| --- | 
 | layout: post | 
 | status: PUBLISHED | 
 | published: true | 
 | title: 'The Apache News Round-up: week ending 9 November 2018' | 
 | id: daeca55a-d0da-4bbe-bc8a-4a9963d151be | 
 | date: '2018-11-09 15:24:21 -0500' | 
 | categories: foundation | 
 | tags: | 
 | - round-up | 
 | - community | 
 | - initiatives | 
 | - software | 
 | - weekly | 
 | - summary | 
 | - projects | 
 | - apache | 
 | - foundation | 
 | - news | 
 | permalink: foundation/entry/the-apache-news-round-up96 | 
 | --- | 
 | <p>Happy Friday to all! Let's review what the Apache community has been up to this week:</p> | 
 | <p>Success at Apache –a monthly blog series that focuses on the processes behind why the ASF "just works".<br /> - Success at Apache: Wearing Small Hats by Rich Bowen <a href="https://s.apache.org/TGuO">https://s.apache.org/TGuO</a></p> | 
 | <p>ASF Board –management and oversight of the business affairs of the corporation in accordance with the Foundation's bylaws.<br /> - Next Board Meeting: 21 November. Board calendar and minutes <a href="http://apache.org/foundation/board/calendar.html">http://apache.org/foundation/board/calendar.html</a></p> | 
 | <div> | 
 | <p>ApacheCon™ –the ASF's official global conference series, now in its 20th year.<br /> - REGISTER for Apache Roadshow DC and free Open Source Job Fair <a href="http://www.apachecon.com/usroadshow18/">http://www.apachecon.com/usroadshow18/</a></p> | 
 | <p>ASF Infrastructure –our distributed team on three continents keeps the ASF's infrastructure running around the clock.<br /> - 7M+ weekly checks yield cracking performance at 98.68% uptime. <a href="http://status.apache.org/">http://status.apache.org/</a></p> | 
 | <p>Apache Code Snapshot –this week, 514 Apache contributors changed 1,106,696 lines of code over 3,154 commits. Top 5 contributors, in order, are: Gary Gregory, Julian Reschke, Andrea Cosentino, Qian Zhang, and Ash Berlin-Taylor.</p> | 
 | <p>Apache Hive™ –Big Data warehouse software that facilitates querying and managing large datasets residing in distributed storage.<br /> - Apache Hive 2.3.4 released <a href="https://hive.apache.org/">https://hive.apache.org/</a><br /> - [SECURITY] CVE-2018-1314: Hive explain query not being authorized <a href="http://mail-archives.apache.org/mod_mbox/www-announce/201811.mbox/%3CCABDpyChoSC%2BO_whkL_7Zh4ZMiXf7qmWpKoa-hep0dS6MTnJYJA%40mail.gmail.com%3E">http://mail-archives.apache.org/mod_mbox/www-announce/201811.mbox/%3CCABDpyChoSC%2BO_whkL_7Zh4ZMiXf7qmWpKoa-hep0dS6MTnJYJA%40mail.gmail.com%3E</a><br /> - [SECURITY] CVE-2018-11777: Blocking local resource access in HiveServer2 <a href="http://mail-archives.apache.org/mod_mbox/www-announce/201811.mbox/%3CCABDpyCjx%2BGpPvEW1mreZPnqCmqBYmAVk3s5NUx4ZGnQKcj7aGg%40mail.gmail.com%3E">http://mail-archives.apache.org/mod_mbox/www-announce/201811.mbox/%3CCABDpyCjx%2BGpPvEW1mreZPnqCmqBYmAVk3s5NUx4ZGnQKcj7aGg%40mail.gmail.com%3E</a> </p> | 
 | <p>Apache Jackrabbit™ –a fully compliant implementation of the Content Repository for Java(TM) Technology API, version 2.0 (JCR 2.0) as specified in the Java Specification Request 283 (JSR 283).<br /> - Apache Jackrabbit 2.12.10 and Jackrabbit Oak 1.9.10 released <a href="http://jackrabbit.apache.org/">http://jackrabbit.apache.org/</a></p> | 
 | <p>Apache Kylin™ –an Open Source Distributed Analytics Engine designed to provide SQL interface and multi-dimensional analysis (OLAP) on Apache Hadoop, supporting extremely large datasets.<br /> - Apache Kylin 2.5.1 released <a href="https://kylin.apache.org/">https://kylin.apache.org/</a></p> | 
