There was a recent report about vulnerabilities of some dependent
libraries: https://issues.apache.org/jira/browse/KAFKA-8952

I think we should fix this for 2.3.1.

Furthermore, we identified the root cause of
https://issues.apache.org/jira/browse/KAFKA-8649 -- it seems to be a
critical issue because it affects upgrading of Kafka Streams
applications. We plan to do a PR asap and hope we can include it in 2.3.1.


-Matthias

On 9/25/19 11:57 AM, David Arthur wrote:
> Thanks, Jason. I agree we should include this. I'll produce RC1 once
> this patch is available. 
> 
> -David
> 
> On Tue, Sep 24, 2019 at 6:02 PM Jason Gustafson <ja...@confluent.io
> <mailto:ja...@confluent.io>> wrote:
> 
>     Hi David,
> 
>     Thanks for running the release. I think we should consider getting
>     this bug
>     fixed: https://issues.apache.org/jira/browse/KAFKA-8896. The impact
>     of this
>     bug is that consumer groups cannot commit offsets or rebalance. The
>     patch
>     should be ready shortly.
> 
>     Thanks,
>     Jason
> 
> 
> 
>     On Fri, Sep 13, 2019 at 3:53 PM David Arthur <davidart...@apache.org
>     <mailto:davidart...@apache.org>> wrote:
> 
>     > Hello Kafka users, developers and client-developers,
>     >
>     >
>     > This is the first candidate for release of Apache Kafka 2.3.1 which
>     > includes many bug fixes for Apache Kafka 2.3.
>     >
>     >
>     > Release notes for the 2.3.1 release:
>     >
>     >
>     https://home.apache.org/~davidarthur/kafka-2.3.1-rc0/RELEASE_NOTES.html
>     >
>     >
>     > *** Please download, test and vote by Wednesday, September 18, 9am PT
>     >
>     >
>     > Kafka's KEYS file containing PGP keys we use to sign the release:
>     >
>     > https://kafka.apache.org/KEYS
>     >
>     >
>     > * Release artifacts to be voted upon (source and binary):
>     >
>     > https://home.apache.org/~davidarthur/kafka-2.3.1-rc0/
>     >
>     >
>     > * Maven artifacts to be voted upon:
>     >
>     > https://repository.apache.org/content/groups/staging/org/apache/kafka/
>     >
>     >
>     > * Javadoc:
>     >
>     > https://home.apache.org/~davidarthur/kafka-2.3.1-rc0/javadoc/
>     >
>     >
>     > * Tag to be voted upon (off 2.3 branch) is the 2.3.1 tag:
>     >
>     > https://github.com/apache/kafka/releases/tag/2.3.1-rc0
>     >
>     >
>     > * Documentation:
>     >
>     > https://kafka.apache.org/23/documentation.html
>     >
>     >
>     > * Protocol:
>     >
>     > https://kafka.apache.org/23/protocol.html
>     >
>     >
>     > * Successful Jenkins builds for the 2.3 branch:
>     >
>     > Unit/integration tests: https://builds.apache.org/job/kafka-2.3-jdk8/
>     >
>     > System tests:
>     > https://jenkins.confluent.io/job/system-test-kafka/job/2.3/119
>     >
>     >
>     >
>     > We have yet to get a successful unit/integration job run due to
>     some flaky
>     > failures. I will send out a follow-up email once we have a passing
>     build.
>     >
>     >
>     > Thanks!
>     >
>     > David
>     >
> 
> 
> 
> -- 
> David Arthur
> 
> -- 
> You received this message because you are subscribed to the Google
> Groups "kafka-clients" group.
> To unsubscribe from this group and stop receiving emails from it, send
> an email to kafka-clients+unsubscr...@googlegroups.com
> <mailto:kafka-clients+unsubscr...@googlegroups.com>.
> To view this discussion on the web visit
> https://groups.google.com/d/msgid/kafka-clients/CA%2B0Ze6q9tTVS4eYoZmaN2z4UB_vxyQ%2BhY_2Gisv%3DM2Pmn-hWpA%40mail.gmail.com
> <https://groups.google.com/d/msgid/kafka-clients/CA%2B0Ze6q9tTVS4eYoZmaN2z4UB_vxyQ%2BhY_2Gisv%3DM2Pmn-hWpA%40mail.gmail.com?utm_medium=email&utm_source=footer>.

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to