Hi Shivji,
  The 2.7.4 has been already released and includes 2.17.0.

Regards
Jiwei Guo (Tboy)


On Tue, Dec 21, 2021 at 6:47 PM Shivji Kumar Jha <shiv4...@gmail.com> wrote:
>
> Hi Pulsar Team,
>
> 2.16.0 is prone to DDoS attacks [1].  Is it possible to move to 2.17.0 in
> pulsar 2.7.4 ?
>
> [1] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45105
>
> Regards,
> Shivji Kumar Jha
> http://www.shivjijha.com/
> +91 8884075512
>
>
> On Tue, 21 Dec 2021 at 02:46, Michael Marshall <mmarsh...@apache.org>
wrote:
>
> > Thank you Penghui, Technoboy, and BewareMyPower for picking up where I
> > left off to get the 2.7.4 release ready to go. You cherry-picked many
> > commits,
> > resolved many conflicts, and fixed a bunch of tests!
> >
> > Thanks,
> > Michael
> >
> >
> > On Thu, Dec 16, 2021 at 7:37 PM guo jiwei <techno...@apache.org> wrote:
> > >
> > > Hi,
> > > After we have fixed some issue like ZookeeperCache NPE, listing
namespace
> > > exception, and skip some flaky tests (verified locally), now the CI
have
> > > passed.
> > > Skipped flaky tests are tracked here:
> > > https://github.com/apache/pulsar/issues/13299
> > > Now we decide to vote for releasing 2.7.4.
> > >
> > > Regards
> > > Jiwei Guo (Tboy)
> > >
> > >
> > > On Tue, Dec 14, 2021 at 11:58 AM PengHui Li <peng...@apache.org>
wrote:
> > >
> > > > Thanks for the update, I will move it 2.7.5
> > > >
> > > > Thanks,
> > > > Penghui
> > > >
> > > > On Tue, Dec 14, 2021 at 9:47 AM Matteo Merli <matteo.me...@gmail.com
>
> > > > wrote:
> > > >
> > > > > Let's take https://github.com/apache/pulsar/pull/12484 out of the
> > > > > picture since it's failing the tests.
> > > > >
> > > > >
> > > > > --
> > > > > Matteo Merli
> > > > > <matteo.me...@gmail.com>
> > > > >
> > > > > On Sun, Dec 12, 2021 at 11:06 PM PengHui Li <peng...@apache.org>
> > wrote:
> > > > > >
> > > > > > Yes,
> > > > > >
> > > > > > https://github.com/apache/pulsar/pull/13215 has cherry-picked,
so
> > we
> > > > can
> > > > > > close it.
> > > > > > https://github.com/apache/pulsar/pull/12484 blocked by the test.
> > > > > >
> > > > > > Penghui
> > > > > >
> > > > > > On Mon, Dec 13, 2021 at 2:35 PM Dave Fisher <
wave4d...@comcast.net
> > >
> > > > > wrote:
> > > > > >
> > > > > > > I see 2 PRs still open at
> > > > > > >
> > > > >
> > > >
> >
https://github.com/apache/pulsar/pulls?q=is%3Aopen+is%3Apr+label%3Arelease%2F2.7.4
> > > > > > >
> > > > > > > Sent from my iPhone
> > > > > > >
> > > > > > > > On Dec 12, 2021, at 8:22 PM, guo jiwei <techno...@apache.org
>
> > > > wrote:
> > > > > > > >
> > > > > > > > I have pushed out some fixes in
> > > > > > > https://github.com/apache/pulsar/pull/13243
> > > > > > > > After the tests get passed, I will send out the RC-1 VOTE
for
> > 2.7.4
> > > > > > > >
> > > > > > > > Regards
> > > > > > > > Jiwei Guo (Tboy)
> > > > > > > >
> > > > > > > >
> > > > > > > >> On Sun, Dec 12, 2021 at 3:11 PM PengHui Li <
> > peng...@apache.org>
> > > > > wrote:
> > > > > > > >>
> > > > > > > >> Just put an update here. We have done the PR cherry-picking
> > > > > > > >>
> > > > > > > >> https://github.com/apache/pulsar/commits/branch-2.7
> > > > > > > >>
> > > > > > > >> And most of the integration tests are fixed due to the
docker
> > > > image
> > > > > > > issue
> > > > > > > >> or the testcontainer issue, now some integration tests get
> > passed,
> > > > > but
> > > > > > > some
> > > > > > > >> are not.
> > > > > > > >> And there are some failed tests, maybe a flaky test, we
need
> > to
> > > > > ensure
> > > > > > > it's
> > > > > > > >> not a regression.
> > > > > > > >>
> > > > > > > >> We are continuing on the test part.
> > > > > > > >>
> > > > > > > >> Penghui
> > > > > > > >>
> > > > > > > >>
> > > > > > > >>
> > > > > > > >>> On Sat, Dec 11, 2021 at 5:36 PM PengHui Li <
> > peng...@apache.org>
> > > > > wrote:
> > > > > > > >>>
> > > > > > > >>> Hi Michael,
> > > > > > > >>>
> > > > > > > >>> +1,
> > > > > > > >>>
> > > > > > > >>> Thanks for the great work.