 | <p>Apache Struts™ –an elegant, extensible framework for creating enterprise-ready Java Web applications.<br /> - [SECURITY] Immediately upgrade commons-fileupload to version 1.3.1 when running Struts 2.3.36 <a href="http://mail-archives.apache.org/mod_mbox/www-announce/201811.mbox/%3CCAMopvkMgZiJ%2BZkT1HmkQt94q7-bzNWnZm0Td9vq589vz5YM%3DMw%40mail.gmail.com%3E">http://mail-archives.apache.org/mod_mbox/www-announce/201811.mbox/%3CCAMopvkMgZiJ%2BZkT1HmkQt94q7-bzNWnZm0Td9vq589vz5YM%3DMw%40mail.gmail.com%3E</a><br /> - [SECURITY] Immediately upgrade commons-fileupload to version 1.3.3 when running Struts 2.3.36 or prior <a href="http://mail-archives.apache.org/mod_mbox/www-announce/201811.mbox/%3CCAMopvkMo8WiP%3DfqVQuZ1Fyx%3D6CGz0Epzfe0gG5XAqP1wdJCoBQ%40mail.gmail.com%3E">http://mail-archives.apache.org/mod_mbox/www-announce/201811.mbox/%3CCAMopvkMo8WiP%3DfqVQuZ1Fyx%3D6CGz0Epzfe0gG5XAqP1wdJCoBQ%40mail.gmail.com%3E</a></p> | 
 | <p>Apache Syncope™ –an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology.<br /> - Apache Syncope 2.0.11 and 2.1.2 released <a href="http://syncope.apache.org/">http://syncope.apache.org/</a><br /> - [SECURITY] CVE-2018-17184 Apache Syncope <a href="http://mail-archives.apache.org/mod_mbox/www-announce/201811.mbox/%3Ccf9fdd28-aba5-f586-01c0-d37beb50008a%40apache.org%3E">http://mail-archives.apache.org/mod_mbox/www-announce/201811.mbox/%3Ccf9fdd28-aba5-f586-01c0-d37beb50008a%40apache.org%3E</a><br /> - [SECURITY] CVE-2018-17186 Apache Syncope <a href="http://mail-archives.apache.org/mod_mbox/www-announce/201811.mbox/%3Cb1bdfd0b-2151-cafd-d5c9-425de23311f4%40apache.org%3E">http://mail-archives.apache.org/mod_mbox/www-announce/201811.mbox/%3Cb1bdfd0b-2151-cafd-d5c9-425de23311f4%40apache.org%3E</a></p> | 
 | <p>Apache Tomcat™ –an Open Source software implementation of the Java Servlet, JavaServer Pages, Java Unified Expression Language, Java WebSocket and JASPIC technologies.<br /> - Apache Tomcat 8.5.35 and 9.0.13 released <a href="http://tomcat.apache.org/">http://tomcat.apache.org/</a></p> | 
 | <p><strong>Did You Know?</strong></p> | 
 | <div> | 
 | <p> - Did you know that the following Apache projects are celebrating anniversaries? Many happy returns to Apache Ant (16 years); Labs (12 years); HttpComponents (11 years); Attic, Buildr, CouchDB, and Qpid (10 years); Community Development (9 years); OODT and ZooKeeper (8 years); Kafka and Sycope (7 years); Ambari and Marmotta (5 years); BookKeeper, Drill, and MetaModel (4 years); Brooklyn, Groovy, Kylin, REEF (3 years); Geode (2 years); Guacamole, Impala, and Mnemonic (1 year)! <a href="https://projects.apache.org/committees.html?date">https://projects.apache.org/committees.html?date</a></p> | 
 | <p> - Did you know that Apache CouchDB is porting a test suite from JS to Elixir is seeking assistance from the Elixir community? <a href="http://couchdb.apache.org/">http://couchdb.apache.org/</a></p> | 
 | <p> - Did you know that Yelp runs millions of tests every day using Apache Mesos? <a href="http://mesos.apache.org/">http://mesos.apache.org/</a></p> | 
 | <p><strong><br />Apache Community Notices:</strong></p> | 
 | </p></div> | 
 | <p> - ASF Operations Summary: Q1 FY2019 <a href="https://s.apache.org/qiKn">https://s.apache.org/qiKn</a></p> | 
