Re: 2.1.2 maintenance release?

2017-09-08 Thread Sean Owen
Let's look at the standard ASF guidance, which actually surprised me when I first read it: https://www.apache.org/foundation/voting.html VOTES ON PACKAGE RELEASES Votes on whether a package is ready to be released use majority approval -- i.e. at least three PMC members must vote affirmatively fo

CVE-2017-12612 Unsafe deserialization in Apache Spark launcher API

2017-09-08 Thread Sean Owen
Severity: Medium Vendor: The Apache Software Foundation Versions Affected: Versions of Apache Spark from 1.6.0 until 2.1.1 Description: In Apache Spark 1.6.0 until 2.1.1, the launcher API performs unsafe deserialization of data received by its socket. This makes applications launched programmat

Re: 2.1.2 maintenance release?

2017-09-08 Thread Felix Cheung
+1 on both 2.1.2 and 2.2.1 And would try to help and/or wrangle the release if needed. (Note: trying to backport a few changes to branch-2.1 right now) From: Sean Owen Sent: Friday, September 8, 2017 12:05:28 AM To: Holden Karau; dev Subject: Re: 2.1.2 maintenan

Re: 2.1.2 maintenance release?

2017-09-08 Thread Ryan Blue
There's no problem that I'm aware of with a non-PMC member volunteering to be release manager. I was RM for a couple Avro releases without being on the PMC, and this is done regularly in the incubator where IPMC members have binding votes, but someone in the incubating community is the RM. We want

Re: 2.1.2 maintenance release?

2017-09-08 Thread Reynold Xin
+1 as well. We should make a few maintenance releases. On Fri, Sep 8, 2017 at 6:46 PM Felix Cheung wrote: > +1 on both 2.1.2 and 2.2.1 > > And would try to help and/or wrangle the release if needed. > > (Note: trying to backport a few changes to branch-2.1 right now) > >