Index Links: 2026 - All years - Original
                    The Apache Software Foundation

                  Board of Directors Meeting Minutes

                           August 19, 2026


1. Call to order

    The meeting was scheduled for 21:00 UTC and began at 21:03 when
    a sufficient attendance to constitute a quorum was recognized by
    the chair.

            Other Time Zones: https://www.timeanddate.com/worldclock/fixedtime.html?iso=2026-08-19T21:00:00&msg=ASF+Board+Meeting

    The meeting was held via teleconference, hosted by the Secretary
    via Zoom.

    The #asfboard channel on the-asf.slack.com was used for backup.

2. Roll Call

    Directors Present:

        Zili Chen
        Shane Curcuru
        Christofer Dutz
        Emmanuel Lécharny
        Justin Mclean
        Christopher Schultz
        Greg Stein
        Sander Striker

    Directors Absent:

        Jean-Baptiste Onofré

    Executive Officers Present:

        Craig McClanahan
        Ruth Suehle
        Craig L Russell
        Daniel Ruggeri

    Executive Officers Absent:

        Matt Sicker

    Guests:

        Daniel Gruno
        Sally Khudairi
        Thomas Neidhart
        Andrew Wetmore
        Paul King
        Alin Jerpelea
        Jamie Goodyear
        Jeff Genender
        Brian Proffitt
        Daniel Sahlberg
        Rich Bowen
        Julien Le Dem
        Whitney P True
        Henri Yandell
        Melissa Logan
        Drew Foulks

3. Minutes from previous meetings

    Published minutes can be found at:

        https://www.apache.org/foundation/board/calendar.html

    A. The meeting of July 15, 2026

       See: board_minutes_2026_07_15.txt

       Tabled.

    B. The meeting of July 22, 2026

       See: board_minutes_2026_07_22.txt

       Approved by General Consent.

4. Executive Officer Reports

    A. Board Chair [Sander Striker]

       Triggered by last month's discussion on board committees, I worked
       with the VP Security and the security team on what the right structure for the
       Foundation's security function looks like. The resulting resolution is on
       today's agenda (7F).

       Work is underway to clear backlog on the agenda tool and land some
       long-standing improvements. The most visible one for directors is Action
       Without a Meeting: special orders that reach the agenda well ahead of a
       meeting are now surfaced automatically for early voting, and if the board is
       unanimous the action is taken without waiting, per Section 5.12 of the bylaws.

       My intent is to make our decision-making more asynchronous and to normalize
       written consent, so that uncontroversial matters don't sit for any longer than
       they need to.  I unsuccessfully tried to introduce this a number of years ago,
       which I attributed to the tooling we had for it at the time.  With current
       integration into the agenda tool, I have higher expectations.  Consider it an
       experiment, but I do expect directors make an effort to contribute to its
       success.

       Separately there are pending changes to publish categorized minutes to the
       main www.apache.org site, replacing what has been rendered through Whimsy for
       many years.  A welcome side effect is that going through them has refreshed my
       memory of some of our history.

       I remain keen to make progress on the reporting changes discussed in
       June 2024 (8C) and re-affirmed in September 2025 (8B).  I believe the tooling
       is now at a point where it can serve as a foundation for this change.

    B. President [Ruth Suehle]

       Congrats to Community Over Code Asia on another successful event!

       Looking forward to the ASF representation at Open Source Congress next month.
       Thank you to Andrew Musselman and Henri Yandell, who will be on panels at the
       event, and to Brian Proffitt for help with the organization, as it was our
       "turn" this year (after previous events run by LF, OpenAtom, and Eclipse).

       D&O insurance has been renewed. I've noticed in this quote and the event
       insurance quotes that insurance costs in general seem to be lugubriously on
       the rise quite a bit. Not in any way our budgets can't handle this year, but
       it's something to be aware of when we're planning in the future.

       Additionally, please see Attachments 1 through 11.

    C. Treasurer [Craig McClanahan]

       Normal operations continue, including additional information requests for our
       audit, and a bunch of questions from Conferences and Fundraising about
       invoicing and payments for CoC Sponsors.

    D. Secretary [Matt Sicker]

       In July 2026 the secretary received 49 ICLAs, two CCLAs, and one SGA.

    E. Executive Vice President [Daniel Ruggeri]

       Nothing of interest to report this month. The machine remains well oiled and
       spinning away

    F. Vice Chair [Justin Mclean]

       Nothing to report.

    Executive officer reports approved as submitted by General Consent.

5. Additional Officer Reports

    A. VP of W3C Relations [Andy Seaborne / Emmanuel Lécharny]

       See Attachment 12

    B. Apache Legal Affairs Committee [Justin Mclean]

       See Attachment 13

    C. Apache Security Team Project [Mark J. Cox / Justin Mclean]

       See Attachment 14

    D. VP of Responsible AI [Jeff Genender / Sander Striker]

       See Attachment 15

    Additional officer reports approved as submitted by General Consent.

6. Committee Reports

    Summary of Reports

     The following reports required further discussion:

        # Fluss [cdutz]
        # Ignite [striker]
        # Impala [striker]
        # Kafka [striker]
        # Logging Services [striker]
        # Perl [elecharny, jmclean, striker]
        # Responsible AI [jmclean]
        # SDAP [elecharny]
        # SIS [gstein]
        # ShenYu [cdutz]
        # Uniffle [jmclean]
        # Xalan [elecharny]

    A. Apache AGE Project [Jeff Jirsa / Greg Stein]

       No report was submitted.

    B. Apache Airavata Project [Suresh Marru / Jean-Baptiste Onofré]

       No report was submitted.

    C. Apache Airflow Project [Bolke de Bruin / Shane Curcuru]

       See Attachment C

    D. Apache Ambari Project [Brahma Reddy Battula / Zili Chen]

       No report was submitted.

    E. Apache Ant Project [J Pai / Christopher Schultz]

       See Attachment E

    F. Apache Artemis Project [Christopher L. Shannon / Christofer Dutz]

       See Attachment F

    G. Apache Attic Project [Hervé Boutemy / Greg Stein]

       See Attachment G

    H. Apache Avro Project [Ryan Skraba / Zili Chen]

       See Attachment H

    I. Apache BookKeeper Project [Enrico Olivelli / Shane Curcuru]

       No report was submitted.

    J. Apache Brooklyn Project [Juan D. Cabrerizo / Emmanuel Lécharny]

       See Attachment J

    K. Apache BuildStream Project [Abderrahim Kitouni / Christopher Schultz]

       No report was submitted.

    L. Apache Cassandra Project [Ekaterina Dimitrova / Jean-Baptiste Onofré]

       See Attachment L

    M. Apache Celeborn Project [Keyong Zhou / Justin Mclean]

       No report was submitted.

    N. Apache Celix Project [Pepijn Noltes / Christofer Dutz]

       See Attachment N

    O. Apache Community Development Project [Rich Bowen / Sander Striker]

       See Attachment O

    P. Apache CouchDB Project [Jan Lehnardt / Jean-Baptiste Onofré]

       No report was submitted.

    Q. Apache Creadur Project [Philipp Ottlinger / Shane Curcuru]

       See Attachment Q

    R. Apache Curator Project [Enrico Olivelli / Justin Mclean]

       See Attachment R

    S. Apache DataSketches Project [Lee Rhodes / Christofer Dutz]

       See Attachment S

    T. Apache DeltaSpike Project [Mark Struberg / Sander Striker]

       See Attachment T

    U. Apache Doris Project [Mingyu Chen / Zili Chen]

       See Attachment U

    V. Apache Drill Project [Charles Givre / Emmanuel Lécharny]

       No report was submitted.

    W. Apache Empire-db Project [Rainer Döbele / Christopher Schultz]

       See Attachment W

    X. Apache EventMesh Project [Eason Chen / Greg Stein]

       No report was submitted.

    Y. Apache Flex Project [Harbs / Justin Mclean]

       No report was submitted.

    Z. Apache Fluss Project [Jark Wu / Christofer Dutz]

       See Attachment Z

    AA. Apache FreeMarker Project [Dániel Dékány / Jean-Baptiste Onofré]

       See Attachment AA

    AB. Apache Geode Project [Mark Bretl / Greg Stein]

       See Attachment AB

    AC. Apache Geronimo Project [Jean-Louis Monteiro / Greg Stein]

       No report was submitted.

    AD. Apache Grails Project [James Fredley / Sander Striker]

       See Attachment AD

    AE. Apache Groovy Project [Paul King / Emmanuel Lécharny]

       See Attachment AE

    AF. Apache Hop Project [Hans Van Akelyen / Justin Mclean]

       See Attachment AF

    AG. Apache HTTP Server Project [Joe Orton / Zili Chen]

       See Attachment AG

    AH. Apache HttpComponents Project [Michael Osipov / Christopher Schultz]

       See Attachment AH

    AI. Apache Ignite Project [Dmitry Pavlov / Shane Curcuru]

       See Attachment AI

    AJ. Apache Impala Project [Zoltán Borók-Nagy / Zili Chen]

       See Attachment AJ

    AK. Apache Incubator Project [Justin Mclean / Justin Mclean]

       See Attachment AK

    AL. Apache Johnzon Project [Jean-Louis Monteiro / Sander Striker]

       No report was submitted.

    AM. Apache Juneau Project [James Bognar / Christofer Dutz]

       See Attachment AM

    AN. Apache Kafka Project [Mickael Maison / Christopher Schultz]

       See Attachment AN

    AO. Apache Knox Project [Larry McCay / Emmanuel Lécharny]

       No report was submitted.

    AP. Apache Kylin Project [Yang Li / Christopher Schultz]

       See Attachment AP

    AQ. Apache Libcloud Project [Miguel Caballer / Justin Mclean]

       See Attachment AQ

    AR. Apache Livy Project [Jean-Baptiste Onofré / Jean-Baptiste Onofré]

       See Attachment AR

    AS. Apache Logging Services Project [Jan Friedrich / Shane Curcuru]

       See Attachment AS

    AT. Apache Lucene.Net Project [Shad Storhaug / Greg Stein]

       No report was submitted.

    AU. Apache MADlib Project [Ed Espino / Zili Chen]

       No report was submitted.

    AV. Apache Magpie Project [Jarek Potiuk / Justin Mclean]

       See Attachment AV

    AW. Apache ManifoldCF Project [Piergiorgio Lucidi / Jean-Baptiste Onofré]

       See Attachment AW

    AX. Apache Maven Project [Hervé Boutemy / Christopher Schultz]

       See Attachment AX

    AY. Apache Mynewt Project [Szymon Janc / Emmanuel Lécharny]

       No report was submitted.

    AZ. Apache OpenWebBeans Project [Mark Struberg / Justin Mclean]

       See Attachment AZ

    BA. Apache OpenWhisk Project [Dave Grove / Zili Chen]

       See Attachment BA

    BB. Apache ORC Project [William Hyun / Sander Striker]

       No report was submitted.

    BC. Apache Ozone Project [Sammi Chen / Greg Stein]

       See Attachment BC

    BD. Apache PDFBox Project [Andreas Lehmkühler / Jean-Baptiste Onofré]

       See Attachment BD

    BE. Apache Perl Project [Steve Hay / Shane Curcuru]

       See Attachment BE

       roll call

    BF. Apache Phoenix Project [Viraj Jasani / Christofer Dutz]

       See Attachment BF

    BG. Apache Pinot Project [Kishore G / Greg Stein]

       No report was submitted.

    BH. Apache POI Project [Dominik Stadler / Shane Curcuru]

       See Attachment BH

    BI. Apache Polaris Project [Jean-Baptiste Onofré / Jean-Baptiste Onofré]

       See Attachment BI

    BJ. Apache Pony Mail Project [Rich Bowen / Sander Striker]

       See Attachment BJ

    BK. Apache Qpid Project [Robbie Gemmell / Emmanuel Lécharny]

       See Attachment BK

    BL. Apache Ranger Project [Selvamohan Neethiraj / Jean-Baptiste Onofré]

       No report was submitted.

    BM. Apache RocketMQ Project [Xiaorui Wang / Christopher Schultz]

       No report was submitted.

    BN. Apache Roller Project [Dave Johnson / Christofer Dutz]

       See Attachment BN

    BO. Apache Samza Project [Jagadish Venkatraman / Greg Stein]

       No report was submitted.

    BP. Apache Santuario Project [Colm O hEigeartaigh / Zili Chen]

       See Attachment BP

    BQ. Apache SDAP Project [Nga Thien Chung / Justin Mclean]

       See Attachment BQ

       @Justin Mclean: roll call

    BR. Apache Sedona Project [Jia Yu / Justin Mclean]

       See Attachment BR

    BS. Apache Serf Project [Daniel Sahlberg / Emmanuel Lécharny]

       See Attachment BS

    BT. Apache ServiceComb Project [Zhangjian He / Sander Striker]

       No report was submitted.

    BU. Apache ShardingSphere Project [Liang Zhang / Zili Chen]

       See Attachment BU

    BV. Apache ShenYu Project [Yu Xiao / Christofer Dutz]

       See Attachment BV

    BW. Apache SIS Project [Martin Desruisseaux / Shane Curcuru]

       See Attachment BW

    BX. Apache Solr Project [Alessandro Benedetti / Jean-Baptiste Onofré]

       See Attachment BX

    BY. Apache Spark Project [Matei Zaharia / Christopher Schultz]

       See Attachment BY

    BZ. Apache Steve Project [Greg Stein / Greg Stein]

       No report was submitted.

    CA. Apache StormCrawler Project [Richard Zowalla / Shane Curcuru]

       See Attachment CA

    CB. Apache StreamPipes Project [Philipp Zehnder / Greg Stein]

       See Attachment CB

    CC. Apache Subversion Project [Nathan Hartman / Christopher Schultz]

       See Attachment CC

    CD. Apache Superset Project [Maxime Beauchemin / Shane Curcuru]

       See Attachment CD

    CE. Apache Syncope Project [Francesco Chicchiriccò / Justin Mclean]

       See Attachment CE

    CF. Apache SystemDS Project [Matthias Boehm / Shane Curcuru]

       See Attachment CF

    CG. Apache Tcl Project [Georgios Petasis / Christopher Schultz]

       No report was submitted.

    CH. Apache TomEE Project [David Blevins / Christofer Dutz]

       See Attachment CH

    CI. Apache Traffic Server Project [Bryan Call / Zili Chen]

       See Attachment CI

    CJ. Apache TsFile Project [Jialin Qiao / Greg Stein]

       No report was submitted.

    CK. Apache Turbine Project [Georg Kallidis / Jean-Baptiste Onofré]

       See Attachment CK

    CL. Apache Uniffle Project [He Qi / Greg Stein]

       See Attachment CL

    CM. Apache Velocity Project [Nathan Bubna / Sander Striker]

       No report was submitted.

    CN. Apache Wayang Project [Zoi Kaoudi / Emmanuel Lécharny]

       See Attachment CN

    CO. Apache Whimsy Project [David Fisher / Zili Chen]

       See Attachment CO

    CP. Apache Xalan Project [Gary D. Gregory / Justin Mclean]

       See Attachment CP

    CQ. Apache Xerces Project [Michael Glavassevich / Jean-Baptiste Onofré]

       No report was submitted.

    CR. Apache XML Graphics Project [Clay Leeds / Christofer Dutz]

       See Attachment CR

    CS. Apache YuniKorn Project [Wilfred Spiegelenburg / Emmanuel Lécharny]

       See Attachment CS

    Committee reports, approved as submitted by General Consent.

7. Special Orders

    A. Change the Apache Druid Project Chair

       WHEREAS, the Board of Directors heretofore appointed Abhishek Agarwal
       (abhishek) to the office of Vice President, Apache Druid, and

       WHEREAS, the Board of Directors is in receipt of the resignation of Abhishek
       Agarwal from the office of Vice President, Apache Druid, and

       WHEREAS, the Project Management Committee of the Apache Druid project has
       chosen by vote to recommend Karan Kumar (karan) as the successor to the post;

       NOW, THEREFORE, BE IT RESOLVED, that Abhishek Agarwal is relieved and
       discharged from the duties and responsibilities of the office of Vice
       President, Apache Druid, and

       BE IT FURTHER RESOLVED, that Karan Kumar be and hereby is appointed to the
       office of Vice President, Apache Druid, to serve in accordance with and
       subject to the direction of the Board of Directors and the Bylaws of the
       Foundation until death, resignation, retirement, removal or disqualification,
       or until a successor is appointed.

       Special Order 7A, Change the Apache Druid Project Chair, was
       approved by Unanimous Vote of the directors present.

    B. Appoint Assistant VP Legal Affairs

       WHEREAS, the office of Assistant VP Legal Affairs of The Apache Software
       Foundation is to be filled;

       NOW, THEREFORE, BE IT RESOLVED, that Zili Chen (tison) be and hereby is
       appointed to the office of Assistant VP Legal Affairs, to serve in accordance
       with and subject to the direction of the Board of Directors and the Bylaws of
       the Foundation until death, resignation, retirement, removal or
       disqualification, or until a successor is appointed.

       Special Order 7B, Appoint Assistant VP Legal Affairs, was
       approved by Unanimous Vote of the directors present.

