Thanks for your feedback. I've submitted the report as is including a fix for the typo Maruan mentioned.

Andreas

Am 09.08.26 um 13:40 schrieb Andreas Lehmkühler via dev:
Hi,

find attached a quick draft of the board report we're expected to submit this month. It's based upon the report wizard template which can be found at [1]

Any comments or additions are appreciated ...

[1] https://reporter.apache.org/wizard/?pdfbox

<draft>
## Description:
The mission of PDFBox is the creation and maintenance of software related to
Java library for working with PDF documents

## Project Status:
Current project status: Ongoing with moderate activity
Issues for the board: none

## Membership Data:
Apache PDFBox was founded 2009-10-21 (17 years ago)
There are currently 21 committers and 21 PMC members in this project.
The Committer-to-PMC ratio is 1:1.

Community changes, past quarter:
- No new PMC members. Last addition was Matthäus Mayer on 2017-10-16.
- No new committers. Last addition was Joerg O. Henne on 2017-10-09.

## Project Activity:
Recent releases:

     2.0.37 was released on 2026-07-15.
     3.0.8 was released on 2026-07-11.
     3.0.5 JBIG2 was released on 2026-05-20.

## Community Health:
- there is a steady stream of contributions, bug reports and questions on the
   mailing lists
- 3.0.5 of the JBIG2 plugin was released. We  increased our decoder
   compatibility with the serenity tests up to 100%, see
   https://s.apache.org/jbig2_serenity_test
- 3.0.8 and 2.0.37 were released. The most important change is to no longer
  provide binaries for our examples subproject. We did so accidentically at
   least via maven. Some users are using them in production and complained
   about (security) issues and expected some soon bugfix release. Those
  examples were never meant to be production ready. They are examples on how
   to use pdfbox, nothing more, nothing less.
- we defined a security model for PDFBox to support anybody who tries to
   analyze our code using some sort of AI or something similar
- we received some security reports through security@apache and already
   benefited from our security model as our friends from security are using
  some AI to triage the reports before they rich us. The results are looking
   promising
- most of the reports don't meet our requirements for a security issue and are
   already handled and/or fixed

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]



---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to