[VOTE] Release Commons Collections 4.1 Based on RC2 (24h vote)

classic Classic list List threaded Threaded
8 messages Options
Reply | Threaded
Open this post in threaded view
|

[VOTE] Release Commons Collections 4.1 Based on RC2 (24h vote)

Thomas Neidhart
Hi all,

we have accumulated enough changes since the last 4.0 release as well as
we need to provide a fix for the known remote code exploit via java
de-serialization. Therefore, I would like to start a vote to release
Commons Collections 4.1 based on RC2.

Note:

 * The fix for the security related issue results in Clirr errors as
   unsafe classes in the functor package do not implement the
   Serializable interface anymore. This is mentioned in the release
   notes.

 * There are 2 test failures with the IBM 6 JDK. The same failures were
   reported for the 4.0 release and are related to a buggy Map
   implementation in this JDK

 * Commons Collections 4.X does not successfully compile with JDK 9 EA
   This will be tackled in a later release.

Changes since RC1:

 * fixed compilation problems of test classes with some Java 8 compilers
 * fixed some javadoc in IterableUtils and MultiValuedMap
 * added travis configuration (only in the repository, not part of the
   release) to help a RM by building with different jdks

Collections 4.1 RC2 is available for review here:
    https://dist.apache.org/repos/dist/dev/commons/collections/
    (svn revision 11307)

Maven artifacts are here:

https://repository.apache.org/content/repositories/orgapachecommons-1129/org/apache/commons/commons-collections4/4.1/

Details of changes since 4.0 are in the release notes:

https://dist.apache.org/repos/dist/dev/commons/collections/RELEASE-NOTES.txt

http://people.apache.org/builds/commons/collections/4.1/RC2/changes-report.html

The tag is here:

https://svn.apache.org/repos/asf/commons/proper/collections/tags/COLLECTIONS_4_1_RC2
    (svn revision 1716550)

Site:
    http://people.apache.org/builds/commons/collections/4.1/RC2/

Clirr Report (compared to 4.0):

http://people.apache.org/builds/commons/collections/4.1/RC2/clirr-report.html

RAT Report:

http://people.apache.org/builds/commons/collections/4.1/RC2/rat-report.html

KEYS:
    https://www.apache.org/dist/commons/KEYS

Please review the release candidate and vote.

This vote will close no sooner than 24 hours from now, i.e. after 2400
GMT 26-November 2015

  [ ] +1 Release these artifacts
  [ ] +0 OK, but...
  [ ] -0 OK, but really should fix...
  [ ] -1 I oppose this release because...

Thanks,

Thomas

---------------------------------------------------------------------
To unsubscribe, e-mail: [hidden email]
For additional commands, e-mail: [hidden email]

Reply | Threaded
Open this post in threaded view
|

Re: [VOTE] Release Commons Collections 4.1 Based on RC2 (24h vote)

Luc Maisonobe-2
Le 25/11/2015 23:20, Thomas Neidhart a écrit :

> Hi all,
>
> we have accumulated enough changes since the last 4.0 release as well as
> we need to provide a fix for the known remote code exploit via java
> de-serialization. Therefore, I would like to start a vote to release
> Commons Collections 4.1 based on RC2.
>
> Note:
>
>  * The fix for the security related issue results in Clirr errors as
>    unsafe classes in the functor package do not implement the
>    Serializable interface anymore. This is mentioned in the release
>    notes.
>
>  * There are 2 test failures with the IBM 6 JDK. The same failures were
>    reported for the 4.0 release and are related to a buggy Map
>    implementation in this JDK
>
>  * Commons Collections 4.X does not successfully compile with JDK 9 EA
>    This will be tackled in a later release.
>
> Changes since RC1:
>
>  * fixed compilation problems of test classes with some Java 8 compilers
>  * fixed some javadoc in IterableUtils and MultiValuedMap
>  * added travis configuration (only in the repository, not part of the
>    release) to help a RM by building with different jdks
>
> Collections 4.1 RC2 is available for review here:
>     https://dist.apache.org/repos/dist/dev/commons/collections/
>     (svn revision 11307)
>
> Maven artifacts are here:
>
> https://repository.apache.org/content/repositories/orgapachecommons-1129/org/apache/commons/commons-collections4/4.1/
>
> Details of changes since 4.0 are in the release notes:
>
> https://dist.apache.org/repos/dist/dev/commons/collections/RELEASE-NOTES.txt
>
> http://people.apache.org/builds/commons/collections/4.1/RC2/changes-report.html
>
> The tag is here:
>
> https://svn.apache.org/repos/asf/commons/proper/collections/tags/COLLECTIONS_4_1_RC2
>     (svn revision 1716550)
>
> Site:
>     http://people.apache.org/builds/commons/collections/4.1/RC2/
>
> Clirr Report (compared to 4.0):
>
> http://people.apache.org/builds/commons/collections/4.1/RC2/clirr-report.html
>
> RAT Report:
>
> http://people.apache.org/builds/commons/collections/4.1/RC2/rat-report.html
>
> KEYS:
>     https://www.apache.org/dist/commons/KEYS
>
> Please review the release candidate and vote.
>
> This vote will close no sooner than 24 hours from now, i.e. after 2400
> GMT 26-November 2015
>