    C. Establish Foundation Code of Conduct

       WHEREAS the Apache Software Foundation ("the Foundation") is committed to
       providing a welcoming, respectful, and harassment-free environment for all
       participants in its projects, communications channels, and events; and

       WHEREAS a proposed Apache Software Foundation Code of Conduct, as provided
       in Attachment CT, adapted from the Contributor Covenant version 2.1, has
       been prepared and circulated to the membership for review and comment; and

       WHEREAS the proposed Code of Conduct provides for enforcement within each
       project community by that project's Project Management Committee, with the
       President of the Foundation, or the President's designee, serving as the
       escalation point for matters that extend beyond a single project or raise
       Foundation-wide concerns;

       NOW, THEREFORE, BE IT RESOLVED, that the Board endorses the Apache Software
       Foundation Code of Conduct, as provided in Attachment CT; and be it
       further

       RESOLVED that the President is directed to adopt, publish, administer, and
       maintain the Code of Conduct as Foundation policy, and to establish and
       publish the reporting contacts and list of designated volunteers referred to
       therein; and be it further

       RESOLVED that the Board confirms that the responsibility of each Project
       Management Committee for enforcement of the Code of Conduct within its project
       community is exercised under the authority delegated to Project Management
       Committees by the Board; and be it further

       RESOLVED that no action taken under the Code of Conduct shall terminate or
       suspend the membership of any ASF Member except in accordance with section 4.7
       of the Bylaws of the Foundation; and be it further

       RESOLVED that the President may amend the Code of Conduct as needed, provided
       that any substantive change to its scope, standards, or enforcement provisions
       shall be approved by the Board before taking effect; and be it further

       RESOLVED that the Code of Conduct, once published, supersedes the Foundation's
       existing published Code of Conduct and any prior Foundation-level conduct
       guidelines to the extent of any inconsistency; and be it further

       RESOLVED that the enforcement of the Code of Conduct shall start once
       published, applying to events that occur after that date, and shall not be
       used to retroactively address events that precede the date of publication.

       Special Order 7C, Establish Foundation Code of Conduct, was
       approved (Yes: curcuru, cdutz, elecharny, jmclean, schultz, striker;
       No: tison, gstein).

    D. Change the Apache Hop Project Chair

       WHEREAS, the Board of Directors heretofore appointed Hans Van Akelyen (hansva)
       to the office of Vice President, Apache Hop, and

       WHEREAS, the Board of Directors is in receipt of the resignation of Hans Van
       Akelyen from the office of Vice President, Apache Hop, and

       WHEREAS, the Project Management Committee of the Apache Hop project has chosen
       by vote to recommend Bart Maertens (bartmaer) as the successor to the post;

       NOW, THEREFORE, BE IT RESOLVED, that Hans Van Akelyen is relieved and
       discharged from the duties and responsibilities of the office of Vice
       President, Apache Hop, and

       BE IT FURTHER RESOLVED, that Bart Maertens be and hereby is appointed to the
       office of Vice President, Apache Hop, to serve in accordance with and subject
       to the direction of the Board of Directors and the Bylaws of the Foundation
       until death, resignation, retirement, removal or disqualification, or until a
       successor is appointed.

       Special Order 7D, Change the Apache Hop Project Chair, was
       approved by Unanimous Vote of the directors present.

    E. Allocate Budget for Vice President, Responsible AI

       WHEREAS, the Board of Directors has established the office of
       Vice President, Responsible AI; and

       WHEREAS, the Apache Software Foundation anticipates expenses
       associated with the responsibilities of that office;

       NOW, THEREFORE, BE IT RESOLVED, that a budget of $83,500 be
       allocated to the Vice President, Responsible AI, to be used for
       expenses incurred as authorized by the Vice President, Responsible AI.

       Special Order 7E, Allocate Budget for Vice President, Responsible
       AI, was approved by Unanimous Vote of the directors present.

    F. Dissolve the Apache Security Team as a Board Committee

       WHEREAS, the Board previously constituted the Apache Security Team as an
       Executive Committee of the Board with authority to act on behalf of the
       Foundation in matters of security; and

       WHEREAS, the Board has determined that these responsibilities are better
       vested in the office of Vice President, Security, an officer serving at the
       direction of and reporting to the Board of Directors, supported by a team to
       which that officer may delegate; and

       WHEREAS, the Board intends to grant that officer sufficient authority to act
       effectively while retaining for itself the oversight of the Foundation's
       security function;

       NOW, THEREFORE, BE IT RESOLVED, that the Apache Security Team is hereby
       dissolved as a committee of the Board; and be it further

       RESOLVED, that the Vice President, Security is responsible for organization
       and oversight of efforts to maintain the security of software produced by the
       Foundation's projects, and shall maintain oversight and tracking of security
       issues affecting those projects, consistent with the Foundation's security
       policy; and be it further

       RESOLVED, that in furtherance of that responsibility the Vice President,
       Security may take, and may direct Foundation resources to take, any and all
       steps reasonably necessary to that end; and be it further

       RESOLVED, that such steps include altering or removing project content,
       releases, or artifacts; issuing advisories on a project's behalf; disabling a
       site, service, or account; determining whether an issue is a security
       vulnerability; and communicating externally on security matters affecting the
       Foundation or any of its projects, including on a project's behalf; and be it
       further

       RESOLVED, that this authority is to be exercised in cooperation with the
       relevant project where practical, and to override it where necessary; and be
       it further

       RESOLVED, that the Vice President, Security may delegate work to a team whose
       members serve at that officer's discretion; and be it further

       RESOLVED, that all policies, procedures, and guidelines previously adopted by
       or under the authority of the Apache Security Team, including the
       vulnerability handling process and project security policy, remain in full
       force and effect as policies of the Vice President, Security until amended or
       revoked by that officer; and that the Foundation's role as a CVE Numbering
       Authority, all in-progress reports, all embargoes and confidentiality
       undertakings, and all associated infrastructure and communication channels are
       unaffected by this reconstitution and continue under the authority of the Vice
       President, Security; and be it further

       RESOLVED, that all prior actions of the Apache Security Team are ratified.

       Special Order 7F, Dissolve the Apache Security Team as a Board
       Committee, was approved by Unanimous Vote of the directors
       present.

    G. Establish the Apache Sourcelume Project

       WHEREAS, the Board of Directors deems it to be in the best
       interests of the Foundation and consistent with the
       Foundation's purpose to establish a Project Management
       Committee charged with the creation and maintenance of
       open-source software, for distribution at no charge to the
       public, related to AI training-data provenance.

       NOW, THEREFORE, BE IT RESOLVED, that a Project Management
       Committee (PMC), to be known as the "Apache Sourcelume Project", be
       and hereby is established pursuant to Bylaws of the Foundation;
       and be it further

       RESOLVED, that the Apache Sourcelume Project be and hereby is
       responsible for the creation and maintenance of software
       related to AI training-data provenance; and be it further

       RESOLVED, that the office of "Vice President, Apache Sourcelume" be
       and hereby is created, the person holding such office to serve
       at the direction of the Board of Directors as the chair of the
       Apache Sourcelume Project, and to have primary responsibility for
       management of the projects within the scope of responsibility
       of the Apache Sourcelume Project; and be it further

       RESOLVED, that the persons listed immediately below be and
       hereby are appointed to serve as the initial members of the
       Apache Sourcelume Project:

         * Jamie Goodyear <jgoodyear@apache.org>
         * Andrew Musselman <akm@apache.org>
         * Calvin Kirs <kirs@apache.org>
         * Dave Fisher <wave@apache.org>
         * Jeff Genender <jgenender@apache.org>
         * Achim Nierbeck <anierbeck@apache.org>
         * JB Onofré <jbonofre@apache.org>
         * Raúl Cumplido <raulcd@apache.org>

       NOW, THEREFORE, BE IT FURTHER RESOLVED, that Jamie Goodyear be
       appointed to the office of Vice President, Apache Sourcelume, to
       serve in accordance with and subject to the direction of the
       Board of Directors and the Bylaws of the Foundation until
       death, resignation, retirement, removal or disqualification, or
       until a successor is appointed.

       Special Order 7G, Establish the Apache Sourcelume Project, was
       approved by Unanimous Vote of the directors present.

    H. Establish the Apache Iggy Project

       WHEREAS, the Board of Directors deems it to be in the best interests of the
       Foundation and consistent with the Foundation's purpose to establish a Project
       Management Committee charged with the creation and maintenance of open-source
       software, for distribution at no charge to the public, related to Iggy is a
       high-performance, ultra-low latency and large-scale persistent message
       streaming platform written in Rust..

       NOW, THEREFORE, BE IT RESOLVED, that a Project Management Committee (PMC), to
       be known as the "Apache Iggy Project", be and hereby is established pursuant
       to Bylaws of the Foundation; and be it further

       RESOLVED, that the Apache Iggy be and hereby is responsible for the creation
       and maintenance of software related to Iggy is a high-performance, ultra-low
       latency and large-scale persistent message streaming platform written in
       Rust.; and be it further

       RESOLVED, that the office of "Vice President, Apache Iggy" be and hereby is
       created, the person holding such office to serve at the direction of the Board
       of Directors as the chair of the Apache Iggy Project, and to have primary
       responsibility for management of the projects within the scope of
       responsibility of the Apache Iggy Project; and be it further

       RESOLVED, that the persons listed immediately below be and hereby are
       appointed to serve as the initial members of the Apache Iggy Project:

         * Hao Ding <xuanwo@apache.org>
         * Yonik Seeley <yonik@apache.org>
         * Zili Chen <tison@apache.org>
         * Hulk Lin <hulk@apache.org>
         * Grzegorz Koszyk <gkoszyk@apache.org>
         * Hubert Gruszecki <hgruszecki@apache.org>
         * Kranti Parisa <kranti@apache.org>
         * Piotr Gankiewicz <piotr@apache.org>
         * Patryk Huzarski <patryk@apache.org>

       NOW, THEREFORE, BE IT FURTHER RESOLVED, that Kranti Parisa be appointed to the
       office of Vice President, Apache Iggy, to serve in accordance with and subject
       to the direction of the Board of Directors and the Bylaws of the Foundation
       until death, resignation, retirement, removal or disqualification, or until a
       successor is appointed; and be it further

       RESOLVED, that the Apache Iggy Project be and hereby is tasked with the
       migration and rationalization of the Apache Incubator Iggy podling; and be it
       further

       RESOLVED, that all responsibilities pertaining to the Apache Incubator Iggy
       podling encumbered upon the Apache Incubator PMC are hereafter discharged.

       Special Order 7H, Establish the Apache Iggy Project, was approved
       by Unanimous Vote of the directors present.

    I. Dissolve Legal Affairs as a Board Committee

       WHEREAS, the Legal Affairs Committee was established as an
       Executive Committee of the Board of Directors by resolution of
       28 March 2007 (Special Order 6C), responsible for establishing
       and managing legal policies; and

       WHEREAS, those functions have in practice been carried out
       through the office of Vice President, Legal Affairs, and the
       Board deems it to be in the best interests of the Foundation
       that they continue under a clear delegation of authority to
       that office;

       NOW, THEREFORE, BE IT RESOLVED, that the Legal Affairs Committee
       is hereby dissolved as a committee of the Board, and all actions
       taken by or under its authority are hereby ratified and
       affirmed; and be it further

       RESOLVED, that the office of Vice President, Legal Affairs,
       appointed by and serving at the direction of the Board, be and
       hereby is continued, with responsibility for the legal affairs
       of the Foundation, including custodianship of the Apache License,
       establishing and maintaining legal policy binding on the
       Foundation's projects and officers, and resolving legal questions
       raised by projects and officers, with such resolutions binding on
       the requesting party, in each case unless the Board directs
       otherwise. The legal affairs of the Foundation include
       any matter, in whatever area of the Foundation's activities it
       arises, concerning the licensing, provenance, or terms governing
       contributions to and releases of the Foundation's projects; the
       Foundation's intellectual property; contracts and agreements
       entered into by the Foundation; and the regulatory and statutory
       obligations applicable to the Foundation or its projects; and be
       it further

       RESOLVED, that guidance issued by other officers and committees
       within their own areas of responsibility shall be consistent
       with legal policy so established, with questions of
       interpretation of such policy resolved by the Vice President,
       Legal Affairs; and be it further

       RESOLVED, that all policies and guidance previously adopted by
       or under the authority of the Legal Affairs Committee, including
       those published at https://www.apache.org/legal/, remain in full
       force and effect as policies of the Vice President, Legal
       Affairs until amended or revoked by that officer; and be it
       further

       RESOLVED, that matters concerning the Bylaws of the Foundation,
       the initiation or settlement of litigation, and modification of
       the Apache License remain reserved to the Board, and that
       trademark and brand management matters remain delegated to the
       Vice President, Brand Management; and be it further

       RESOLVED, that the Vice President, Legal Affairs may delegate
       responsibilities to a legal team of the Vice President's
       choosing, shall document the scope and current policies of the
       office at https://www.apache.org/legal/, and shall continue to
       report monthly to the Board.

       Special Order 7I, Dissolve Legal Affairs as a Board Committee,
       was tabled.

8. Discussion Items

9. Review Outstanding Action Items

    * Greg Stein: talk to Pinot PMC about communication channels
          [ Pinot 2025-11-19 ]
          Status:

    * Greg Stein: follow up with TsFile PMC about publishing to PyPI
          [ TsFile 2025-11-19 ]
          Status: Done. Canceling. No requests have surface about this in many months, that I've seen.

    * Greg Stein: follow up with board about PyPI policy
          [ TsFile 2025-11-19 ]
          Status: Done. Canceling. No requests have surface about this in many months, that I've seen.

    * Shane Curcuru: follow up about licensing
          [ SIS 2026-02-18 ]
          Status: Can be closed: this is a longer-term strategy issue that doesn't have a
                  current board solution.

    * Greg Stein: pursue roll call
          [ Geronimo 2026-04-15 ]
          Status: attention is present, but so far it sounds like the
                  correct approach is "spin out components" rather than a
                  complete TLP move to the Attic. "spin out" to a new TLP
                  designated to support those? To Tomcat or TomEE or
                  Commons? ... still waiting on further feedback/roll-call

    * Zili Chen: follow up about project viability
          [ MADlib 2026-04-15 ]
          Status: Follow up - https://lists.apache.org/thread/781rspl421vcmclzjdqlstzq8b5vgf4m

                  Seems MADlib didn't reply to Cloudberry's collaboration suggestion.

    * Shane Curcuru: roll call for BVAL
          [ BVal 2026-05-20 ]
          Status: Done. No roll call needed; BVal has a new release and some code updates recently

    * Justin Mclean: suggest chair change
          [ Hop 2026-05-20 ]
          Status: Done. Sent an email suggesting a chair change and we have a proposal to change the
                  chair.

    * Christopher Schultz: suggest ways to improve the board report
          [ Spark 2026-05-20 ]
          Status: Completed. https://lists.apache.org/thread/cztsg4vmzosyzzq5zpj4ptry10gcgwcg

    * Shane Curcuru: message all PMCs to improve board reports and discuss
                     "Emeritus" concept for PMCs.
          [ Superset 2026-05-20 ]
          Status:

    * Christopher Schultz: discuss failed roll call and future direction
          [ Kylin 2026-05-20 ]
          Status: https://lists.apache.org/thread/fzy0hjl46fmy2w8c6woljjq0co5zff4j

                  The PMC has sent invitations to some new committers and PMC members.

    * Sander Striker: follow up about release candidate location
          [ Gravitino 2026-06-17 ]
          Status:

    * Christopher Schultz: reach out about communication issues
          [ IoTDB 2026-06-17 ]
          Status: Will reach-out to IOTDB in mid-July.

    * Christopher Schultz: follow up about AI code usage
          [ OpenDAL 2026-06-17 ]
          Status:

    * Jean-Baptiste Onofré: follow up about Xerces-C EOL
          [ Xerces 2026-06-17 ]
          Status:

    * Greg Stein: follow up about chair responsibilities
          [ Flagon 2026-07-15 ]
          Status:

    * Justin Mclean: follow up on clarification on chair/project authorizations
          [ Magpie 2026-07-15 ]
          Status: Done. done, PMC discussed, reminded them to add resolution

    * Sander Striker: pursue a roll call
          [ Rya 2026-07-15 ]
          Status:

    * Justin Mclean: Determine the board's position on whether security triage
                     and release management are "paying for development" under
                     the Targeted Sponsorship Policy, and report back.
          [ Logging Services 2026-08-19 (created by Justin Mclean) ]
          Status:

    * Justin Mclean: Roll Call for Xalan
          [ Xalan 2026-08-19 (created by Sander Striker) ]
          Status:

    * Shane Curcuru: Ask whether the Ignite 3 project is still a going concern,
                     and if not, when will users be notified?
          [ Ignite 2026-08-19 (created by Justin Mclean) ]
          Status:

10. Unfinished Business

11. New Business

12. Announcements

13. Adjournment

    Adjourned at 22:10 UTC


============
ATTACHMENTS:
============

-----------------------------------------
Attachment 1: Report from the VP of Brand Management  [Mark Thomas]

Covering the period July 2026

* ISSUES FOR THE BOARD

The GLUTEN PMC is not responding to trademarks@a.o


* OPERATIONS

Daan Hoogland continues to provide some very welcome assistance with trademark
issues.

