[VOTE] Release Apache Commons DBCP 2.10.0 based on RC1

2023-08-28 Thread Gary Gregory
We have fixed a few bugs and added some enhancements since Apache Commons DBCP 2.9.0 was released, so I would like to release Apache Commons DBCP 2.10.0. Apache Commons DBCP 2.10.0 RC1 is available for review here: https://dist.apache.org/repos/dist/dev/commons/dbcp/2.10.0-RC1 (svn revision 63

Re: [commons-crypto] OpenSSL 3.x, FIPS, digests, and HMAC

2023-08-28 Thread Alex Remily
Given Marcelo's response, I think it makes sense to retain support for 1.1.x, add support for 3.0.x using dynamic version discovery, and drop support for anything older than 1.1. This would align us with the openssl LTS versions. Looks like 3.1.x isn't FIPS validated. https://www.openssl.org/sou

Re: [VOTE] Release Apache Commons JCS 3.2 based on rc1

2023-08-28 Thread Gary Gregory
ping. On Sat, Aug 26, 2023 at 11:08 AM Gary Gregory wrote: > Is this vote this open? If not please, cancel it. > > There is nothing at > > https://repository.apache.org/content/repositories/orgapachecommons-orgapachecommons-1650/org/apache/commons/commons-jcs3/3.2/ > > Gary > > On Tue, Aug 22, 2

[security] finding known issues for commons projects

2023-08-28 Thread Mike Drob
Hello commons-dev! I found the very lovely https://commons.apache.org/security.html page and I very much appreciate the links out to individual project's security pages. However, it looks like a little under half (9/21) have security pages linked. Does this mean that the other 12 projects have