> > > > > > > >>> We will continue on the PR cherry-picking and the release
> > process
> > > > > to
> > > > > > > make
> > > > > > > >>> sure the urgent release can be done ASAP.
> > > > > > > >>>
> > > > > > > >>> Penghui
> > > > > > > >>>
> > > > > > > >>> On Sat, Dec 11, 2021 at 3:42 PM Michael Marshall <
> > > > > mmarsh...@apache.org
> > > > > > > >
> > > > > > > >>> wrote:
> > > > > > > >>>
> > > > > > > >>>> Given the log4j CVE, we should work to release 2.7.4.
> > > > > > > >>>>
> > > > > > > >>>> I started preparing the release today by cherry-picking
> > merged
> > > > PRs
> > > > > > > >>>> that have the `release/2.7.4` label but have not yet been
> > > > > > > >>>> cherry-picked to `branch-2.7` [0]. There are still 37 PRs
> > that
> > > > > have
> > > > > > > >>>> not been cherry picked. I think it will take too long to
> > cherry
> > > > > pick
> > > > > > > >>>> all of these commits, as many have conflicts, and we
should
> > > > > prioritize
> > > > > > > >>>> releasing 2.7.4. The main commits that we should get
> > > > cherry-picked
> > > > > > > >>>> before creating the git tag are any labeled with
> > > > > `component/security`.
> > > > > > > >>>> There are only a few remaining commits to cherry pick.
> > Please
> > > > let
> > > > > me
> > > > > > > >>>> know if you think any other commits ought to be
> > cherry-picked.
> > > > > > > >>>>
> > > > > > > >>>> The earliest I'll be able to build the release is Monday.
> > If we
> > > > > need
> > > > > > > >>>> to start sooner, perhaps someone else will be available
to
> > > > manage
> > > > > this
> > > > > > > >>>> urgent release.
> > > > > > > >>>>
> > > > > > > >>>> Thanks,
> > > > > > > >>>> Michael
> > > > > > > >>>>
> > > > > > > >>>> [0] -
> > > > > > > >>>>
> > > > > > > >>
> > > > > > >
> > > > >
> > > >
> >
https://github.com/apache/pulsar/pulls?page=2&q=label%3Arelease%2F2.7.4+sort%3Acreated-asc+is%3Apr+-label%3Acherry-picked%2Fbranch-2.7
> > > > > > > >>>> [1] -
> > > > > > > >>>>
> > > > > > > >>
> > > > > > >
> > > > >
> > > >
> >
https://github.com/apache/pulsar/pulls?q=label%3Arelease%2F2.7.4+sort%3Acreated-asc+is%3Apr+-label%3Acherry-picked%2Fbranch-2.7+label%3Acomponent%2Fsecurity
> > > > > > > >>>>
> > > > > > > >>>>
> > > > > > > >>>> On Thu, Dec 9, 2021 at 4:03 PM Neng Lu <nl...@apache.org>
> > > > wrote:
> > > > > > > >>>>>
> > > > > > > >>>>> +1
> > > > > > > >>>>>
> > > > > > > >>>>> On 2021/12/09 15:29:55 Michael Marshall wrote:
> > > > > > > >>>>>> Hello Pulsar Community,
> > > > > > > >>>>>>
> > > > > > > >>>>>> I'd like to propose that we release 2.7.4. We have
merged
> > > > > several
> > > > > > > >>>>>> important fixes since we released 2.7.3 in August.
> > > > > > > >>>>>>
> > > > > > > >>>>>> I am happy to volunteer to be the release manager.
> > > > > > > >>>>>>
> > > > > > > >>>>>> Here [0] you can find the list of 36 commits
> > cherry-picked to
> > > > > > > >>>>>> branch-2.7 since 2.7.3 release. It looks like there are
> > more
> > > > PRs
> > > > > > > >>>>>> labeled with `release/2.7.4` than commits
cherry-picked,
> > so I
> > > > > will
> > > > > > > >>>>>> need to work on cherry-picking those before we can
create
> > the
> > > > > tag
> > > > > > > >> for
> > > > > > > >>>>>> the release [1].
> > > > > > > >>>>>>
> > > > > > > >>>>>> Also, I see 3 open PRs labeled with `release/2.7.4`.
I'll
> > > > > follow up
> > > > > > > >> on
> > > > > > > >>>>>> each of those PRs to see if they will be completed
soon.
> > > > > > > >>>>>>
> > > > > > > >>>>>> Thanks,
> > > > > > > >>>>>> Michael
> > > > > > > >>>>>>
> > > > > > > >>>>>> [0] -
> > > > > https://github.com/apache/pulsar/compare/v2.7.3...branch-2.7
> > > > > > > >>>>>> [1] -
> > > > > > > >>>>
> > > > > > > >>
> > > > > > >
> > > > >
> > > >
> >
https://github.com/apache/pulsar/pulls?q=is%3Aopen+is%3Apr+label%3Arelease%2F2.7.4
> > > > > > > >>>>>>
> > > > > > > >>>>
> > > > > > > >>>
> > > > > > > >>
> > > > > > >
> > > > >
> > > >
> >

Reply via email to