there is a small typo "... before they rich us ..." -> "... before they reach us ..."
Other than that +1 Maruan Am Sonntag, dem 09.08.2026 um 13:40 +0200 schrieb Andreas Lehmkühler via dev: > Hi, > > find attached a quick draft of the board report we're expected to > submit > this month. It's based upon the report wizard template which can be > found at [1] > > Any comments or additions are appreciated ... > > [1] https://reporter.apache.org/wizard/?pdfbox > > <draft> > ## Description: > The mission of PDFBox is the creation and maintenance of software > related to > Java library for working with PDF documents > > ## Project Status: > Current project status: Ongoing with moderate activity > Issues for the board: none > > ## Membership Data: > Apache PDFBox was founded 2009-10-21 (17 years ago) > There are currently 21 committers and 21 PMC members in this project. > The Committer-to-PMC ratio is 1:1. > > Community changes, past quarter: > - No new PMC members. Last addition was Matthäus Mayer on 2017-10-16. > - No new committers. Last addition was Joerg O. Henne on 2017-10-09. > > ## Project Activity: > Recent releases: > > 2.0.37 was released on 2026-07-15. > 3.0.8 was released on 2026-07-11. > 3.0.5 JBIG2 was released on 2026-05-20. > > ## Community Health: > - there is a steady stream of contributions, bug reports and > questions > on the > mailing lists > - 3.0.5 of the JBIG2 plugin was released. We increased our decoder > compatibility with the serenity tests up to 100%, see > https://s.apache.org/jbig2_serenity_test > - 3.0.8 and 2.0.37 were released. The most important change is to no > longer > provide binaries for our examples subproject. We did so > accidentically at > least via maven. Some users are using them in production and > complained > about (security) issues and expected some soon bugfix release. > Those > examples were never meant to be production ready. They are > examples > on how > to use pdfbox, nothing more, nothing less. > - we defined a security model for PDFBox to support anybody who tries > to > analyze our code using some sort of AI or something similar > - we received some security reports through security@apache and > already > benefited from our security model as our friends from security are > using > some AI to triage the reports before they rich us. The results are > looking > promising > - most of the reports don't meet our requirements for a security > issue > and are > already handled and/or fixed > > --------------------------------------------------------------------- > To unsubscribe, e-mail: [email protected] > For additional commands, e-mail: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