>   [X] +1 Release these artifacts

Luc

>
> Thanks,
>
> Thomas
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [hidden email]
> For additional commands, e-mail: [hidden email]
>
>


---------------------------------------------------------------------
To unsubscribe, e-mail: [hidden email]
For additional commands, e-mail: [hidden email]

Reply | Threaded
Open this post in threaded view
|

Re: [VOTE] Release Commons Collections 4.1 Based on RC2 (24h vote)

Jörg Schaible
In reply to this post by Thomas Neidhart
Thomas Neidhart wrote:

> Hi all,
>
> we have accumulated enough changes since the last 4.0 release as well as
> we need to provide a fix for the known remote code exploit via java
> de-serialization. Therefore, I would like to start a vote to release
> Commons Collections 4.1 based on RC2.
>
> Note:
>
>  * The fix for the security related issue results in Clirr errors as
>    unsafe classes in the functor package do not implement the
>    Serializable interface anymore. This is mentioned in the release
>    notes.
>
>  * There are 2 test failures with the IBM 6 JDK. The same failures were
>    reported for the 4.0 release and are related to a buggy Map
>    implementation in this JDK
>
>  * Commons Collections 4.X does not successfully compile with JDK 9 EA
>    This will be tackled in a later release.
>
> Changes since RC1:
>
>  * fixed compilation problems of test classes with some Java 8 compilers
>  * fixed some javadoc in IterableUtils and MultiValuedMap
>  * added travis configuration (only in the repository, not part of the
>    release) to help a RM by building with different jdks
>
> Collections 4.1 RC2 is available for review here:
>     https://dist.apache.org/repos/dist/dev/commons/collections/
>     (svn revision 11307)
>
> Maven artifacts are here:
>
>
https://repository.apache.org/content/repositories/orgapachecommons-1129/org/apache/commons/commons-collections4/4.1/https://svn.apache.org/repos/asf/commons/proper/collections/tags/COLLECTIONS_4_1_RC2

>     (svn revision 1716550)
>
> Site:
>     http://people.apache.org/builds/commons/collections/4.1/RC2/
>
> Clirr Report (compared to 4.0):
>
> http://people.apache.org/builds/commons/collections/4.1/RC2/clirr-report.html
>
> RAT Report:
>
> http://people.apache.org/builds/commons/collections/4.1/RC2/rat-report.html
>
> KEYS:
>     https://www.apache.org/dist/commons/KEYS
>
> Please review the release candidate and vote.
>
> This vote will close no sooner than 24 hours from now, i.e. after 2400
> GMT 26-November 2015
>
>   [ ] +1 Release these artifacts
>   [ ] +0 OK, but...
>   [ ] -0 OK, but really should fix...
>   [ ] -1 I oppose this release because...

+1

Cheers,
Jörg


---------------------------------------------------------------------
To unsubscribe, e-mail: [hidden email]
For additional commands, e-mail: [hidden email]

Reply | Threaded
Open this post in threaded view
|

Re: [VOTE] Release Commons Collections 4.1 Based on RC2 (24h vote)

Oliver Heger-3
In reply to this post by Thomas Neidhart
Hi Thomas,

+1

Many thanks
Oliver

Am 25.11.2015 um 23:20 schrieb Thomas Neidhart:

