+1

Tilman

Am 09.08.2026 um 13:40 schrieb Andreas Lehmkühler via dev:
Hi,

find attached a quick draft of the board report we're expected to submit this month. It's based upon the report wizard template which can be found at [1]

Any comments or additions are appreciated ...

[1] https://reporter.apache.org/wizard/?pdfbox

<draft>
## Description:
The mission of PDFBox is the creation and maintenance of software related to
Java library for working with PDF documents

## Project Status:
Current project status: Ongoing with moderate activity
Issues for the board: none

## Membership Data:
Apache PDFBox was founded 2009-10-21 (17 years ago)
There are currently 21 committers and 21 PMC members in this project.
The Committer-to-PMC ratio is 1:1.

Community changes, past quarter:
- No new PMC members. Last addition was Matthäus Mayer on 2017-10-16.
- No new committers. Last addition was Joerg O. Henne on 2017-10-09.

## Project Activity:
Recent releases:

    2.0.37 was released on 2026-07-15.
    3.0.8 was released on 2026-07-11.
    3.0.5 JBIG2 was released on 2026-05-20.

## Community Health:
- there is a steady stream of contributions, bug reports and questions on the
  mailing lists
- 3.0.5 of the JBIG2 plugin was released. We  increased our decoder
  compatibility with the serenity tests up to 100%, see
  https://s.apache.org/jbig2_serenity_test
- 3.0.8 and 2.0.37 were released. The most important change is to no longer   provide binaries for our examples subproject. We did so accidentically at
  least via maven. Some users are using them in production and complained
  about (security) issues and expected some soon bugfix release. Those
  examples were never meant to be production ready. They are examples on how
  to use pdfbox, nothing more, nothing less.
- we defined a security model for PDFBox to support anybody who tries to
  analyze our code using some sort of AI or something similar
- we received some security reports through security@apache and already
  benefited from our security model as our friends from security are using   some AI to triage the reports before they rich us. The results are looking
  promising
- most of the reports don't meet our requirements for a security issue and are
  already handled and/or fixed

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]



---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to