Responded to the following queries, liaising with projects as required:
- Provided advice to SIS regarding a potential new logo
- Provided advice to a vendor looking to provide add-ons for ACTIVEMQ
- Provided advice to a vendor looking to use ASF project names and logos in a
  marketing presentation
- Provided advice to a vendor looking to use the OSSIE logo in marketing
  material
- Provided advice for FLUSS regarding unofficial 'contrib' projects


* REGISTRATIONS

The OFBIZ mark has been renewed in the US.

The CASSANDRA mark has been renewed in the US.

Worked with counsel to maintain our APISIX registration in the US.


* INFRINGEMENTS

Provided advice to CLOUDSTACK regarding various potential infringements.

The SPARK PMC is working on a potential infringement.

The Airflow PMC has identified potentially infringing releases on npm.

Still no progress from the GLUTEN PMC to address a range of product naming
issues with multiple 3rd parties.

There remaining issue for IOTDB has been resolved.

No further progress regarding the downstream vendor with multiple
infringements of ASF marks.

The SPARK PMC is making progress in addressing a range of product naming
issues with multiple 3rd parties.

No progress regarding a website with potential infringements of KIE.

Working with counsel to oppose a conflicting registration of FLINK in the EU.

I've asked for an update from the XMLGRAPHICS PMC regarding progress of the
complaint with GitHub regarding a potential third-party infringement of FOP.


-----------------------------------------
Attachment 2: Report from the VP of Fundraising  [Bob Paulin]


-----------------------------------------
Attachment 3: Report from the VP of Marketing and Publicity  [Brian Proffitt]

Foundation Communications

* Fielded inquiry from The Register about the ASF brand update
* Published blogs:
  * ALC Taipei in Computex 2026 by Chia-Ping Tsai
  * Sponsor Success at Apache: Google and Apache Iceberg
* Produced and issued July issue of Plus One newsletter
  * Subscriber list now totals 4,830 (395 new subscribers in July)
  * Total sent: 4,300 | Unique opens: 905 | Open rate: 21%
* Finalized design of Annual Report
* ASF Tooling case study published on the Alpha-Omega blog
* Began Dev.to syndication project

Foundation Brand

* Received confirmation of trademark for new ASF logo; updated logo set and
  Brand Guidelines

Foundation Digital

* Completed Community Over Code website design and development, adding
  Lakehouse Day, Airflow Contributor Days, Community Over Code Sydney, and
  Community Over Code Beijing
* Ported archival ApacheCon links and content from recent Community Over Code
  events to the new website’s Past Events page
* Completed LinkedIn advertising for Lakehouse Day; continued ads for
  Community Over Code
* Asked Members about access to ASF-branded pages on LinkedIn, X, and Facebook
  in order to update branding and/or redirect/remove the page; completed
  updates for X-VP Brands and received Meta approval for trademark
  infringement protections

Social Media Overview

The highest performing pieces of content for July include project news, ALC
Taipei in Computex 2026, and Sponsor Success at Apache posts.

Social Highlights (X + Bluesky + Fosstodon + LinkedIn)

* Total Audience: 151,151
  * X: 66,292
  * Bluesky: 1,159
  * Fosstodon: 226
  * LinkedIn: 83,474
* Total Posts:
  * X / Bluesky / Fosstodon / Bluesky: 72
  * LinkedIn: 27
* Total Engagements: 3,187 (X 1,903 + LinkedIn 1,179; Bluesky 105)

Website Analytics

790,225 visits, 790,041 unique visitors +9.4%
2 min 26s average visit duration +17.7%
60% visits have bounced (left the website after one page) -1.6%
2.2 actions (page views, downloads, outlinks, internal site searches)
 per visit 0%
1,390,797 pageviews, 1,008,895 unique pageviews +16.9%
16 total searches on your website, 13 unique keywords +60%
102,284 downloads, 72,978 unique downloads +2.5%
271,961 outlinks, 190,146 unique outlinks -9.4%


-----------------------------------------
Attachment 4: Report from the VP of Infrastructure  [Danny Angus]

General
-------
No issues currently require the Board's attention.

DKIM/Mail Delivery Problem Resolution
-------------------------------------
Improvements to DKIM signing were rolled out in late July, which should
greatly improve email delivery. This was confirmed by testers as largely
working, but another related delivery issue arose, and Infra has
implemented a fix for that as well.

MFA Rollout
-----------
MFA soft-rollout continues. Some UI/UX points of confusion have been
identified: additional documentation is being developed, and Infra is
engaging with UI/UX Authentik experts to improve the workflow/user
experience.

Atlassian Cloud Migration Status
--------------------------------
Migration preparation continues. There are a few migration blockers we
are working through with Atlassian, but progress is being made on other
aspects of the migration testing.

Community News
--------------
The August Infra Roundtable featured a presentation on the current state
of the Apache Trusted Releases (ATR) platform, with a tour of the user
interface that demonstrated how this platform will greatly simplify the
work of project release managers and reduce the likelihood of errors or
omissions in release artifacts.

The September 3 Roundtable, 1700 UTC, will have a review of the current
state of the new Contingent Approval Platform (CAP).

At Community Over Code Glasgow, in October, Infra will present a rich
track of talks and discussions, along with the popular Games Night.


-----------------------------------------
Attachment 5: Report from the VP of Tooling  [David Fisher]

# Tooling Initiative

## Apache Trusted Releases

We are building the ATR production server and preparing the Beta release. When
ready we will be sending an announcement to all PMCs.

Highlights include:

- Catalog of All ASF Releases including Archived Releases. A complete
  inventory ASF release artifacts was used to build a full catalog. The test
  catalog is available at https://release-catalog-test.apache.org/
- Identifying sub-projects is imperfect and complex. We are prepared to reseed
  after interacting with PMCs once complex sub-project organization is
  confirmed.
- ATR watches svn:dist:release changes using pubsub to capture non-ATR
  releases and archivals.
- Release records are emailed to releases@tooling.apache.org
- Expedited security releases are secret. They are completely private which
  was a challenge.
- Project metadata and policies are derived from DOAP and can be maintained in
  both ATR and .asf.yaml. ATR has a yaml export for projects allowing these
  records to be synchronized.
- Tooling now has a self hosted GH Runner which means that staff remains
  productive despite GH Runner contention.

ATR Releases since July 1, 2026

- Cordova File Transfer Plugin 2.0.1
- Maven Toolchains Plugin 3.3.0
- Maven Resolver 2.0.21
- Maven JAR Plugin 3.5.1
- Cordova Android 15.1.0
- Maven Resolver Ant Tasks 1.6.1

## Board Agenda Tool

Sander and Thomas have been making a very large number of AI assisted
improvements to the tool related to new agenda creation, presentation mode,
executive sessions, actions without a meeting, and a redesign of the site. The
new UX is on agenda-dev.apache.org Work is being done to fully replace
whimsy's board minutes views with much more accurate history to be fully
hosted on www.apache.org.

## Responsible AI Tooling

We are working with RAI to build out the tooling framework. We added Greg
Stein to the Tooling committee to support work on our model gateway called
LLMAO. llm.apache.org

Tooling has been covering small charges for tokens and hosted LLMs in our
limited budget. These items are now appropriately shifted to the RAI budget. I
would need to review with the Treasurer next month what our spend this fiscal
has been on these items.

Please note that one of the Tooling staff members is now dedicated to RAI.


-----------------------------------------
Attachment 6: Report from the VP of Conferences  [Brian Proffitt]

We are still planning for evening events around the conferences in Glasgow,
but the main reception is essentially set.

Rich Bowen has put together the project hackathon track, and has coordinated
the keynote speakers.

Sponsorships continue to come in for Lakehouse Day and Community Over Code
Glasgow, at a good rate.

The new communityovercode.apache.org launched in July, just ahead of Community
Over Code Beijing.

Speaking of that event, Willem Jiang has filed an addendum about how C/C
Beijing went:

"We just held the CommunityOverCode Asia 2026 last week (August 7-9).

"Here are some highlights of the conference I want to share:

"We received 259 CFP submissions and ultimately accepted 145 sessions across
 22 tracks.

"The conference brings together more than 180 speakers from over 10 countries
 and regions, representing more than 50 Apache projects.

"Over 900 people registered for the event, with 700 attending in person. About
 60K people watched the online broadcast of the three-day keynote sessions.

"Now we are doing some wrap-up work, such as processing the conference videos,
 etc."

The planning team has tentatively secured a venue for the 2027 North America
Community Over Code. A site visit is scheduled for September, 2026.

CFP for Community Over Code Sydney event, to be held November 18-19,
continues.


-----------------------------------------
Attachment 7: Report from the Apache Travel Assistance Committee  [Gavin McDonald]

Current Events
==============

Community Over Code - Glasgow
-----------------------------

Flights continue to be booked with plenty of time. We are awaiting Visa news
from several applicants before we would book their flights. Hotel rooms are
booked

Community Over Code - Beijing
-----------------------------

This event has just finished, by all accounts was a great success. TAC will
provide its report on this next month.

Monthly Meetings
================

Next meeting is due 2nd week of week of September

Future Events
=============

None Currently

TAC has agreed to provide budget for a welcome meal for students and TAC
members/volunteers for the Sydney C/C event in November.


Short/Medium Term Priorities
============================

Keeping an eye out for other smaller events to support.

Post surveys for Bratislava, Hangzhou, Denver, Beijing and Minneapolis still
to be done.


-----------------------------------------
Attachment 8: Report from the VP of Diversity and Inclusion  [Daniel Gruno]


-----------------------------------------
Attachment 9: Report from the VP of Data Privacy  [Christian Grobmeier]


-----------------------------------------
Attachment 10: Report from the VP of Public Affairs  [Dirk-Willem van Gulik]

TLDR - nothing that needs board attention as most of the policy world is shut
down over the sumer.

That said - on the CRA and related - lots of guidance and other information
becoming final/official.

All of it generally as expected and good enough / not overly a concern for us:

	This includes a simple factsheet on the now (mandatory from the 11th of
	September) reporting https://www.enisa.europa.eu/media/57221

	Industry practices described in the ENISA secure by design and default
	playbook:

	 	https://www.enisa.europa.eu/publications/enisa-secure-by-design-and-default-playbook
	 	https://github.com/enisaeu/enisa-sbd-playbook/

	And some practical suggestions around SBOMs;

		https://www.cisa.gov/sites/default/files/2026-07/2026_cisa_sbom_minimum_elements_508c.pdf

	And also more clarity for our industry:

		https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Technische-Richtlinien/TR-nach-Thema-sortiert/tr03183/TR-03183_node.html

And we keep getting loaded/framing questions on AI & Security and the
potential risk of the US being in the sole control.

Our general response is that, at our global scale, none of the models is
particularly special relative to the others,

And that smaller, highly specialist models, can be just as interesting
(especially if the usual global, open source mechanisms of feedback &
incremental improvement works).

And that a lot of this is not about the tech -- but much more about business
models, marketing, attention, framing and whom, or what, gets addicted, or too
reliant, on whose `free' tokens, predatory pricing & market control.


-----------------------------------------
Attachment 11: Report from the VP of ECMA Relations  [Piotr Karwasz]

The CycloneDX working group has submitted the Threat Model BOM proposal to
ECMA TC-54: https://github.com/Ecma-TC54/meetings/issues/9

This BOM format only **partially** covers the information we provide in our
descriptive threat model pages. LLM-generated TM-BOMs are available here:
https://s.apache.org/tm-bom

Most notably, the format does not allow us, out of the box, to define which
threats are in-scope versus which are the operator's responsibility, but we
can work around this using custom ASF properties.


-----------------------------------------
Attachment 12: Report from the VP of W3C Relations  [Andy Seaborne]

Niklas Merz and Bryan Ellis (niklasmerz@ and erisu@) have joined the W3C
Embedded Web Engines & Native Web Runtimes Community Group.

These are the first participants from ASF; ASF has signed the W3C Community
Contributor License Agreement.

Jan Lehnardt (jan@) has joined the No Build Community Group.

This is the first participant from ASF; ASF has signed the W3C Community
Contributor License Agreement.


-----------------------------------------
Attachment 13: Report from the Apache Legal Affairs Committee  [Roman Shaposhnik]

This is my first report as VP Legal Affairs, having taken over from Roman
Shaposhnik following last month's board meeting.

July was a fairly quiet month on the public legal lists. There are currently 6
open LEGAL JIRA issues. Three new LEGAL issues were raised during July,
covering third party data licensing, source header policy, and a code
donation; one has already been resolved.

A review of the ASF bylaws was undertaken. Most items examined raised no
concerns or only minor ones carrying little or no risk. Three items warrant
board attention and are under discussion: how board committees are structured
and operated under the bylaws, whether STV satisfies the plurality requirement
for director elections (3.9), and PMC composition with respect to non-Member
members (6.3).

The main activity this month has been a proposal to terminate the Legal
Affairs Committee and re-grant its powers explicitly to the office of VP
Legal. A similar restructure is under discussion for Security, and both
discussions are ongoing. Trademark matters would be explicitly carved out as
delegated to VP Brand Management, with bylaws matters and the initiation or
settlement of litigation reserved to the board. The resolution would ratify
the committee's past acts, and all current committee members are expected to
continue as an advisory legal team. Monthly reporting will continue unchanged.
Feedback is being incorporated and a resolution will come to the board once
discussion has concluded.

A board agenda item proposes appointing Zili Chen (tison) as Assistant VP
Legal Affairs, filling the vacant assistant role.


-----------------------------------------
Attachment 14: Report from the Apache Security Team Project  [Mark J. Cox]

July

* While still consistently more than before May, there is no clear rising (or
  dropping) trend in the incoming load anymore. Many projects have accumulated
  a backlog of open security reports, so we'll be working with them to help
  get back to normal. We'll focus both on projects with many and with old
  reports.

* We've further improved the PMC security dashboard at
  https://dash.security.apache.org, getting ready to publish it more widely.

* We're close to upgrading the CVE preparation and publication tool
  (cveprocess/vulnogram), which will unlock and simplify further automation,
  add initial support for Package URLs, and run on updated infrastructure.

* We've participated in a test of the Single Reporting Platform (SRP) that
  ENISA is building for notifications of security events, as mandated by the
  EU's Cyber Resilience Act (CRA).

* We've assisted Infra in various improvements to the DKIM infrastructure,
  which should ultimately improve email deliverability.

* We've assisted Infra with the GitHub Actions allowlist management

* One Tomcat vulnerability made it to the exclusive Known Exploited
  Vulnerabilities list:
  CVE-2026-34486<https://www.cve.org/CVERecord?id=CVE-2026-34486> "Missing
  Encryption of Sensitive Data"

Stats for Jul 2026:

        32      [license confusion]
        16      [support request/question not security notification]
        15      [report/question relating to dependencies]

Security reports: 750 (last months: 574, 739, 515, 386, 200, 160, 98)

        52      ['httpd']
        49      ['tomcat']
        34      ['airflow']
        31      ['cloudstack']
        29      ['commons']
        23      ['nuttx']
        22      ['superset']
        21      ['fineract']
        20      ['doris', 'openoffice']
        19      ['cxf']
        14      ['apisix']
        12      ['answer', 'website or infrastructure', 'zeppelin']
        11      ['kafka', 'thrift']
        10      ['camel', 'httpcomponents']
        9       ['nifi', 'trafficserver']
        8       ['fory', 'hugegraph', 'struts']
        7       ['artemis', 'dolphinscheduler', 'dubbo', 'gravitino', 'hive',
                 'linkis', 'solr', 'spark']
        6       ['couchdb', 'flink', 'hertzbeat', 'mynewt', 'shenyu', 'tika']
        5       ['accumulo', 'calcite', 'casbin', 'cassandra', 'guacamole',
                 'iotdb', 'ranger', 'streampark', 'xerces']
        4       ['activemq', 'arrow', 'avro', 'axis', 'beam', 'brpc',
                 'devlake', 'kylin', 'ofbiz', 'openmeetings', 'pulsar',
                 'seatunnel', 'wicket']
        3       ['atlas', 'eventmesh', 'fluss', 'ignite', 'knox', 'logging',
                 'netbeans', 'opennlp', 'seata', 'skywalking']
        2       ['druid', 'groovy', 'inlong', 'kyuubi', 'lucene', 'mina',
                 'orc', 'pdfbox', 'phoenix', 'pinot', 'qpid', 'rocketmq',
                 'santuario', 'shiro', 'submarine', 'subversion']
        1       ['allura', 'amoro', 'apr', 'bifromq', 'burr', 'celeborn',
                  'cordova', 'curator', 'fesod', 'geaflow', 'geode',
                  'gobblin', 'hadoop', 'helix', 'hop', 'hudi', 'iceberg',
                  'iggy', 'impala', 'james', 'johnzon', 'karaf', 'lucy',
                  'maven', 'myfaces', 'oozie', 'ossie', 'parquet', 'plc4x',
                  'poi', 'polaris', 'ponymail', 'ratis', 'samza',
                  'servicecomb', 'shardingsphere', 'shindig', 'sling',
                  'streampipes', 'syncope', 'tez', 'tvm', 'xmlgraphics',
                  'xtable', 'zookeeper']

In total, as of 1st July 2026, we're tracking 1574 (last months: 1314, 1139,
856, 629, 440) open issues across 165 projects, median age 63 days (last
months: 54, 51, 44, 47, 64). 300 of those issues have CVE names assigned. 48
(last months: 29, 25, 32, 28) of these issues, across 18 projects, are older
than 365 days.

