+1
Tilman
Am 09.08.2026 um 13:40 schrieb Andreas Lehmkühler via dev:
Hi,
find attached a quick draft of the board report we're expected to
submit this month. It's based upon the report wizard template which
can be found at [1]
Any comments or additions are appreciated ...
[1] https://reporter.apache.org/wizard/?pdfbox
<draft>
## Description:
The mission of PDFBox is the creation and maintenance of software
related to
Java library for working with PDF documents
## Project Status:
Current project status: Ongoing with moderate activity
Issues for the board: none
## Membership Data:
Apache PDFBox was founded 2009-10-21 (17 years ago)
There are currently 21 committers and 21 PMC members in this project.
The Committer-to-PMC ratio is 1:1.
Community changes, past quarter:
- No new PMC members. Last addition was Matthäus Mayer on 2017-10-16.
- No new committers. Last addition was Joerg O. Henne on 2017-10-09.
## Project Activity:
Recent releases:
2.0.37 was released on 2026-07-15.
3.0.8 was released on 2026-07-11.
3.0.5 JBIG2 was released on 2026-05-20.
## Community Health:
- there is a steady stream of contributions, bug reports and questions
on the
mailing lists
- 3.0.5 of the JBIG2 plugin was released. We increased our decoder
compatibility with the serenity tests up to 100%, see
https://s.apache.org/jbig2_serenity_test
- 3.0.8 and 2.0.37 were released. The most important change is to no
longer
provide binaries for our examples subproject. We did so
accidentically at
least via maven. Some users are using them in production and complained
about (security) issues and expected some soon bugfix release. Those
examples were never meant to be production ready. They are examples
on how
to use pdfbox, nothing more, nothing less.
- we defined a security model for PDFBox to support anybody who tries to
analyze our code using some sort of AI or something similar
- we received some security reports through security@apache and already
benefited from our security model as our friends from security are
using
some AI to triage the reports before they rich us. The results are
looking
promising
- most of the reports don't meet our requirements for a security issue
and are
already handled and/or fixed
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]