> Hi all,
>
> we have accumulated enough changes since the last 4.0 release as well as
> we need to provide a fix for the known remote code exploit via java
> de-serialization. Therefore, I would like to start a vote to release
> Commons Collections 4.1 based on RC2.
>
> Note:
>
>  * The fix for the security related issue results in Clirr errors as
>    unsafe classes in the functor package do not implement the
>    Serializable interface anymore. This is mentioned in the release
>    notes.
>
>  * There are 2 test failures with the IBM 6 JDK. The same failures were
>    reported for the 4.0 release and are related to a buggy Map
>    implementation in this JDK
>
>  * Commons Collections 4.X does not successfully compile with JDK 9 EA
>    This will be tackled in a later release.
>
> Changes since RC1:
>
>  * fixed compilation problems of test classes with some Java 8 compilers
>  * fixed some javadoc in IterableUtils and MultiValuedMap
>  * added travis configuration (only in the repository, not part of the
>    release) to help a RM by building with different jdks
>
> Collections 4.1 RC2 is available for review here:
>     https://dist.apache.org/repos/dist/dev/commons/collections/
>     (svn revision 11307)
>
> Maven artifacts are here:
>
> https://repository.apache.org/content/repositories/orgapachecommons-1129/org/apache/commons/commons-collections4/4.1/
>
> Details of changes since 4.0 are in the release notes:
>
> https://dist.apache.org/repos/dist/dev/commons/collections/RELEASE-NOTES.txt
>
> http://people.apache.org/builds/commons/collections/4.1/RC2/changes-report.html
>
> The tag is here:
>
> https://svn.apache.org/repos/asf/commons/proper/collections/tags/COLLECTIONS_4_1_RC2
>     (svn revision 1716550)
>
> Site:
>     http://people.apache.org/builds/commons/collections/4.1/RC2/
>
> Clirr Report (compared to 4.0):
>
> http://people.apache.org/builds/commons/collections/4.1/RC2/clirr-report.html
>
> RAT Report:
>
> http://people.apache.org/builds/commons/collections/4.1/RC2/rat-report.html
>
> KEYS:
>     https://www.apache.org/dist/commons/KEYS
>
> Please review the release candidate and vote.
>
> This vote will close no sooner than 24 hours from now, i.e. after 2400
> GMT 26-November 2015
>
>   [ ] +1 Release these artifacts
>   [ ] +0 OK, but...
>   [ ] -0 OK, but really should fix...
>   [ ] -1 I oppose this release because...
>
> Thanks,
>
> Thomas
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [hidden email]
> For additional commands, e-mail: [hidden email]
>

---------------------------------------------------------------------
To unsubscribe, e-mail: [hidden email]
For additional commands, e-mail: [hidden email]

Reply | Threaded
Open this post in threaded view
|

Re: [VOTE] Release Commons Collections 4.1 Based on RC2 (24h vote)

Phil Steitz
In reply to this post by Thomas Neidhart
Sigs, hashes, release contents look good.
Ant, Maven builds clean on
  OSX: 1.7.0_71, 1.8.0_45
  Ubuntu: 1.6.0_43
Tests run clean against binary jar

+1

Thanks, Thomas!

Phil


On 11/25/15 3:20 PM, Thomas Neidhart wrote:

> Hi all,
>
> we have accumulated enough changes since the last 4.0 release as well as
> we need to provide a fix for the known remote code exploit via java
> de-serialization. Therefore, I would like to start a vote to release
> Commons Collections 4.1 based on RC2.
>
> Note:
>
>  * The fix for the security related issue results in Clirr errors as
>    unsafe classes in the functor package do not implement the
>    Serializable interface anymore. This is mentioned in the release
>    notes.
>
>  * There are 2 test failures with the IBM 6 JDK. The same failures were
>    reported for the 4.0 release and are related to a buggy Map
>    implementation in this JDK
>
>  * Commons Collections 4.X does not successfully compile with JDK 9 EA
>    This will be tackled in a later release.
>
> Changes since RC1:
>
>  * fixed compilation problems of test classes with some Java 8 compilers
>  * fixed some javadoc in IterableUtils and MultiValuedMap
>  * added travis configuration (only in the repository, not part of the
>    release) to help a RM by building with different jdks
>
> Collections 4.1 RC2 is available for review here:
>     https://dist.apache.org/repos/dist/dev/commons/collections/
>     (svn revision 11307)
>
> Maven artifacts are here:
>
> https://repository.apache.org/content/repositories/orgapachecommons-1129/org/apache/commons/commons-collections4/4.1/
>
> Details of changes since 4.0 are in the release notes:
>
> https://dist.apache.org/repos/dist/dev/commons/collections/RELEASE-NOTES.txt
>
> http://people.apache.org/builds/commons/collections/4.1/RC2/changes-report.html
>
> The tag is here:
>
> https://svn.apache.org/repos/asf/commons/proper/collections/tags/COLLECTIONS_4_1_RC2
>     (svn revision 1716550)
>
> Site:
>     http://people.apache.org/builds/commons/collections/4.1/RC2/
>
> Clirr Report (compared to 4.0):
>
> http://people.apache.org/builds/commons/collections/4.1/RC2/clirr-report.html
>
> RAT Report:
>
> http://people.apache.org/builds/commons/collections/4.1/RC2/rat-report.html
>
> KEYS:
>     https://www.apache.org/dist/commons/KEYS
>
> Please review the release candidate and vote.
>
> This vote will close no sooner than 24 hours from now, i.e. after 2400
> GMT 26-November 2015
>
>   [ ] +1 Release these artifacts
>   [ ] +0 OK, but...
>   [ ] -0 OK, but really should fix...
>   [ ] -1 I oppose this release because...
>
> Thanks,
>
> Thomas
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [hidden email]
> For additional commands, e-mail: [hidden email]
>
>



---------------------------------------------------------------------
To unsubscribe, e-mail: [hidden email]
For additional commands, e-mail: [hidden email]

Reply | Threaded
Open this post in threaded view
|

Re: [VOTE] Release Commons Collections 4.1 Based on RC2 (24h vote)

garydgregory
In reply to this post by Thomas Neidhart
Builds like a champ on Java 7 but fails on 8. Site looks good.