* openoffice (Health red): Several issues in OpenOffice are over 365 days old.
  They are not severe enough to warrant stopping distribution of OpenOffice.
  (Last update: 2026-07-01)

* apr (Health amber): releases are few and far-between (Last update:
  2026-06-29)

* spark (Health amber): the project has a backlog of security reports to be
  triaged (Last update: 2026-05-06)

* superset (Health amber): while the project is actively publishing fixes to
  security issues each release, there is concern about a growing backlog.
  (Last update: 2026-07-01)


-----------------------------------------
Attachment 15: Report from the VP of Responsible AI  [Jeff Genender]

# Responsible AI Initiative Board Reports

## Report 1: August 2026

**Description**

The ASF Responsible AI Initiative (RAI) is a program to support the open
source technologies that underpin modern artificial intelligence, and to help
Apache communities adopt AI in a way that is open, transparent, and aligned
with the ASF's values. The initiative is grounded in the ASF's guidelines for
the responsible use of AI — human oversight, licensing integrity, security,
and documentation — core principles rooted in the Foundation's longstanding
philosophy of community over code.

To fulfill its charter, the RAI is undertaking efforts to facilitate:

1. Access to AI models and tooling
2. Ecosystem support for Projects
3. Community engagement and outreach

**Status**

Status on the above activities includes supporting the Security Scanning &
Triage collaboration between the ASF Security team and the Tooling team. More
than 75 PMCs have enlisted: some delays from one of our frontier model donors
are now resolved and initial scans are underway.

I participated on calls with Infrastructure, Tooling, and Fundraising to
coordinate targeted donations, prioritize token usage, and connect with
Initiative backers.

We are planning to conduct a survey of PMCs and operations teams on their use
of AI to have a better idea on the state of AI activity and tooling within the
ASF. We are touching base with the folks on Apache Magpie and coordinating
various projects-in-development, including Low-Rank Adaptation (LoRA) adapters
and a dynamic routing layer, a TLP proposal being prepared for Apache
Sourcelume — an AI training data provenance infrastructure, as well as a
proposal preparing to be submitted to the Apache Incubator or for new Project
(TBD).

Initial work has begun on LLMAO (LLM for Apache.Org), a Foundation-wide way
for committers, projects, and communities to reach sanctioned inference and
related AI capabilities without every PMC holding its own provider keys. The
goal is one governed chokepoint for attribution, budgets, and policy for work
in an AI-capable ASF. This project is to provide gateway access through
LiteLLM to hosted models including frontier and cloud (local) implementations.

We have opened the floor for ideas regarding budget, and worked on
infrastructure for RAI: our initial site is up at https://rai.apache.org/ . We
plan to add a new logo for RAI and are narrowing down to a handful of options.

We had a discussion with the Community Over Code/Asia panelists to review
messaging, and shared a new graph of our email counts that shows the source of
our pull requests (49% from unknown authors: possibly bots; need to look into
this).

As we're just officially getting started (our second week!) we welcome Member
feedback and ideas at `discuss@rai.apache.org` and at `#rai-discuss` on Slack.

We have currently put together an initial budget, in coordination with Tooling
and Infra to obtain some initial numbers primarily for hosting private LLMs
and token acquisition. The budget also includes travel for the VP to
Glasgow/CoC surrounding events with potential for one or more presentations,
Q&A, panel, BoF, and hackathon. The budget request is for $83,500.00 for the
current fiscal year. A resolution to approve the budget will be submitted to
the Board for consideration.

**Upcoming**

We aim to share results as we develop our tooling and processes. We are
planning to attend Community Over Code in Glasgow, and look forward to sharing
our progress with the greater community.

**Work items**

From our proposal for RAI, we have begun our initial work items:

1. Assess foundation-wide the current state of AI activity and tooling
2. Prioritize AI resources PMCs would like the Foundation to provide
3. Assemble a situation report with gap analysis
4. Prepare a strategy within 60 days
5. Maintain a rolling 60-day roadmap and plan
6. Construct budget updates for the Board's consideration
7. Collaborate with existing teams on policy

We are assembling estimates for potential work streams to support budget
plans. And we will be coordinating with existing teams this month to assess
any policy needs.


-----------------------------------------
Attachment A: Report from the Apache AGE Project  [Jeff Jirsa]


-----------------------------------------
Attachment B: Report from the Apache Airavata Project  [Suresh Marru]


-----------------------------------------
Attachment C: Report from the Apache Airflow Project  [Bolke de Bruin]

## Description:

The mission of Apache Airflow is the creation and maintenance of software
related to workflow automation and scheduling that can be used to author and
manage data pipelines

## Project Status:
Current project status: Ongoing, very high activity
Issues for the board: No issues for the board


## Membership Data:
Apache Airflow was founded 2018-12-19 (8 years ago)
There are currently 79 committers and 43 PMC members in this project.
The Committer-to-PMC ratio is roughly 5:3.

Community changes, past quarter:
- Pavan Kumar was added to the PMC on 2026-08-08
- Niko Oliveira was added to the PMC on 2026-05-21
- Henry Chen was added as committer on 2026-06-26
- Przemysław Mirowski was added as committer on 2026-06-30

## Project Activity:
As usual, we continue to have frequent releases of Airflow, and the separate
modules, with the "main" project release of 3.3.0 on 6th of July and a point
release, 3.3.1 on 12th of August.

We are increasing the languages that Airflow natively supports with our first
beta release of a Java (and Kotlin) SDK on 13th July.

Apache Airflow 3.3.1 was released on 2026-08-12.
Task SDK 1.3.1 was released on 2026-08-12.
Provider packages 2026-08-08 was released on 2026-08-10.
Provider packages 2026-08-06 was released on 2026-08-08.
Provider packages 2026-07-22 was released on 2026-07-28.
Apache Airflow Python Client 3.3.0 was released on 2026-07-14.
Java SDK 1.0.0-beta1 was released on 2026-07-13.
Provider packages 2026-07-06 was released on 2026-07-10.
Apache Airflow 3.3.0 was released on 2026-07-06.
Task SDK 1.3.0 was released on 2026-07-06.
Provider packages 2026-07-01 was released on 2026-07-04.
Provider packages 2026-06-26 was released on 2026-07-03.
Provider packages 2026-06-16 was released on 2026-06-22.
Provider packages 2025-06-08 was released on 2026-06-11.
Provider packages 2025-06-02 was released on 2026-06-07.
Apache Airflow Helm Chart 1.22.0 was released on 2026-06-04.
Apache Airflow Python Client 3.2.2 was released on 2026-06-04.
Apache Airflow Ctl 0.1.5 was released on 2026-06-03.
Apache Airflow 3.2.2 was released on 2026-05-29.
Task SDK 1.2.2 was released on 2026-05-29.
Provider packages 2026-05-25 was released on 2026-05-27.
Provider packages 2026-05-19 was released on 2026-05-23.

## Community Health:

Our yearly Airflow-focused conference, Airflow Summit is on August 31st
through September 2nd in Austin, TX, and the program is available at
<https://airflowsummit.org/program/>.

Our mailing lists remain at roughly the same level of activity.

We are having discussions as a PMC and as a community about ways of dealing
with the increased PR volume due to LLM generated PRs, but have not reached
any conclusions yet. As ancedata, a single person opened 15+ very low quality
PRs almost simultaneously.

Quarter      Total PRs     Total PRs excluding bots
Q1 2026.     3,019         2,821
Q2 2026      3,059         2,846


(Bot doesn't attempt to classif PRs as Human vs Agent, we only exclude
 dependbot etc)


-----------------------------------------
Attachment D: Report from the Apache Ambari Project  [Brahma Reddy Battula]


-----------------------------------------
Attachment E: Report from the Apache Ant Project  [J Pai]

## Description:
The mission of Apache Ant is the creation and maintenance of the Ant build
system and related software components.

It consists of the following main projects:

- Ant - core and libraries (AntLibs)
- Ivy - Ant based dependency manager

## Project Status:
Current project status: Primarily in bug fix mode and maintenance mode.
Issues for the board: None for now.

## Membership Data:
Apache Ant was founded 2002-11-18 (24 years ago)
There are currently 29 committers and 22 PMC members in this project.
The Committer-to-PMC ratio is roughly 4:3.

Community changes, past quarter:
- No new PMC members. Last addition was Magesh Umasankar on 2018-07-06.
- No new committers. Last addition was Jaikiran Pai on 2017-06-15.

## Project Activity:
The primary goal of Ant these days is to make sure that it can be used
to build projects using a wide variety of Java versions including the
recent releases of Java.

Ant 1.10.17 was released in April 2026. We have accumulated some bug
fixes in the Ant repo since then. Stefan has also integrated the
Apache CycloneDX Ant Library into the Ant project's build so that
new releases of the Ant project can now publish
Software Bill Of Materials (SBOM). Given the bug fixes and this
important and useful new feature, we are considering a new release
of Ant in the next few weeks.

A new release, 2.6.0, of Ant Ivy was released last month
https://lists.apache.org/thread/g1gzqlc4m4l2t9qb4kb6mtwmq4qvtsjo.
This release of Ant Ivy is also the first one to ship the SBOM
files for the Ant Ivy project
https://repo1.maven.org/maven2/org/apache/ivy/ivy/2.6.0/ (the
cdx.json and cdx.xml artifacts at that location).

## Community Health:
Although we don't see too much development activity in Ant,
there are several active users of the Ant build tool. We
occasionally also see bug reports and pull requests on GitHub.
For a project that's in maintenance mode, this amount of
activity, we believe, is decent.


-----------------------------------------
Attachment F: Report from the Apache Artemis Project  [Christopher L. Shannon]

## Description:
The mission of Apache Artemis is the creation and maintenance of software
related to implementing a distributed messaging system

## Project Status:
Current project status: Ongoing
Issues for the board: None

## Membership Data:
Apache Artemis was founded 2025-11-18 (9 months ago)
There are currently 64 committers and 30 PMC members in this project.
The Committer-to-PMC ratio is roughly 2:1.

Community changes, past quarter:
- No new PMC members. Last addition was Andy Taylor on 2025-12-10.
- No new committers. Last addition was Adrian T. Co on 2025-12-03.

## Project Activity:
* Apache Artemis 2.55.0 was released on 2026-06-29.
* Apache Artemis 2.54.0 was released on 2026-05-19.
* Apache Artemis Console 1.8.0 was released on 2026-05-01.

Development is ongoing for an upcoming 2.56.0 release and significant time is
being spent on addressing security reports, just like many other projects.

## Community Health:
The community is healthy and there continues to be little impact to users
after the transition to the new TLP.


-----------------------------------------
Attachment G: Report from the Apache Attic Project  [Hervé Boutemy]

## Description:
The mission of Attic is the creation and maintenance of a home for dormant
projects.

## Project Status:
Current project status: ongoing
Issues for the board: none

## Membership Data:
Apache Attic was founded 2008-11-19 (18 years ago)
There are currently 19 committers and 17 PMC members in this project.
The Committer-to-PMC ratio is roughly 1:1.

Community changes, past quarter:
- No new PMC members. Last addition was Niall Pemberton on 2025-04-04.
- No new committers. Last addition was Niall Pemberton on 2025-04-04.

## Project Activity:
Attic worked on retiring 2 projects:
- Petri retirement is complete
- ServiceMix, started in previous quarter, retirement is complete
Progress tracked at
https://attic.apache.org/tracking.html

## Community Health:
3 active members continue to drive operations, with new small improvements
found on process and tools. Having more people involved in actual retirement
would be useful to spread the load and check our documentation is complete.


-----------------------------------------
Attachment H: Report from the Apache Avro Project  [Ryan Skraba]

## Description:
Apache Avro is a data serialization system with a compact binary format. It is
used for storing and transporting schema-driven serialized data. The unique
features of Avro include automatic schema resolution: when the reader's
expected schema is different from the actual schema with which the data was
serialized the data is automatically adapted to meet reader's requirements.

## Project Status:
Current project status: Ongoing
Issues for the board: None

## Membership Data:
Apache Avro was founded 2010-04-21 (16 years ago) There are currently 39
committers and 25 PMC members in this project. The Committer-to-PMC ratio is
roughly 5:4.

Community changes, past quarter:
- No new PMC members. Last addition was Oscar Westra van Holthe - Kind on
 2024-08-27.
- Mattia Basone was added as committer on 2026-03-20

## Project Activity:

During this entire quarter, we prioritized the 1.12.2 minor release with
accumulated bug and security fixes. Progress was continuous, but slower than
expected for a couple of reasons: we kept finding regressions that needed to
be fixed, as well as new bug fixes that were compelling enough to be included.
In the future, we should open the discussion to continually test Avro with
some of the downstream projects using it in order to prevent these from only
showing up at the last minute.

We managed to get two releases out (technically after the project reporting
period). Avro 1.12.2 has been voted and released, and the Avro Rust SDK
0.22.0 was voted, released and artifacts published.

After this minor release, we can start thinking about doing a major release
with some of the new features that have been waiting for this one.

## Community Health:

Mailing Lists:
- dev@avro.apache.org had 356 emails (-25% change)
- issues@avro.apache.org (mostly notifications) had 586 emails (-27% change)
- user@avro.apache.org continues to have very little traffic, 11 total

JIRA:
- 32 issues opened (+77% change)
- 17 issues closed (+142% change)

Code Repository:
- 114 commits in the past quarter (-42% change)
- 28 code contributors in the past quarter (+27% change)

GitHub:
- 160 PRs opened on GitHub, past quarter (-29% change)
- 140 PRs closed on GitHub, past quarter (-36% change)

Activity is in line with our expectations. Working on a minor release is often
a matter of cherry-picking from main into the release branch, which explains
why opening and closing issues has increased but GitHub activity on the main
branch has slowed down. It's important to maintain momentum on the main branch
to make sure that we get pull requests reviewed quickly.


-----------------------------------------
Attachment I: Report from the Apache BookKeeper Project  [Enrico Olivelli]


-----------------------------------------
Attachment J: Report from the Apache Brooklyn Project  [Juan D. Cabrerizo]

## Description:
The mission of Apache Brooklyn is the creation and maintenance of software
related to a software framework for modeling, monitoring and managing cloud
applications through autonomic blueprints.

## Project Status:
Current project status: Ongoing
Issues for the board: none

## Membership Data:
Apache Brooklyn was founded 2015-11-18 (11 years ago)
There are currently 20 committers and 19 PMC members in this project.
The Committer-to-PMC ratio is roughly 1:1.

Community changes, past quarter:
- No new PMC members. Last addition was Iuliana Cosmina on 2021-06-04.
- No new committers. Last addition was Mykola Mandra on 2022-03-08.

## Project Activity:
Enhanced log search and presentation capabilities, and type coercion for some
components.
The documentation has been updated to detail the limitations surrounding
WinRM environment variables and HTTPS certificates.


## Community Health:
Addressing user requirements and incorporating their feedback remains the
top priority.
As the board mentioned, it may be appropriate to put out a new release soon.


-----------------------------------------
Attachment K: Report from the Apache BuildStream Project  [Abderrahim Kitouni]


-----------------------------------------
Attachment L: Report from the Apache Cassandra Project  [Ekaterina Dimitrova]

-----------8<----------

Are you able to provide adequate oversight of your project? That is, are there

at least three PMC members who are engaged enough to respond in the event of a

CVE or similar crisis?

Yes, we maintain adequate project oversight and can address CVEs. Twenty-four

PMC members responded to the last roll call. Numerous PMC members actively

participate in both dev and private list discussions, ensuring that we have

more than the requisite three members available for rapid response to a CVE or

similar event.

Are there current or upcoming risks that threaten the sustainability of your

project? This could be anything from a change in employment of prolific

contributors, to an acquisition affecting a significant corporate contributor,

to a change in the technology landscape that makes your project less (or more)

relevant.

We currently do not see any specific risks threatening the project's

sustainability. We are focused on long-term health through deliberate

diversification and expansion of our contributor base.

We added a new PMC member - Andy Tolbert.

Additional indicators of Project Health and Growth this Quarter:

Releases: We shipped new versions of the: Cassandra server; Java, NodeJS, and
Python drivers; Cassandra analytics.

Community: The project will have its own track at Community over Code EU
2026. There is good interest and participation, and the community keeps on
      adding new interesting talks to YouTube Planet Cassandra.

What can the Foundation do to more effectively make your project more

successful in its mission of providing software for the public good?

Nothing at this point.


----------->8----------


-----------------------------------------
Attachment M: Report from the Apache Celeborn Project  [Keyong Zhou]


-----------------------------------------
Attachment N: Report from the Apache Celix Project  [Pepijn Noltes]

## Description:
The mission of Celix is the creation and maintenance of software related to
Implementation of the OSGi specification adapted to C

## Project Status:
Current project status: Dormant
Issues for the board: none

## Membership Data:
Apache Celix was founded 2014-07-16 (12 years ago)
There are currently 17 committers and 10 PMC members in this project.
The Committer-to-PMC ratio is roughly 9:5.