 | <p> - ASF Annual Report for FY2018 <a href="https://s.apache.org/FY2018AnnualReport">https://s.apache.org/FY2018AnnualReport</a></p> | 
 | <p> - The Apache Software Foundation 2018 Vision Statement <a href="https://s.apache.org/zqC3">https://s.apache.org/zqC3</a></p> | 
 | <p> - Foundation Statement –Apache Is Open. <a href="https://s.apache.org/PIRA">https://s.apache.org/PIRA</a></p> | 
 | <div> | 
 | <p> - "Success at Apache" focuses on the processes behind why the ASF "just works". <a href="https://blogs.apache.org/foundation/category/SuccessAtApache">https://blogs.apache.org/foundation/category/SuccessAtApache</a></p> | 
 | </p></div> | 
 | <div> | 
 | <p> - Please follow/like/re-tweet the ASF on social media: @TheASF on Twitter and on LinkedIn at <a href="https://www.linkedin.com/company/the-apache-software-foundation">https://www.linkedin.com/company/the-apache-software-foundation</a></p> | 
 | <p> - Do friend and follow us on the Apache Community Facebook page <a href="https://www.facebook.com/ApacheSoftwareFoundation/">https://www.facebook.com/ApacheSoftwareFoundation/</a>and Twitter account <a href="https://twitter.com/ApacheCommunity">https://twitter.com/ApacheCommunity</a></p> | 
 | </p></div> | 
 | <div> | 
 | <p><a href="https://feathercast.apache.org/"></a></p> | 
 | </p></div> | 
 | <div> | 
 | <p> - The list of Apache project-related MeetUps can be found at <a href="http://events.apache.org/event/meetups.html">http://events.apache.org/event/meetups.html</a></p> | 
 | <p> - CFP now open for Flink Forward China 21-22 December 2018 in Beijing <a href="https://china-2018.flink-forward.org/call-for-presentations-submit-talk/">https://china-2018.flink-forward.org/call-for-presentations-submit-talk/</a></p> | 
 | </p></div> | 
 | <div> | 
 | <p> - The Apache Big Data community will be at DataWorks Summit 18-21 March 2019 in Barcelona and 20-23 May 2019 in Washington DC <a href="https://dataworkssummit.com/">https://dataworkssummit.com/</a></p> | 
 | <p> - Future dates for Spark + AI Summit 2019 announced: 23-25 April/San Francisco and 15-17 October/Amsterdam <font color="#bb0000"><a href="https://databricks.com/sparkaisummit/">https://databricks.com/sparkaisummit/</a></font></p> | 
 | <p> - Block your calendars for ApacheCon North America: taking place in September 2019; announcing dates and details soon. <a href="http://apachecon.com/">http://apachecon.com/</a></p> | 
 | <p> - Find out how you can participate with Apache community/projects/activities --opportunities open with Apache HTTP Server, Avro, ComDev (community development), Directory, Incubator, OODT, POI, Polygene, Syncope, Tika, Trafodion, and more! <a href="https://helpwanted.apache.org/">https://helpwanted.apache.org/</a></p> | 
 | </p></div> | 
 | <div> - Are your software solutions Powered by Apache? Download & use our "Powered By" logos <a href="http://www.apache.org/foundation/press/kit/#poweredby">http://www.apache.org/foundation/press/kit/#poweredby</a></div> | 
 | <div></div> | 
 | <div>= = =</div> | 
 | <div></div> | 
 | <div>For real-time updates, sign up for Apache-related news by sending mail to announce-subscribe@apache.org and follow @TheASF on Twitter. For a broader spectrum from the Apache community, <a href="https://twitter.com/PlanetApache">https://twitter.com/PlanetApache</a> provides an aggregate of Project activities as well as the personal blogs and tweets of select ASF Committers.</div> | 
 | </p></div> | 
 | <p># # # </p> |