+1,
Gary





On Wed, Nov 25, 2015 at 2:20 PM, Thomas Neidhart <[hidden email]>
wrote:

> Hi all,
>
> we have accumulated enough changes since the last 4.0 release as well as
> we need to provide a fix for the known remote code exploit via java
> de-serialization. Therefore, I would like to start a vote to release
> Commons Collections 4.1 based on RC2.
>
> Note:
>
>  * The fix for the security related issue results in Clirr errors as
>    unsafe classes in the functor package do not implement the
>    Serializable interface anymore. This is mentioned in the release
>    notes.
>
>  * There are 2 test failures with the IBM 6 JDK. The same failures were
>    reported for the 4.0 release and are related to a buggy Map
>    implementation in this JDK
>
>  * Commons Collections 4.X does not successfully compile with JDK 9 EA
>    This will be tackled in a later release.
>
> Changes since RC1:
>
>  * fixed compilation problems of test classes with some Java 8 compilers
>  * fixed some javadoc in IterableUtils and MultiValuedMap
>  * added travis configuration (only in the repository, not part of the
>    release) to help a RM by building with different jdks
>
> Collections 4.1 RC2 is available for review here:
>     https://dist.apache.org/repos/dist/dev/commons/collections/
>     (svn revision 11307)
>
> Maven artifacts are here:
>
>
> https://repository.apache.org/content/repositories/orgapachecommons-1129/org/apache/commons/commons-collections4/4.1/
>
> Details of changes since 4.0 are in the release notes:
>
>
> https://dist.apache.org/repos/dist/dev/commons/collections/RELEASE-NOTES.txt
>
>
> http://people.apache.org/builds/commons/collections/4.1/RC2/changes-report.html
>
> The tag is here:
>
>
> https://svn.apache.org/repos/asf/commons/proper/collections/tags/COLLECTIONS_4_1_RC2
>     (svn revision 1716550)
>
> Site:
>     http://people.apache.org/builds/commons/collections/4.1/RC2/
>
> Clirr Report (compared to 4.0):
>
>
> http://people.apache.org/builds/commons/collections/4.1/RC2/clirr-report.html
>
> RAT Report:
>
> http://people.apache.org/builds/commons/collections/4.1/RC2/rat-report.html
>
> KEYS:
>     https://www.apache.org/dist/commons/KEYS
>
> Please review the release candidate and vote.
>
> This vote will close no sooner than 24 hours from now, i.e. after 2400
> GMT 26-November 2015
>
>   [ ] +1 Release these artifacts
>   [ ] +0 OK, but...
>   [ ] -0 OK, but really should fix...
>   [ ] -1 I oppose this release because...
>
> Thanks,
>
> Thomas
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [hidden email]
> For additional commands, e-mail: [hidden email]
>
>


--
E-Mail: [hidden email] | [hidden email]
Java Persistence with Hibernate, Second Edition
<http://www.manning.com/bauer3/>
JUnit in Action, Second Edition <http://www.manning.com/tahchiev/>
Spring Batch in Action <http://www.manning.com/templier/>
Blog: http://garygregory.wordpress.com
Home: http://garygregory.com/
Tweet! http://twitter.com/GaryGregory
Reply | Threaded
Open this post in threaded view
|

[VOTE][RESULT] Release Commons Collections 4.1 Based on RC2 (24h vote)

Thomas Neidhart
In reply to this post by Thomas Neidhart
Voting was as follows:

+1 (binding)

Luc Maisonobe
Joerg Schaible
Oliver Heger
Phil Steitz
Gary Gregory
Thomas Neidhart

There were no other votes.

The vote therefore passes.

Thanks to all who voted.

Thomas

---------------------------------------------------------------------
To unsubscribe, e-mail: [hidden email]
For additional commands, e-mail: [hidden email]

Reply | Threaded
Open this post in threaded view
|

Re: [VOTE] Release Commons Collections 4.1 Based on RC2 (24h vote)

Thomas Vandahl
In reply to this post by Thomas Neidhart
On 25.11.15 23:20, Thomas Neidhart wrote:
>   [X] +1 Release these artifacts

Bye, Thomas.


---------------------------------------------------------------------
To unsubscribe, e-mail: [hidden email]
For additional commands, e-mail: [hidden email]