Community changes, past quarter:
- No new PMC members. Last addition was Peng Zheng on 2022-10-16.
- No new committers. Last addition was Zhenbao on 2022-10-19.

## Project Activity:

- Small bug fix on the build environment.
- Activity started on improving properties and JSON support for JSON Schemas.

## Community Health:

"dev@celix.apache.org had a 89% decrease in traffic in the past quarter (13
 emails compared to 111)"

Current activity on Apache Celix is very low, I think it never has been this
low. That being said, I still expect some development will pick up again.

Very recently some new deployment activities are started, but not yet merged
to the project.


-----------------------------------------
Attachment O: Report from the Apache Community Development Project  [Rich Bowen]

# Apache Community Development — Board Report, August 2026

## Description:

The mission of Community Development is the creation and maintenance of
resources, tools, and advice to help ASF Projects grow and retain their
project communities.

## Project Status:

Current project status: Ongoing with high activity
Issues for the board: None

## Membership Data:

Apache Community Development was founded 2009-10-31 (17 years ago)

There are currently 54 committers and 44 PMC members in this project.

Community changes, past quarter:

- No new PMC members. Last addition was Jarek Potiuk on 2026-05-01.
- No new committers. Last addition was Jarek Potiuk on 2026-05-03.

## Project Activity:

### "Thinking Bigger" Initiative

A series of strategic discussions on dev@ titled "Community development
— thinking bigger" proposed that ComDev operate more like a department
that actively invests in project health and sustainability, rather than
relying solely on zero-cost volunteer
efforts. This generated multiple follow-on threads covering three
proposed work streams:

1. **Project Metrics & Health Dashboard** — A prototype project health
dashboard (comdev-metrics) was published, covering git/SVN activity,
mailing list traffic, community growth, and release cadence across all
ASF projects. Discussion on dev@ explored making this an official
ComDev service, potentially hosted at projects.apache.org/metrics.

2. **Project Ambassadors** — A proposal to identify de-facto community
managers/organizers within each ASF project and bring them together
as Project Ambassadors for cross-project
collaboration, shared resources, and regular office hours.

3. **Project Health & Outreach** — Early warning systems for at-risk
projects, proactive outreach, and new contributor workshops in
partnership with universities.

### Google Summer of Code

GSoC 2026 continues. The GSOC JIRA project received its first GSoC 2027
proposal (Maven 4 build-aware dependency tracking from Romain
Manni-Bucau), indicating early preparation for the next cycle. The
dev@ list fielded GSoC participation inquiries from prospective students.

### PonyMail MCP Server

Active development continued on the PonyMail MCP (Model Context Protocol)
server hosted in the comdev repository. Jarek Potiuk contributed API
token authentication with scopes (#312), dark-mode UI fixes, and various
improvements. Updates were merged for hono and body-parser.

### Events Site (events.apache.org)

The events site is being used for supplemental/community-driven content
around Community Over Code, and planning for a hackathon in the Wee Dram
room during the conference.

### Website

Monthly community activity blog posts continued to be published on
community.apache.org. The website continues to serve as the primary
resource for new contributor guidance and project best practices.

## Community Health:

The dev@ mailing list saw 91 messages across 37 threads in June–July
2026, with contributions from 15+ unique individuals. This represents
sustained high activity compared to prior quarters.

The commits@ list recorded 194 messages, reflecting active automated
infrastructure (reporter.apache.org release tracking, projects.apache.org
metadata updates) as well as human commits to the website and comdev
repositories.

The project continues to attract contributors interested in tooling and
developer infrastructure.

## Releases:

Community Development is a non-releasing project. Its output is
services, tools, and documentation rather than versioned software
releases.


-----------------------------------------
Attachment P: Report from the Apache CouchDB Project  [Jan Lehnardt]


-----------------------------------------
Attachment Q: Report from the Apache Creadur Project  [Philipp Ottlinger]

## Description:
The mission of Creadur is the creation and maintenance of software related to
Comprehension and auditing of software distributions

## Project Status:
Current project status: ongoing
Issues for the board: none

## Membership Data:
Apache Creadur was founded 2012-04-18 (14 years ago)
There are currently 11 committers and 10 PMC members in this project.
The Committer-to-PMC ratio is roughly 6:5.

Community changes, past quarter:
- No new PMC members. Last addition was Claude Warren on 2024-01-23.
- No new committers. Last addition was Jean-Baptiste Onofré on 2024-01-23.

## Project Activity:
Development continues as we try to break up RAT to allow a quicker release
of any UI (Maven, Ant, CLI). Apart from that contributions are coming in
via GitHub.
SonarCloud integration finished for all Creadur subprojects.
ASF security integrations took place and we are ready for agentic inputs.

## Community Health:
No change - mailing list traffic remains low and discussions happen
on the PRs itself.


-----------------------------------------
Attachment R: Report from the Apache Curator Project  [Enrico Olivelli]

## Description:
The mission of Curator is the creation and maintenance of software related to
Java libraries that make using Apache ZooKeeper easier

## Project Status:
Current project status: Dormant Issues for the board: none

## Membership Data:
Apache Curator was founded 2013-09-18 (13 years ago) There are currently 16
committers and 16 PMC members in this project. The Committer-to-PMC ratio is
1:1.

Community changes, past quarter:
- No new PMC members. Last addition was Kezhu Wang on 2023-03-25.
- No new committers. Last addition was Kezhu Wang on 2023-03-24.

## Project Activity:

There is basically no activity on the project. I put the status as "Dormant".
The code base is stable and we have plenty of users and a lot of Apache
Project relying on Curator.


## Community Health:

No activity is not really a good sign about community health. We will follow
up in the PMC.


-----------------------------------------
Attachment S: Report from the Apache DataSketches Project  [Lee Rhodes]

## Description:
The mission of Apache DataSketches is the creation and maintenance of software
related to an open source, high-performance library of streaming algorithms
commonly called "sketches" in the data sciences. Sketches are small, stateful
programs that process massive data as a stream and can provide approximate
answers, with mathematical guarantees, to computationally difficult queries
orders-of-magnitude faster than traditional, exact methods

## Project Status:
Current project status: Ongoing and growing activity. Our DataSketches Library
is now available in 5 languages: Java, C++, Python, Go, Rust. And work is
progressing to add a 6th: CUDA.
Issues for the board: none

## Membership Data:
Apache DataSketches was founded 2020-12-15 (6 years ago)
There are currently 26 committers and 18 PMC members in this project.
The Committer-to-PMC ratio is roughly 7:5.

Community changes, past quarter:
- Filippo Rossi was added to the PMC on 2026-05-20
- Hyeonho Kim was added to the PMC on 2026-06-21
- Yijun Zhao was added as a committer on 2026-08-10
- Daniel Juenger was added as a committer on 2026-06-15
- Yunsong Wang was added as a committer on 2026-06-15

## Project Activity:
We had a special request from the Spark community to do a single java
release that will operate on Java 17, 21, and 25. The first part of
that was the datasketches-memory 7.0.0 release in June. A new release
of Java that works with the new memory version is in-process.

An updated version of datasketches-bigquery library was released to the
Google-BigQuery platform. This update was required due to a new
version of the enscripten compiler.

The data sketches-rust team released a 0.3.0 version on May 18.

## Community Health:
Our project is healthy. We have a small, loyal and growing community
of users that contact us when they have questions or issues. We are
experiencing growing interest from major corporations in our
multi-language libraries. The most recent corporate interest is
Nvidia, who has assigned a small team of C++/CUDA engineers to
work with us on migrating our library to CUDA.

We continue to get interest from scientists around the world who
offer ideas for new sketches for our library based on recent research
and consult with us on improving the mathematical rigor of our sketches.


-----------------------------------------
Attachment T: Report from the Apache DeltaSpike Project  [Mark Struberg]

## Description:
 Apache DeltaSpike is a suite of portable CDI (Contexts & Dependency
 Injection) extensions intended to make application development easier when
 working with CDI and Java EE.  Some of its key features include:

 - A core runtime that supports component configuration, type safe messaging
 and internationalization, and exception handling.
 - A suite of utilities to make programmatic bean lookup easier.
 - A plugin for Java SE to bootstrap various CDI containers.
 - JSF integration
 - JPA integration and transaction support.
 - A Data module, to create an easy to use repository pattern on top of JPA.
 - Testing support to allow low level unit testing of CDI enabled projects.

## Issues
 There are no immediate issues requiring board attention at this time.

## Activity
 Still low activity, but after the other EE projects got their round of
 activity boost we hopefully also see some in DeltaSpike as well in the
 next quarter.

## Recent releases:
 - 2.0.1 (JakartaEE) was released on 2025-08-11.
 - 2.0.0 (JakartaEE) was released on 2024-04-10.
 - 1.9.6 was released on 2022-04-12.


-----------------------------------------
Attachment U: Report from the Apache Doris Project  [Mingyu Chen]

## Description:
The mission of Apache Doris is the creation and maintenance of software
related to a MPP-based interactive SQL data warehousing for reporting and
analysis

## Project Status:
Current project status: Ongoing Issues for the board: No

## Membership Data:
Apache Doris was founded 2022-06-15 (4 years ago) There are currently 105
committers and 26 PMC members in this project. The Committer-to-PMC ratio is
roughly 7:2.

Community changes, past quarter:
- No new PMC members. Last addition was Calvin Kirs on 2026-04-24.
- Xin Deng was added as committer on 2026-05-20
- Yukang Lian was added as committer on 2026-08-07
- Ke Shu was added as committer on 2026-07-16
- Hui Lai was added as committer on 2026-06-02
- Sun Chenyang was added as committer on 2026-06-06
- Tiewei Fang was added as committer on 2026-07-20

## Project Activity:
Apache Doris announced five releases this quarter: 4.1.1 (May 24), 4.0.6 (June
8), 4.1.2 (June 17), 4.0.7 (July 12) and 4.1.3 (July 13). 4.0.8 is in the
release candidate stage.

We are maintaining two lines in parallel: 4.0.x is the stable line and carries
mostly bug fixes, while 4.1.x is the current feature line, where patch
releases still pick up new capabilities alongside fixes — 4.1.3, for example,
added Python UDF/UDAF/UDTF support and table-level event-driven cache warm-up.
Both lines have held a roughly monthly cadence since 4.1.0 shipped in April,
and we intend to keep that up.

Development on master remains steady: more than 1,100 commits from 88
contributors, 26 of whom made their first commit to the repository during this
period. The work clusters into a few areas:

- Lakehouse and external catalogs — Iceberg V3 default values, nested column
  schema change and position deletes; Paimon and Hive improvements; a new ADBC
  catalog.
- A rewritten native file scan path (File Scanner V2), which accounts for most
  of the quarter's performance work.
- Native execution for the VARIANT semi-structured type.
- CDC streaming jobs — OceanBase added as a source, and support for following
  upstream MySQL schema changes.
- Moving connectors and filesystems behind plugin interfaces.
- Continued work on storage-compute separation: file cache, cache warm-up and
  tablet placement.

## Community Health:
Community health is good. Six contributors were invited to become committers
this quarter, several of them among the most active contributors to the
Community health is good. Six contributors were invited to become committers
this quarter, several of them among the most active contributors to the
codebase. There were no new PMC members.

We have also moved more of the project's planning into the open. The published
roadmap (https://doris.apache.org/community/roadmap/) now carries the release
plan — 4.0 winding down this month, 4.1 in monthly maintenance, 4.2 targeted
for September and 5.0 for November — and we have adopted tracking issues on
GitHub as the unit of coordination for topic-level work. The intent is that a
newcomer can see what is being worked on and where help is wanted without
having to reconstruct it from pull request traffic. Curated "good first issue"
tickets sit alongside this as an entry point.

Doris Summit 2026 will be held online on October 21–22. The call for papers
opened on July 20 and runs through September 30, with sessions in English.


-----------------------------------------
Attachment V: Report from the Apache Drill Project  [Charles Givre]


-----------------------------------------
Attachment W: Report from the Apache Empire-db Project  [Rainer Döbele]

## Description:
Empire-db is a lightweight relational database access library dealing with all
aspects of storing, manipulating, retrieving and modelling data in relational
database management systems (RDBMS). As an alternative to traditional
OR-Mapping solutions, it provides an SQL centric, no-compromise approach that
uses a Java-Object-Model rather than Mapping Files or Annotations.

## Project Status:
Current project status: Ongoing with moderate activity
Issues for the board: None

## Membership Data:
Apache Empire-db was founded 2012-01-24 (15 years ago)
There are currently 11 committers and 10 PMC members in this project.
The Committer-to-PMC ratio is roughly 6:5.

Community changes, past quarter:
- No new PMC members. Last addition was Ralf Eichinger on 2026-04-16.
- No new committers. Last addition was Sascha Geissler on 2025-12-02.

## Project Activity:
Latest release is empire-db-3.5.0 released on 2026-07-21.
We are happy to announce that this quarter we have been able to complete
and release our latest version empire-db-3.5.0.
The release brought 10 improvements / new features and 4 bugfixes.

## Community Health:
Our community is still alive and healthy.
5 JIRA tickets opened and 13 closed in the past quarter.
The usual bunch of committers are still participating and voting.


-----------------------------------------
Attachment X: Report from the Apache EventMesh Project  [Eason Chen]


-----------------------------------------
Attachment Y: Report from the Apache Flex Project  [Harbs]


-----------------------------------------
Attachment Z: Report from the Apache Fluss Project  [Jark Wu]

## Description:

Apache Fluss is a streaming storage system built for real-time analytics
and AI, serving as the real-time data layer for Lakehouse architectures.

## Project Status:

Current project status: New, with high activity. Issues for the board: none

## Membership Data:

Apache Fluss was founded 2026-07-15 (24 days ago) There are currently 22
committers and 14 PMC members in this project. The Committer-to-PMC ratio is
roughly 3:2.

Community changes, past quarter:
- No new PMC members (project graduated recently).
- Yang Wang was added as committer on 2026-08-06

## Project Activity:

The community completed and published the Apache Fluss graduation
announcement, working with the ASF Marketing and Publicity team and updating
the project website, blog, README, and community channels to reflect the new
TLP status.

Most post-graduation tasks have been completed. This work included:

- Verifying the initial PMC roster, Chair setup, private mailing-list
  membership, and mailing-list moderation.
- Removing remaining "Incubating" references and obsolete Incubator URLs from
  project websites, documentation, repository metadata, Maven configuration,
  CI, and notification settings.
- Updating the Incubator status records to mark Fluss as graduated.
- Creating and verifying the new `/dev/fluss/` and `/release/fluss/`
  distribution areas and copying the project KEYS file.
- Updating release scripts, artifact naming, voting templates, release
  announcement templates, and the release guide for the TLP release process.

The main technical focus is now Apache Fluss 1.0. The community plans to
release it in August 2026 and is currently completing the remaining feature
development and stabilization work.

Apache Fluss also had a strong presence at Community Over Code Asia 2026.
Fluss community members Yang Wang and Yuxia Luo delivered sessions about
Fluss, while project contributors presented two additional Fluss-related
sessions. These 4 sessions helped share the project's work with the broader
Apache and open-source community.

Apache Fluss 1.0 will be the project's first release as a TLP. It will follow
the TLP release process without the `-incubating` suffix. The required release
resources, scripts, templates, distribution locations, and release
documentation have already been updated.

The most recent release was Apache Fluss 0.9.1-incubating, released on
2026-05-04.

## Community Health:

The Fluss community remains active and healthy. PMC members, committers, and
contributors have worked collaboratively on the graduation process,
post-graduation migration, community outreach, and preparation for the 1.0
release.

Mailing-list activity during the past quarter was:

- `dev@fluss.apache.org`: 375 emails, an 8% decrease from 406 in the previous
  quarter.
- `issues@fluss.apache.org`: 3,259 emails, a 28% decrease from 4,476.
- `user@fluss.apache.org`: 2 emails, an 89% decrease from 18.

The decreases on the development and issues mailing lists do not indicate a
community health concern. The reporting period overlapped with the summer
vacation season, which is typically quieter because many community members
take extended leave. At the same time, the community devoted substantial
effort to graduation, post-graduation migration, and preparation for the 1.0
release.

With most graduation-related work now complete, the community has shifted its
focus back to completing the remaining features and stabilizing Apache Fluss
1.0. This renewed focus is already reflected in development activity: traffic
on the dev mailing list increased from 70 emails in June to 129 in July, an
increase of approximately 84%. Issue and pull-request activity is also
expected to grow as the release approaches.

The user mailing list has a small absolute message volume and is primarily
used by community members for announcements. Most Fluss users currently ask
questions and interact with the community through Slack instead of the mailing
list.

The project's recorded monthly community calls provide another sign of growing
engagement. The latest call attracted approximately 30 participants despite
the summer vacation period, and participation has increased over the past
several months as more people have started engaging with the project.

The Fluss LinkedIn page has also grown to approximately 2,300 followers within
its first year; July 2026 marked the first anniversary of the page's creation.

The addition of a new committer, the growing participation in monthly
community calls, the project's expanding social-media reach, and the
community's presence at Community Over Code Asia 2026 provide further signs of
continued participation and growth.

