-1 Looks like we need to merge and cherry-pick into 0.16.0 branch:
* https://github.com/apache/thrift/pull/2519 (the java dependency vulnerability fixes) * https://github.com/apache/thrift/pull/2520 (a follow up from the fix included in rc1, sorry about that) On Sun, Feb 6, 2022 at 8:08 PM Randy Abernethy <randy.aberne...@rx-m.com> wrote: > +1 > > On Fri, Feb 4, 2022 at 2:10 PM Jens Geyer <je...@apache.org> wrote: > > > All, > > > > I propose that we accept the following release candidate as the official > > Apache Thrift 0.16.0 release: > > > > > > > https://dist.apache.org/repos/dist/dev/thrift/0.16.0-rc1/thrift-0.16.0.tar.gz > > > > The release candidate was created from the release/0.16.0 branch and can > > be cloned using: > > > > git clone -b release/0.16.0 https://github.com/apache/thrift.git > > > > The release candidates GPG signature can be found at: > > > > > https://dist.apache.org/repos/dist/dev/thrift/0.16.0-rc1/thrift-0.16.0.tar.gz.asc > > > > The release candidates checksums are: > > md5: b57857fe9f32f4cdeb8368ed74b6f5d1 > > sha1: 750ef4d74f5a863bf1431fa1a64b346a1e2ff0d3 > > sha256: 036894dc05d439889f2a302db95af44f7e2aea64d6b17014b2c941df2798b1b3 > > > > > > A prebuilt statically-linked Windows compiler is available at: > > > https://dist.apache.org/repos/dist/dev/thrift/0.16.0-rc1/thrift-0.16.0.exe > > > > Prebuilt statically-linked Windows compiler GPG signature: > > > > > https://dist.apache.org/repos/dist/dev/thrift/0.16.0-rc1/thrift-0.16.0.exe.asc > > > > Prebuilt statically-linked Windows compiler checksums are: > > md5: 574fb28bcec48a27f3e911f3dab23b99 > > sha1: ee2692de1f38aa45d285709d177c92d490e9ac73 > > sha256: 18f055010bc67ed59b824d8fe41a67dc083177bb6ccd7787499123a04f33f870 > > > > > > The CHANGES list for this release is available at: > > https://github.com/apache/thrift/blob/0.16.0/CHANGES.md > > > > > > Please download, verify sig/sum, install and test the libraries and > > languages of your choice. > > > > This vote will close in 121 hours on 2022-02-10 00:00 UTC > > https://www.timeanddate.com/countdown/generic?iso=20220210T0000&p0=1440 > > > > [ ] +1 Release this as Apache Thrift 0.16.0 > > [ ] +0 > > [ ] -1 Do not release this as Apache Thrift 0.16.0 because... > > > > > > >