hi Luke, > >>> > >>> Thanks for taking this one! > >>> > >>> Best, > >>> > >>> On Tue, Oct 17, 2023 at 8:12 AM Luke Chen <show...@gmail.com> wrote: > >>> > >>>> Hi all, > >>>> > >>>> I'd like to volunteer as release manager for the Apache Kafka 3.5.2, > to > >>>> have an important bug/vulnerability fix release for 3.5.1. > >>>> > >>>> If there are no objections, I'll start building a release plan in > >> thewiki > >>>> in the next couple of weeks. > >>>> > >>>> Thanks, > >>>> Luke > >>>> > >>> > >>> > >>> -- > >>> [image: Aiven] <https://www.aiven.io> > >>> > >>> *Josep Prat* > >>> Open Source Engineering Director, *Aiven* > >>> josep.p...@aiven.io | +491715557497 > >>> aiven.io <https://www.aiven.io> | <https://www.facebook.com/aivencloud > > > >>> <https://www.linkedin.com/company/aiven/> < > https://twitter.com/aiven_io> > >>> *Aiven Deutschland GmbH* > >>> Alexanderufer 3-7, 10117 Berlin > >>> Geschäftsführer: Oskari Saarenmaa & Hannu Valtonen > >>> Amtsgericht Charlottenburg, HRB 209739 B > >> > >> > >> > > >