Overall, the PMC sees no concerns regarding community health. The observed
changes in mailing-list traffic reflect the quieter summer period, a temporary
shift in project focus, and the community's current communication-channel
preferences rather than a reduction in project activity.


-----------------------------------------
Attachment AA: Report from the Apache FreeMarker Project  [Dániel Dékány]

## Description:

Apache FreeMarker is a template engine, i.e. a generic tool to generate text
output based on templates. Apache FreeMarker is implemented in Java as a class
library for programmers.

FreeMarker 2 (the current stable line) produces releases since 2002. The
FreeMarker project has joined the ASF in 2015, and graduated from the
Incubator in early 2018.

## Issues:

There are no issues requiring board attention at this time.

## Activity:

Activity was very low in recent months.

## Health report:

Activity was very low in recent months, though that's not unusual for this
project. User questions and new Jira issues are still being answered. Most
PR-s slowly but eventually getting reviewed and merged. Infrastructure
maintenance is done (such as recent fix of try.freemarker.apache.org
certificate).

Voting on the 2.3.35 release has just started.

Next goal is finishing the java.time support (FREEMARKER-35) that's there for
years, but never received the final push. Another next goal is to work towards
2.4.0, that removes some hystorical baggage that make development/build more
complicated, while almost nobody depends on them anymore, but are still not
100% backward compatible to get rid of (the long abandoned Jython support, the
pre-SLF4J/JCL logging layer, the separate Google App Engine compliant version,
etc.). The even longer term goal is continuing the development on the 3.0
branch, so that the project can innovate, and the code base can become more
modern and attractive for committers.

## PMC changes:

 - Currently 9 PMC members.
 - Last added on 2025-01-01

## Committer base changes:

 - Currently 12 committers.
 - Last added (non-PMC): Siegfried Goeschl on 2020-01-07

## Releases:

 - 2.3.34 was released on 2024-12-22 (2.3.35 voting is ongoing)


-----------------------------------------
Attachment AB: Report from the Apache Geode Project  [Mark Bretl]

## Description:
The mission of Apache Geode is the creation and maintenance of software related
to a data management platform that provides real-time, consistent access to
data-intensive applications throughout widely distributed cloud architectures.

## Project Status:
Current project status: Ongoing
Issues for the board: None

## Membership Data:
Apache Geode was founded 2016-11-15 (10 years ago)
There are currently 126 committers and 34 PMC members in this project.
The Committer-to-PMC ratio is roughly 8:3.

Community changes, past quarter:
- No new PMC members. Last addition was Leon Finker on 2026-04-22.
- No new committers. Last addition was Yuwei Chang on 2026-04-28.

## Project Activity:
There have been no software releases in the past quarter, however, commits
have been made to fix issues, so there is activity on the code base. November
2026 does make it 10 years that Geode has been an Apache Project.

## Community Health:
There is a general decline in community activity, most of it is related to
having no releases since the past report in May 2026. It is concerning that
there is decline, as the project did have a good run of consecutive releases.
The project does have enough members on the roster, however, some releases do
struggle to get enough votes due to not getting enough people to vote.


-----------------------------------------
Attachment AC: Report from the Apache Geronimo Project  [Jean-Louis Monteiro]


-----------------------------------------
Attachment AD: Report from the Apache Grails Project  [James Fredley]

## Description:
The mission of Apache Grails is the creation and maintenance of software
related to the development of a powerful Groovy-based web application framework
for the JVM built on top of Spring Boot

## Project Status:
Current project status: Ongoing
Issues for the board: None

## Membership Data:
Apache Grails was founded 2025-09-23 (a year ago)
There are currently 18 committers and 13 PMC members in this project.
The Committer-to-PMC ratio is roughly 9:7.

Community changes, past quarter:
- No new PMC members. Last addition was Thomas Rasmussen on 2026-01-19.
- Gianluca Sartori was added as committer on 2026-08-05

## Project Activity:
CORE-7.0.15 was released on 2026-08-06.
CORE-7.1.5 was released on 2026-08-06.
CORE-7.2.2 was released on 2026-08-06.
CORE-8.0.0-M5 was released on 2026-08-06.
ACTIONS-1.0.3 was released on 2026-07-24.
CORE-8.0.0-M4 was released on 2026-07-24.
GRAILS-PUBLISH-1.0.0-M2 was released on 2026-07-24.
CORE-7.0.14 was released on 2026-07-14.
CORE-7.1.4 was released on 2026-07-14.
CORE-7.2.1 was released on 2026-07-14.
CORE-8.0.0-M3 was released on 2026-07-14.
CORE-8.0.0-M2 was released on 2026-07-05.
CORE-7.0.13 was released on 2026-07-04.
CORE-7.1.3 was released on 2026-07-04.
CORE-7.2.0 was released on 2026-07-04.
CORE-7.0.12 was released on 2026-06-22.
CORE-7.1.2 was released on 2026-06-22.

## Community Health:
The project is more active than it has been in around a decade.  The Grails 8
release will be larger than 7 and the largest to date.  There will be four
Apache Grails presentations at Community over Code and it will be the largest
gathering of Grails committers and users in many years.


-----------------------------------------
Attachment AE: Report from the Apache Groovy Project  [Paul King]

## Description:
Apache Groovy is responsible for the evolution and maintenance of the Groovy
programming language

## Project Status:
Current project status: Ongoing with moderate activity
Issues for the board: None

## Membership Data:
Apache Groovy was founded 2015-11-18 (11 years ago)
There are currently 25 committers and 14 PMC members in this project.
The Committer-to-PMC ratio is roughly 7:4.

Community changes, past quarter:
- No new PMC members. Last addition was Jonny Carter on 2025-12-02.
- Björn Kautler was added as committer on 2026-08-06

## Project Activity:
6.0.0-beta-1 was released on 2026-08-04.
4.0.33 was released on 2026-08-01.
5.0.8 was released on 2026-08-01.
6.0.0-alpha-2 was released on 2026-07-04.
5.0.7 was released on 2026-07-03.

## Community Health:
There was an uptick in community activity in the last quarter.
245 JIRA tickets opened and 243 closed in the past quarter.

We just released our first beta version of Groovy 6.
We are excited by the many features this new version of Groovy offers.
It includes features that AI agents have requested from a programming
language to make Groovy a very efficient language to reason about once
agents are trained on its latest features.

We look forward to contributing to the Community over Code Glasgow
conference in October. An excellent select of talks has been accepted
for the Groovy Track covering Groovy, Geb and Grails among other topics
in the broader Groovy ecosystem.


-----------------------------------------
Attachment AF: Report from the Apache Hop Project  [Hans Van Akelyen]

## Description:
The mission of Apache Hop is the creation and maintenance of software related
to a platform for data orchestration

## Project Status:
Current project status: Ongoing
Issues for the board: none

## Membership Data:
Apache Hop was founded 2021-12-15 (5 years ago)
There are currently 24 committers and 10 PMC members in this project.
The Committer-to-PMC ratio is roughly 2:1.

Community changes, past quarter:
- No new PMC members. Last addition was Bart Maertens on 2021-12-15.
- No new committers. Last addition was Sergio De Lorenzis on 2024-06-11.

## Project Activity:
We are working on our next release 2.19.0, which will be our biggest release
ever. We have also decided to do a rotating chair position and will move the
Chair position to Bart Maertens. We will rotate every two years.
We are currently also in the progress of adding a new committer.

## Community Health:
We are seeing an increase of first time contributors, and AI assisted
contributions. Mail volume on dev@ and issues@ has gone up, mainly because of
increase in development activities and cleanup effort of the backlog. users@
has gone down, this relates to less discussions in GitHub


-----------------------------------------
Attachment AG: Report from the Apache HTTP Server Project  [Joe Orton]

## Description:
The mission of HTTP Server is the creation and maintenance of software related
to Apache Web Server (httpd)

## Project Status:
Current project status: ongoing, moderate
Issues for the board: none

## Membership Data:
Apache HTTP Server was founded 1995-02-27 (31 years ago)
There are currently 129 committers and 58 PMC members in this project.
The Committer-to-PMC ratio is roughly 9:4.

Community changes, past quarter:
- Vladimír Chlup was added to the PMC on 2026-06-23
- Michael Osipov was added to the PMC on 2026-06-01
- Vladimír Chlup was added as committer on 2026-06-22
- Michael Osipov was added as committer on 2026-06-01

## Project Activity:
The "vulnpocalypse" which started around February/March this year has
continued unabated into the current quarter. I reported in May that the
project was struggling to cope with the flow of security reports. We have made
improvements on a number of fronts, but I would say we are still struggling.
For avoidance of doubt - I still see this as a challenge which the project has
to resolve, not a concern for the board. Starting with the positives:

* With huge thanks to the work of the Security team - we now have access to
  much better report tracking with the new dashboard allowing us to see
  pending and triaged reports in a single place. The security team are also
  doing a great job acting as "level 1 support" for the incoming queue.

* We have made improvements in automation around the CVE process and patch
  handling which reduce some of the pain and manual effort required. We also
  published a security model, a first line of defence against low-severity
  (and/or quality) reports; the security team are also able to triage directly
   against this.

* The project voted to allow Low severity security issues to be resolved
  outside of the normal non-public process via direct, obfuscated, commits,
  which will again reduce the overhead of dealing with a significant
  percentage of the incoming reports.

* We shipped httpd 2.4.68 with 13 more CVEs resolved, all rated Low or
  Moderate severity.

However:

* the number of committers doing triage remains small, and the rate of
  incoming reports exceeds the rate we are resolving them, resulting in a
  ever-growing backlog.

* we have a quite large, old codebase, with many areas suffering from poor
  test coverage, this increases the risk of regressions from making
  significant changes addressing the more complex issues.

Working through the security reports, patches and release preparation took
most of our focus in the last quarter. Thanks to an incredible effort by Jim
Jagielski, the entire Perl-based test suite was converted to Python and
imported to trunk - which now should have a much lower barrier to entry.

Michael Osipov and Vladimír Chlup were both voted in as new committers and
onto the PMC.

## Community Health:
The strong flow of GitHub PRs from non-committers continues, including many
"hardening" fixes in the last quarter. Mailing list activity was mostly
around the release, release preparation, cleaning up CI and the process
changes discussed above.


-----------------------------------------
Attachment AH: Report from the Apache HttpComponents Project  [Michael Osipov]

## Description:
The mission of HttpComponents is the creation and maintenance of software
related to Java toolset of low level HTTP components

## Project Status
- There are no issues requiring board attention at this time.

## Membership Data:
Apache HttpComponents was founded 2007-11-14 (18 years ago)
There are currently 20 committers and 9 PMC members in this project.
The Committer-to-PMC ratio is roughly 5:3.

Community changes, past quarter:
- No new PMC members. Last addition was Arturo Bernal on 2023-10-27.
- No new committers. Last addition was Arturo Bernal on 2023-06-20.

## Project Activity:
 - Development on master is 5.7 for Client and 5.5 for Core

## Community Health:
 - Overall the project remains active. Issues and discussions are
   resolved in time.

## Releases:
- HttpClient 5.6.3 GA: 2026-07-31
- HttpClient 5.6.2 GA: 2026-06-30
- HttpCore 5.4.3 GA: 2026-06-25
- HttpCore 5.5-beta2: 2026-06-25
- HttpCore 5.5-beta1: 2026-06-05


-----------------------------------------
Attachment AI: Report from the Apache Ignite Project  [Dmitry Pavlov]

## Description:
The mission of Ignite project is the creation and maintenance of software
related to high-performance distributed database engine providing in-memory
and persistent data caching, partitioning, processing, and querying
components.

## Project Status:
Current project status: Ongoing
Issues for the board: none

## Membership Data:
Apache Ignite was founded 2015-08-19 (11 years ago) There are currently 81
committers and 42 PMC members in this project. The Committer-to-PMC ratio is
roughly 7:4.

Community changes, past quarter:
- No new PMC members. Last addition was Evgeny Stanilovsky on 2026-03-07.
- Dmitry Werner was added as committer on 2026-07-09

## Project Activity:
Ignite 2.x:
 - SQL/Calcite gained SELECT FOR UPDATE, window functions, extensible
   aggregates, and correctness fixes.
 - The main code effort - modernized messaging and serialization, reducing
   maintenance costs and enabling safer protocol evolution.
 - Multi-DC resilience and CI stability improved.

Ignite 3.x:
- No changes were merged; the default branch has been unchanged since April
  23, 2026.

## Community Health:
- dev@ traffic decreased by 39%, while discussions covered Java 17, ending JDK
  11 support, tracing removal, and transactional SQL.
- One new committer joined, and prospective contributors requested onboarding.
- Activity remains concentrated in Ignite 2.x. Restoring Ignite 3 development
  and broadening participation are the main concerns.


-----------------------------------------
Attachment AJ: Report from the Apache Impala Project  [Zoltán Borók-Nagy]

## Description:
The mission of Apache Impala is the creation and maintenance of software
related to a high-performance distributed SQL engine

## Project Status:
Current project status: Ongoing with high activity

Issues for the board: None

## Membership Data:
Apache Impala was founded 2017-11-15 (9 years ago)
There are currently 72 committers and 42 PMC members in this project.
The Committer-to-PMC ratio is roughly 3:2.

Community changes, past quarter:
- Stephen Carlin was added to the PMC on 2026-07-31
- No new committers. Last addition was Noémi Pap-Takács on 2025-03-12.

## Project Activity:
- Apache Calcite planner integration
- Apache Iceberg V3 support
- New type-system work: VARIANT, UUID
- Histogram-Based Optimization
- Kubernetes operator and Helm chart support
- OpenTelemetry integration
- Lineage improvements for UPDATE/MERGE statements
- Event-processing scalability

## Community Health:
reviews@ is the most reliable metric of Impala community activity level.
There were 4250 emails to that list in June, July,
and August (until 4th)


-----------------------------------------
Attachment AK: Report from the Apache Incubator Project  [Justin Mclean]

# Incubator PMC report for August 2026

The Apache Incubator is the entry path into the ASF for projects and
codebases wishing to become part of the Foundation's efforts.

There are currently 24 podlings under incubation. In July, the Incubator
made six releases, and a release vote for one podling is currently
underway. There were no additions or removals to IPMC membership.

Two podlings graduated in July: Apache Fluss and Apache Pony Mail, after
incubating since 2016. A vote to graduate Apache ResilientDB is currently
underway following an extended discussion on the general list.

Mailing list discussion otherwise focused on release voting, the
ResilientDB graduation, and an experimental AI concierge skill for
answering Incubator questions.

Casbin's first release candidate passed its dev list vote and came before
the IPMC, where it received a binding -1 due to signing, checksum, and
license header issues; the vote was canceled, and a second candidate is
being prepared. The podling has stopped publishing snapshot CI builds in
favor of properly voted releases. The IP clearance questions raised last
month have been resolved.

OpenServerless has still not made an ASF release despite over two years of
incubation, although development activity remains high. Encouragingly, the
community began discussing its first source release on its dev list in late
July, with mentors providing guidance on the ASF release process. The IPMC
hopes to see a release candidate and vote follow.

Pegasus, incubating since 2020, has had no release in over 12 months and
its activity has dropped to near zero, with no dev list traffic in July and
a single active committer in the past quarter. The IPMC will follow up with
the podling and its mentors.

PouchDB has now passed 12 months of incubation without an ASF release.
Commit activity continues, but its dev list was silent in July, and it has
yet to correct the redirection of the legacy pouchdb.com site.

XTable, which had gone over 12 months without a release, attempted one in
July. The vote on a 0.4.0-incubating release candidate was canceled due to
a source build failure and license documentation issues; a second candidate
is expected once these are resolved.

Toree continues to show very low activity, with no dev list traffic in
July, two commits over the past quarter, and no visible progress on the
release candidate prepared in May.

GeaFlow made its 0.8.0-incubating release in late June, but overall
activity has contracted sharply over the past quarter, with development now
down to one or two active committers and little dev list discussion; this
will be watched.

The IPMC continues to monitor long-running podlings and will follow up on
any community concerns as needed.

When submitted 3 podlings (cloudberry, graphar, pegasus) did not have
mentor sign-off; they been notified and will hopefully sign off before the
board meeting

## Community

### New IPMC members:
- none

### People who left the IPMC:
- none

## New Podlings
- none

## Podlings that failed to report, expected next month
- None

## Graduations
- Fluss
- Pony Mail

  The board has motions for the following:

- None

## Releases

The following releases entered distribution during the month of
July:
- Auron 8.0.0-incubating
- GeaFlow 0.8.0-incubating
- Hamilton (contrib) 0.0.9-incubating
- Hamilton (lsp) 0.2.0-incubating
- Hamilton (sdk) 0.9.0-incubating
- Hamilton (ui) 0.0.18-incubating

## IP Clearance
- none

## Legal / Trademarks
- N/A

## Infrastructure
- N/A

## Table of Contents
[Amoro](#amoro)
[Burr](#burr)
[Casbin](#casbin)
[Cloudberry](#cloudberry)
[Fesod](#fesod)
[GeaFlow](#geaflow)
[GraphAr](#graphar)
[Hamilton](#hamilton)
[Pegasus](#pegasus)
[Seata](#seata)
[Texera](#texera)
[Toree](#toree)
[XTable](#xtable)

--------------------
## Amoro

Amoro is a Lakehouse management system built on open data lake formats like
Apache Iceberg and Apache Paimon.

Amoro has been incubating since 2024-03-11.

### Three most important unfinished issues to address before graduating:

1. Fix possible and potential security vulnerability issues.
2. Release more versions under ASF.
3. Initiate the discussion on graduating from the ASF Incubator and
complete some preparatory work.

### Are there any issues that the IPMC or ASF Board need to be aware of?

Currently no.

### How has the community developed since the last report?

* Added 3 new contributors
* Jinsong and ZhuoJun presented technical practices related to Apache Amoro
at Community Over Code Asia 2026.

### How has the project developed since the last report?

* Merged 40+ PRs.
* Releasing 0.9.0-incubating, the release vote is currently underway on the
dev mailing list.

### How would you assess the podling's maturity?
Please feel free to add your own commentary.

- [ ] Initial setup
- [ ] Working towards first release
- [ ] Community building
- [X] Nearing graduation
- [ ] Other:

### Date of last release:

* 2025-09-11, released Amoro 0.8.1-incubatiing

### When were the last committers or PPMC members elected?

* 2026-01-07, committer:Fei Wang(turboFei)

### Have your mentors been helpful and responsive?

Yes, Amoro's mentors actively participate in the project, contribute
insights, and help advance the project towards graduation.

### Is the PPMC managing the podling's brand / trademarks?

No Answer

### Signed-off-by:

- [X] (amoro) Justin Mclean
   Comments:
- [ ] (amoro) Zhongyi Tan
   Comments:
- [ ] (amoro) Yu Li
   Comments:
- [X] (amoro) Xinyu Zhou
   Comments:
- [ ] (amoro) Kent Yao
   Comments:

### IPMC/Shepherd notes:

[PJF] there are a number of issues on the private mailing list that have
not been addressed even after multiple months.

--------------------
## Burr

Burr is a lightweight in-process python framework that standardizes the
expression and execution of state machines as action-driven graphs, while
making graph             execution easily observable. It is particularly
suited for AI agent workflows,             simulations, and other dynamic
systems, and comes with a self-hostable observability UI             that
integrates with OpenTelemetry.

Burr has been incubating since 2025-05-24.

### Three most important unfinished issues to address before graduating:

1. Build release knowledge & ability through PPMC.
2. Build community
3. Build roadmap

### Are there any issues that the IPMC or ASF Board need to be aware of?
No.

### How has the community developed since the last report?
Was on the front page of hackernews - drove some discord joins.

### How has the project developed since the last report?
Added new PPMC member.

### How would you assess the podling's maturity?
Please feel free to add your own commentary.

- [X] Initial setup
- [X] Working towards first release
- [-] Community building
- [ ] Nearing graduation
- [ ] Other:

### Date of last release:

2026-05-09

### When were the last committers or PPMC members elected?
2026-05-22

### Have your mentors been helpful and responsive?
N/A

### Is the PPMC managing the podling's brand / trademarks?
N/A

### Signed-off-by:

- [ ] (burr) Kevin Ratnasekera
   Comments:
- [X] (burr) Ayush Saxena
   Comments:
- [X] (burr) PJ Fanning
   Comments:
- [ ] (burr) Jarek Potiuk
   Comments:

### IPMC/Shepherd notes:

--------------------
## Caldera

Caldera provides a modular platform for modeling, scripting, and executing
adversary behavior. It allows users to construct emulation plans, provides
agents for             communicating with the command and control server,
and enables users to evaluate             security detections in a
structured, scalable, and repeatable way. With the use of             plug-
ins and community-contributed features, Caldera supports a range of use
cases             including adversary emulation, purple teaming, detection
engineering, and continuous             security validation. Using Caldera,
defenders can emulate known threat actor behavior             and perform
other red team activity to evaluate their organization’s defensive
capabilities, test analytics, and find detection gaps. As a modular tool
based on the             MITRE ATT&CK framework, Caldera is designed to be
extensible, intelligence-driven,             and automation-friendly.

Caldera has been incubating since 2025-12-19.

### Three most important unfinished issues to address before graduating:

1. Community Growth
2. Grow the PPMC

### Are there any issues that the IPMC or ASF Board need to be aware of?
No.

### How has the community developed since the last report?
Petitioned for an additional PPMC member; in process of vetting and voting
on them.
Github Stars are over 7.2k.

### How has the project developed since the last report?
We had 4 new PRs merged and closed on GitHub. Added .asf.yml and NOTICE
files to repo. Updated README file. Updated submodule pin references for
plugins. We handled 3 software library version updates.

### How would you assess the podling's maturity?
Please feel free to add your own commentary.

- [X] Initial setup
- [ ] Working towards first release
- [X] Community building
- [ ] Nearing graduation
- [ ] Other:

### Date of last release:

No Apache release yet.

### When were the last committers or PPMC members elected?
At founding/incubation.

### Have your mentors been helpful and responsive?
Yes.

### Is the PPMC managing the podling's brand / trademarks?
Finalizing third-party references and branding references,
including documentation and website references as well as plugin
repository
mentions and references.

### Signed-off-by:

- [ ] (caldera) Kevin Ratnasekera
   Comments:
- [X] (caldera) Francis Chuang
   Comments: Steady progress is being made.
- [X] (caldera) PJ Fanning
   Comments:
- [ ] (caldera) Gordon King
   Comments:

### IPMC/Shepherd notes:

--------------------
## Casbin

Casbin is a powerful, efficient open-source access control framework that
provides a unified, model-driven approach to authorization. Built on the
PERM (Policy, Effect, Request, Matchers) metamodel and its domain-specific
language, Casbin brings ACL, RBAC, and ABAC together under one model so
that policies can be expressed flexibly and enforced at a fine-grained
level. It offers high-performance enforcement and a broad multi-language
ecosystem spanning Go, Java, Node.js, Python, .NET, C++, and Rust.

Casbin has been incubating since 2026-02-07.

### Three most important unfinished issues to address before graduating:

1. Complete the first official Apache incubating release.
2. Clarify repository scope, release plans, and IP/grant coverage for the
large set of Casbin repositories under the Apache GitHub organization.
3. Continue building a diverse, public, mailing-list-centered community and
keep project decisions visible on dev@casbin.apache.org.

### Are there any issues that the IPMC or ASF Board need to be aware of?

No new issues require special attention from the IPMC or ASF Board at this
time. The podling is addressing the release-compliance findings from RC1
and is preparing RC2. The review of repository scope and IP/grant coverage
remains ongoing with mentor and IPMC guidance.

### How has the community developed since the last report?

- dev@ had 8 messages across 4 threads, with 4 participants.
- The public dev list continued to carry Incubator report review and
discussion about repository scope and IP/grant coverage.
- Participation remained concentrated among existing contributors.
Broadening the active contributor and discussion base remains a community
priority.
- The main apache/casbin repository reached about 20.3k GitHub stars.

### How has the project developed since the last report?

- Across 239 tracked Casbin Apache GitHub repositories, 6 PRs were merged
and 0 issues were closed from 2026-07-01 to 2026-07-31. All six merged PRs
were in the Go core repository, apache/casbin.
- The merged work focused on NOTICE and DISCLAIMER corrections, migration
to standard ASF license headers, accounting for a bundled MIT-licensed
configuration file, and adding a project-specific Apache RAT policy.
- The resulting source-archive policy was validated with Apache RAT 0.18 at
zero unapproved or unknown files, and tests passed both in the repository
and from a clean source archive.
- RC1 was cancelled after the binding IPMC review. The release remains in
RC2 preparation, and no new release vote had opened by the end of July.

### How would you assess the podling's maturity?

The podling is actively learning and applying the ASF release process. The
first IPMC release review exposed compliance gaps that are being addressed,
while community participation remains concentrated and needs to broaden.
The podling is not yet nearing graduation.

- [X] Initial setup
- [X] Working towards first release
- [X] Community building
- [ ] Nearing graduation
- [ ] Other:

### Date of last release:

No official Apache release yet.

### When were the last committers or PPMC members elected?

2026-02-07

### Have your mentors been helpful and responsive?

Yes. Mentors and IPMC members have provided detailed, actionable feedback
on release compliance, repository scope, and IP/grant coverage.

### Is the PPMC managing the podling's brand / trademarks?

The project name has been approved in PODLINGNAMESEARCH-251. The PPMC is
continuing to review release, website, and repository materials for Apache
branding and trademark requirements.

### Signed-off-by:

- [ ] (casbin) Hao Ding
   Comments:
- [X] (casbin) Huajie Wang
   Comments:
- [X] (casbin) Hulk Lin
   Comments:
- [ ] (casbin) Jerry Shao
   Comments:
- [X] (casbin) Zili Chen
   Comments:

### IPMC/Shepherd notes:

[PJF] There are a number of open issues on the private mailing list where
the issues have been open for many months.

--------------------
## Cloudberry

 Apache Cloudberry is an advanced and mature open-source Massively Parallel
Processing (MPP) database, derived from the last open-source version of the
Greenplum Database® but built on a more modern PostgreSQL kernel and with
more advanced enterprise capabilities. Cloudberry can serve as a data
warehouse and can also be used for large-scale analytics and AI/ML
workloads.

Cloudberry has been incubating since 2024-10-11.

### Three most important unfinished issues to address before graduating:

1. Grow the contributor and community to ensure long-term sustainability.
2. Publish a few more Apache releases following the ASF release processes.

### Are there any issues that the IPMC or ASF Board need to be aware of?

No issues.

### How has the community developed since the last report?

- The community continued its public bi-weekly meetings, holding six
meetings from May through July 2026. Discussions covered the PostgreSQL 16
kernel upgrade, release coordination, CI and packaging, ecosystem projects,
documentation, community governance, and open technical topics.
- New Committers: Anton Kurochkin (@woblerr) and Liu Shengsong
(@lss602726449) were announced as new committers on June 26 and July 6,
respectively.
- Contributors and community participation continued to grow through work
on the main repository and related ecosystem projects. The community also
discussed new Kubernetes operators and the creation of an Apache Cloudberry
Command Center repository.
- Community governance and responsible AI use continued to receive
attention. The community discussed the AI guideline and the use of
AI-assisted code review tools, with AI-assisted code review tools, such as
GitHub Copilot, were discussed as optional review suggestions subject to
normal community review.
- Events and outreach:
  - Community Over Code Asia 2026: Seven Cloudberry-related talks, a
Cloudberry booth: https://s.apache.org/knmjs
  - Saint Highload 2026: our PPMC member Leonid Borchuk presented a
session on PAX: https://s.apache.org/re82o

### How has the project developed since the last report?

- PostgreSQL kernel upgrade and core development:
  - Merged the PostgreSQL 16 kernel upgrade into the `main` branch with
5730 commits. The remaining FIXME items are planned to be addressed as part
of the future 3.0 release.
  - Started discussion about a future kernel upgrade from PostgreSQL 16
to PostgreSQL 18.
  - Continued PostgreSQL 14.x maintenance on the 2.x stable branch,
including work to backport 14.8 and archive-related fixes.
  - Added security fixes for several CVEs and continued dependency and
security maintenance across the repositories.
  - New extensions:
    - Added the `gp_relsizes_stats` extension.
    - Introduced the `yezzey` extension for the 2.x stable branch as a
submodule.
    - Added the `TRY_CONVERT` extension.
    - Added the `reject_partition_fullscan` extension.
  - Continued ORCA and planner improvements, including fixes for CTE
handling, intra-segment parallel table scans, HAVING and grouping-set
handling, non-ASCII column aliases, empty-partition statistics, outer-join
predicate pushdown, and other correctness and stability issues.
- datalake_fdw: Started implementing Iceberg support in the
`datalake_fdw`.
- Ecosystem and sub-repositories:
  - `cloudberry-pxf`:
    - Continued the 2.2 release plan.
    - Added Java 21 support, upgraded the Gradle wrapper, updated HBase
and Log4j dependencies, improved S3-related Testcontainers coverage, and
added session and command-count information to logging context.
    - Applied security and dependency updates and restored green CI
testing.
  - `cloudberry-backup`:
    - Completed the Go 1.25 upgrade and continued PostgreSQL 16 support
work.
    - Pinned the CI branch to Cloudberry 2.x stable branch and applied
dependency updates to address security alerts.
    - Added the `gpbackup_exporter` Prometheus exporter for the backup
history database.
  - `cloudberry-go-libs`:
    - Added a new CI/CD workflow and completed the ASF compliance work.
The project is ready for the 2.2 release.
  - Other ecosystem work:
    - `WAL-G` added support for PAX incremental backups.
    - `Odyssey` 1.5.1 was released, and Odyssey support was documented on
the Cloudberry website.
    - Community members developed Kubernetes operators for Cloudberry.
    - Yandex Cloud plans to donate the `Command Center` project to Apache
Cloudberry - https://s.apache.org/urvsc
- Release, CI, and packaging:
  - Release:
    - Provided the convenience packages for 2.1 release.
    - Started preparing Apache Cloudberry (Incubating) 2.2.0. By the end
of July, the release was considered ready to enter the release process,
with remaining work including cherry-picking changes to `REL_2_STABLE`, and
finalizing PXF Rocky Linux 10 support.
    - Created the release runbook wiki page for the release manager.
  - CI workflows:
    - Added Rocky Linux 10 workflow support.
    - Completed the CI consolidation work from OS-specific CI workflows
into matrix-based workflows for easier maintenance and future platform
expansion.
    - Bumped the Go version to 1.25 in the development Docker images and
CI workflows.
    - Planned to add a macOS CI workflow.
  - Packaging:
    - Improved RPM packaging for the core repository, including custom
installation prefixes and support for installing multiple major versions
side by side.
    - Merged the source-release-based convenience packages workflow for
the main repository, `cloudberry-backup` and `cloudberry-pxf` for the
coming 2.2+ releases.
- Website and documentation:
  - Upgraded the website to Docusaurus 3.10.2 and continued UI
improvements.
  - Added the “Powered by” page and integrated `cloudberry-pxf`
documentation into the main website.
  - Added a project history page and ecosystem documentation for
`Odyssey` and `WAL-G`.
  - Added a new page on backward-incompatible changes from Greenplum 6.x.
  - Refreshed the deployment guide.
  - Published five new blog posts to share the latest community news.

### How would you assess the podling's maturity?
Please feel free to add your own commentary.

- [ ] Initial setup
- [ ] Working towards first release
- [X] Community building
- [X] Nearing graduation
- [ ] Other:

### Date of last release:

- April 14, 2026 - Apache Cloudberry (Incubating) 2.1.0

### When were the last committers or PPMC members elected?

- June 22, 2026 - Anton Kurochkin (woblerr) was announced as a new
committer.
- July 6, 2026 - Liu Shengsong (@lss602726449) was announced as a new
committer.

### Have your mentors been helpful and responsive?

Yes.

### Is the PPMC managing the podling's brand / trademarks?

Yes.

### Signed-off-by:

- [ ] (cloudberry) Roman Shaposhnik
   Comments:
- [ ] (cloudberry) Willem Ning Jiang
   Comments:
- [ ] (cloudberry) Kent Yao
   Comments:

### IPMC/Shepherd notes:

--------------------
## Fesod

Fesod is a high-performance and memory-efficient Java library for reading
and writing Excel files, designed to simplify development and ensure
reliability.

Fesod has been incubating since 2025-09-17.

### Three most important unfinished issues to address before graduating:

1. Ensure that the website and codebase are fully compliant with ASF
policies.
2. Add more core contributors.
3. Get more focused on building community.

### Are there any issues that the IPMC or ASF Board need to be aware of?

No.

### How has the community developed since the last report?

1. We have voted and approved two new committers.
2. There five new contributors joined project and contribute some good
features.
3. Shuxin Pan will represent Fesod in one accepted session at Community
Over code Asia 2026.
4. We actively communicate with relevant security reporters, striving to
ensure the reliable and security.

### How has the project developed since the last report?

1. We released a fix version (2.0.2-incubating) in May to address
CVE-2026-49328.
2. Overall project development is proceeding smoothly, with no obstacles
hindering our progress.
3. We are currently finalizing details for the second official release,
scheduled for mid-August.
4. Regarding the vulnerability, we have confirmed the remediation details
with the reporter and the ASF security team
   via the private mailing list.

### How would you assess the podling's maturity?

- [ ] Initial setup
- [ ] Working towards first release
- [X] Community building
- [ ] Nearing graduation
- [ ] Other:

### Date of last release:

2026-05-28

### When were the last committers or PPMC members elected?

2026-04-22

### Have your mentors been helpful and responsive?

Yes, we truly thanks our mentors' helpful suggestions.

### Is the PPMC managing the podling's brand / trademarks?

Not aware of any issues.

### Signed-off-by:

- [X] (fesod) tison
   Comments:
- [X] (fesod) Dave Fisher
   Comments:
- [X] (fesod) Huajie Wang
   Comments:
- [X] (fesod) PJ Fanning
   Comments:

### IPMC/Shepherd notes:

--------------------
## GeaFlow

GeaFlow is a streaming graph computing engine for distributed,
large-scale, real-time graph storage and analysis. It supports
large-scale graph storage, hybrid graph and table processing,
real-time and offline graph computing, and interactive graph analysis.
The community is also developing Graph Memory as infrastructure for
agent memory.

GeaFlow has been incubating since 2025-06-06.

### Three most important unfinished issues to address before graduating:

1. Broaden the contributor and committer base across organizations and
   regions.

2. Keep review and triage timely as first-time contributions increase.

3. Maintain a predictable release cycle and high project stability.

### Are there any issues that the IPMC or ASF Board need to be aware of?
No.

### How has the community developed since the last report?

Since May, the community has focused on making the path into the project
clearer without lowering review standards. It published 13 good first
issues with context, reference code, test guidance, and explicit
acceptance criteria. These issues have attracted contributions from both
first-time and returning contributors. Maintainers are holding
concentrated review rounds, giving specific feedback, and resolving
overlapping implementations in public based on correctness and
maintainability.

In July, the PPMC initiated a committer nomination and vote for Xinyuan
Chen (GitHub: kitalkuyo-gita), based on sustained contributions to graph
algorithms, ISO-GQL, design discussions, and reviews of other
contributors. Xinyuan was also recognized as a 2025 Apache Doris
Community MVP.

The community is participating in Open Source Promotion Plan 2026,
GitLink Programming Summer Camp, and the Open Source Academy program.
Mentored projects cover GraphRAG, hybrid graph-text-vector retrieval, and
graph-native memory. Students use the normal issue, discussion, review,
and test process, with the goal of continuing as community contributors
after the programs end.

Litao Lin, Xinyuan Chen and Yao Zhongqiang will represent GeaFlow in
three accepted sessions at Community Over Code Asia 2026. The sessions
are in the Data + AI, Streaming, and Incubator tracks and cover agent
memory, streaming memory, and GeaFlow's incubation and technical
practice.

### How has the project developed since the last report?

The 0.8.0-incubating source release entered distribution on June 10 and
was announced on July 3. It is the second community release since
GeaFlow entered the Apache Incubator.

The release added vector storage and retrieval, Graph Memory and AI
components, graph algorithms, more ISO-GQL predicates, and new or
improved connectors. It also improved JDK 8 and JDK 11 build profiles
and release tooling. The release removed bundled Category-X MySQL JDBC
artifacts and other non-source content from the source distribution.

Merged PRs added math and date functions, a Doris connector, graph
algorithm regression tests, and safer cluster exception tests. Open
work includes MongoDB, ClickHouse, and Redis connectors, a SQLite store,
graph algorithms, SQL functions, ISO-GQL support, and an incremental
resident keyword index for AI search.

### How would you assess the podling's maturity?

Please feel free to add your own commentary.

- [ ] Initial setup
- [ ] Working towards first release
- [X] Community building
- [ ] Nearing graduation
- [ ] Other:

### Date of last release:

2026-07-03

### When were the last committers or PPMC members elected?

The last committers were elected on January 4, 2026.

### Have your mentors been helpful and responsive?

Yes, we have received helpful guidance.

### Is the PPMC managing the podling's brand / trademarks?
No known issues.

### Signed-off-by:

- [ ] (geaflow) Willem Ning Jiang
   Comments:
- [X] (geaflow) Xin Wang
   Comments:
- [ ] (geaflow) Jingsong Lee
   Comments:
- [X] (geaflow) Paul King
   Comments:
- [ ] (geaflow) Justin Mclean
   Comments:

### IPMC/Shepherd notes:

--------------------
## GraphAr

GraphAr is an open-source and language-independent data file format designed
for efficient graph data storage and retrieval.

GraphAr has been incubating since 2024-03-25.

### Three most important unfinished issues to address before graduating:

1.Attract more committers, contributors, and users to grow the community.
2.Release more versions compliant with ASF standards.
3.Cultivate more committers and release managers

### Are there any issues that the IPMC or ASF Board need to be aware of?

None.

### How has the community developed since the last report?

1. Several new contributors completed PR merges.

2. A native Go SDK effort started and is attracting new contributors.

### How has the project developed since the last report?

1.Merged 21 PRs since the last report.

2. C++ library: new features and bug fixes for builders, and upgraded to
Apache Arrow 24.0.0.

3. Rust module: completed the builder layer of the Rust roadmap.

4. Bootstrapped a native Go SDK, with more language support in progress.

5. CI/CD improvements: fixed build issues across C++, Python and Rust
workflows, and added PR template checklist.

### How would you assess the podling's maturity?
Please feel free to add your own commentary.

- [ ] Initial setup
- [ ] Working towards first release
- [X] Community building
- [ ] Nearing graduation
- [ ] Other:

### Date of last release:

2025-08-29

### When were the last committers or PPMC members elected?

2026-04-22

### Have your mentors been helpful and responsive?

The mentors are very helpful and responsive.

### Is the PPMC managing the podling's brand / trademarks?

There are no known brand and naming issues.

### Signed-off-by:

- [x] (graphar) Calvin Kirs
   Comments: Great to see the sharing at CoC Asia!
- [ ] (graphar) tison
   Comments:
- [ ] (graphar) Xiaoqiao He
   Comments:
- [ ] (graphar) Yu Li
   Comments:

### IPMC/Shepherd notes:

--------------------
## Hamilton

Hamilton is a lightweight in-process framework to define, execute, and
observe             directed acyclic graphs (DAGs) that express data
transformations. In Hamilton, one can             express complex DAGs of
transformations, e.g. from dataframe transformations (using
pandas, polars, PySpark), machine learning pipelines, through to regular
software             engineering API request and LLM API based workflows.
Observability hooks are built into             the framework. The Hamilton
UI is a self-hostable service to capture observability             output
from workflow runs.

Hamilton has been incubating since 2025-04-12.

### Three most important unfinished issues to address before graduating:

1. Get more PPMC comfortable with releases.
2. Add to PPMC
3. Build community

### Are there any issues that the IPMC or ASF Board need to be aware of?
No.

### How has the community developed since the last report?
Still people joining slack.

### How has the project developed since the last report?
More first time contributors.

### How would you assess the podling's maturity?
Please feel free to add your own commentary.

- [X] Initial setup
- [X] Working towards first release
- [-] Community building
- [ ] Nearing graduation
- [ ] Other:

### Date of last release:

2026-07-13

### When were the last committers or PPMC members elected?
N/A

### Have your mentors been helpful and responsive?
No answer

### Is the PPMC managing the podling's brand / trademarks?
No answer

### Signed-off-by:

- [ ] (hamilton) Kevin Ratnasekera
   Comments:
- [X] (hamilton) Ayush Saxena
   Comments:
- [X] (hamilton) PJ Fanning
   Comments:
- [ ] (hamilton) Jarek Potiuk
   Comments:

### IPMC/Shepherd notes:

--------------------
## Pegasus

Pegasus is a distributed key-value storage system which is designed to be
simple, horizontally scalable, strongly consistent and high-performance.

Pegasus has been incubating since 2020-06-28.

### Three most important unfinished issues to address before graduating:

1. We are working to revitalize the community, including cultivating more
active contributors and promoting regular releases.
2.
3.

### Are there any issues that the IPMC or ASF Board need to be aware of?

None.

### How has the community developed since the last report?

Overall community activity remained limited during this reporting period,
and no new committers or PPMC members were added.

The community will continue encouraging active contributors to take greater
responsibility for development, code review, and release work.

### How has the project developed since the last report?

Project development remained relatively limited during this reporting
period. A small number of changes were merged, including improvements to
the new metrics framework and updates to GitHub Actions to comply with ASF
infrastructure requirements. Several additional bug fixes and improvements
have been proposed and are currently under review.


### How would you assess the podling's maturity?
Please feel free to add your own commentary.

- [ ] Initial setup
- [ ] Working towards first release
- [X] Community building
- [X] Nearing graduation
- [ ] Other:

### Date of last release:

2023-12-12

### When were the last committers or PPMC members elected?

2024-09-26

### Have your mentors been helpful and responsive?

No issues were encountered that required mentor assistance.

### Is the PPMC managing the podling's brand / trademarks?

Yes.

### Signed-off-by:

- [ ] (pegasus) Duo Zhang
   Comments:
- [ ] (pegasus) Liang Chen
   Comments:
- [ ] (pegasus) Von Gosling
   Comments:
- [ ] (pegasus) Liu Xun
   Comments:

### IPMC/Shepherd notes:

--------------------
## Seata

Seata(Simple Extensible Autonomous Transaction Architecture)is an easy-to-
use             and high-performance distributed transaction solution, used
to solve the data             consistency problem.

Seata has been incubating since 2023-10-29.

### Three most important unfinished issues to address before graduating:

1. Complete the transfer of Seata's existing trademarks to ASF. We are
currently awaiting further response from the ASF counsel team.

### Are there any issues that the IPMC or ASF Board need to be aware of?

No issues at the moment.

### How has the community developed since the last report?
1. 2 new committers were elected.
2. We have prepared 3 topic proposals for Community over Code Asia.

### How has the project developed since the last report?
1. Since the last report, we have merged 78 PRs, primarily including
several new architectural evolution features.
2. Since the last report, we have introduced AI Skills exploration into
our roadmap.

### How would you assess the podling's maturity?
Please feel free to add your own commentary.

- [ ] Initial setup
- [ ] Working towards first release
- [ ] Community building
- [X] Nearing graduation
- [ ] Other:

### Date of last release:

2026-03-12

### When were the last committers or PPMC members elected?

2026-07-24

### Have your mentors been helpful and responsive?

Our mentors have been very helpful and responsive.

### Is the PPMC managing the podling's brand / trademarks?

No Trademark issues.

### Signed-off-by:

- [ ] (seata) Sheng Wu
   Comments:
- [X] (seata) Justin Mclean
   Comments:
- [X] (seata) Huxing Zhang
   Comments:  The podling is still handling trademark issues with ASF,
   otherwise it is all good.
- [ ] (seata) Heng Du
   Comments:
- [X] (seata) Xin Wang
   Comments:

### IPMC/Shepherd notes:

--------------------
## Texera

Texera is an open-source system to support collaborative data science, AI,
and             ML using GUI-based workflows. Our vision is to develop a
system to support cloud             platforms on which users can easily
analyze data and use AI/ML techniques provided as             operators.
Users with various backgrounds, irrespective of whether they know coding or
not, can collaborate on the same project to construct a pipeline.
Experienced users can             use programming languages such as Python,
R, Java, and Scala to implement customized             computation logic.
The platform allows users to pause the execution of a workflow to
investigate the operator states, and resume the execution at a later time.
The platform             can be used by a research community to publish
valuable resources such as data sets,             workflows, and ML models
to share their domain-specific knowledge and support
reproducibility of scientific research. The platform also allows users to
elastically             request computing resources from public clouds for
computationally-intensive tasks.

Texera has been incubating since 2025-04-12.

### Three most important unfinished issues to address before graduating:

1. Publish a sequence of ASF releases following the scheduled quarterly
release cadence.

2. Increase community diversity, and identify and elect new committers and
PPMC members from active contributors.

3. Grow real-world adoption and the user community of the project.

### Are there any issues that the IPMC or ASF Board need to be aware of?

None.

### How has the community developed since the last report?

- dev:
- **21** new first-time contributors made their first commit between May
2026 and July 2026; **44** contributors were active in total.
- The dev@ mailing list had **181** direct messages from **26** unique
posters, including release votes, design RFCs, and policy votes.
- Design and feature discussions increasingly happen on GitHub
Discussions, with 61 new threads between May and July 2026.
- Three universities (UCI, UCLA, and UMich) received an NSF award of
nearly $9M to develop a national center to use the Texera project to
provide services to research labs and communities for three years (2026 -
2029).
- Three monthly community sync meetings were held (June 2, June 30, and
July 28); the meeting minutes are published at
https://texera.apache.org/monthly-meetings
- users:
- Apache Texera (Incubating) was presented at the American Diabetes
Association conference in New Orleans, introducing the project to the
diabetes research community.
- The team launched dknet-ai.org and ran the dkNet-AI Texera Agent
Hackathon.
- Texera was used by about 20 students in a summer camp organized by
dkNET.
- Texera was used by 12 high-school students to learn data science and AI
in the DS4ALL summer program (https://ds4all.ics.uci.edu/summer2026).

### How has the project developed since the last report?

- On May 20, 2026, the project completed its **first ASF release,
v1.1.0-incubating**:
    - Announcement:
https://lists.apache.org/thread/35l99q11mmwl9s5mqmtqfy6hk08sftmm
    - Release notes and artifacts:
https://github.com/apache/texera/releases/tag/v1.1.0-incubating
    - Website:
https://texera.apache.org/announcements/1.1.0-incubating-released
- On May 29, 2026, the community adopted a release branch naming and
release cadence policy, and on June 1, 2026, defined a Release Manager
role, both via dev@ votes.
- On June 3, 2026, the release branch for the second release,
v1.2.0-incubating, was cut; the release is in progress.
- Development activity between May and July 2026: **964** commits to
main, **1,148** PRs merged, and **1,147** issues opened.

### How would you assess the podling's maturity?

- [X] Initial setup
- [X] Working towards first release
- [X] Community building
- [X] Nearing graduation
    - [ ] Status file tasks signed off
    - [X] Suitable name — checked 2025-04-12
    - [X] Ability to create Apache releases — demonstrated with
1.1.0-incubating; 1.2.0 in flight
    - [X] Community readiness
- [ ] Other:

### Date of last release:

2026-05-20, Release v1.1.0-incubating

### When were the last committers or PPMC members elected?

May 6, 2026, a new committer: Xuan Gu (ASF id: xuangu).

### Have your mentors been helpful and responsive?

Yes, the mentors have been very helpful and responsive. In particular,
Ian Maxon provided extensive help during the v1.2.0-incubating release
reviews and joins the monthly sync meetings.

### Is the PPMC managing the podling's brand / trademarks?

Yes.

### Signed-off-by:

- [ ] (texera) Cezar Andrei
   Comments:
- [ ] (texera) Gordon King
   Comments:
- [X] (texera) PJ Fanning
   Comments:
- [X] (texera) Ian Maxon
   Comments:

### IPMC/Shepherd notes:

--------------------
## Toree

Toree provides applications with a mechanism to interactively and remotely
access Apache Spark.

Toree has been incubating since 2015-12-02.

### Three most important unfinished issues to address before graduating:

None

### Are there any issues that the IPMC or ASF Board need to be aware of?

None, Nothing much of news from previous report

### How has the community developed since the last report?

The community slowed down this last couple months and there hasn't been
much progress on getting Release 0.6.0 through the incubator review
process.

The original community plan was to finalize and publish Release 0.6.0 and
then push
for graduation once the release process completes.

### How has the project developed since the last report?

There has been little progress with Release 0.6.0 preparation for RC6
vote.

The upcoming release officially brings support for Scala 2.13 and Spark
3.4.4 which is
already getting a little old.

### How would you assess the podling's maturity?
Please feel free to add your own commentary.

- [ ] Initial setup
- [ ] Working towards first release
- [ ] Community building
- [X] Nearing graduation
- [ ] Other:

### Date of last release:

2022-04-11

### When were the last committers or PPMC members elected?

- PJ Fanning was added to the PPMC on 2025-11-10

### Have your mentors been helpful and responsive?

Note applicable

### Is the PPMC managing the podling's brand / trademarks?

No trademark issues

### IPMC/Shepherd notes:

### Signed-off-by:

- [X] (toree) Luciano Resende
   Comments:  The podling should push graduation after release is out
- [ ] (toree) Ryan Blue
   Comments:
- [ ] (toree) Weiwei Yang
   Comments:

### IPMC/Shepherd notes:

--------------------
## XTable

XTable is a cross-format converter for lakehouse tables. It translates the
metadata that describes a table - schema, partitioning, file listings,
column statistics and snapshot history between Apache Hudi, Apache Iceberg,
Delta Lake, Apache Parquet and Apache Paimon without rewriting or copying
the underlying data files. A single physical copy of a dataset can
therefore be read by
engines and catalogs across various platforms.

XTable has been incubating since 2024-02-11.

### Three most important unfinished issues to address before graduating:

1. Shipping 0.4.0-incubating. rc1 was voted on 2026-07-22 and cancelled
on 2026-07-27 over a source release build failure and LICENSE/NOTICE gaps
in bundled jars; fixes are merged or in review and rc2 is next.
2. Grow the contributor base and elect new committers/PPMC members from
it. Patches now arrive from a reasonably wide set of people, but review and
merge activity is still concentrated in a few hands. Publishing
committer/PPMC expectations (done this period) was the first step;
converting active contributors into committers is the next.
3. Distribute release and maintainer responsibility beyond one
individual. One person has acted as release manager for the last four
releases. A `[DISCUSS] Rotating release managers` thread is open on dev@,
and a PPMC member has already volunteered to take a future release.

### Are there any issues that the IPMC or ASF Board need to be aware of?
No.

### How has the community developed since the last report?
- 7 unique contributors had pull requests merged during this period, with
open pull requests under review from 5 new contributors.
- 14 new issues opened by 6 distinct reporters, 11 closed.
- Committer and PPMC expectations are now published on the website,
prompted by two dev@ threads including one from a contributor asking about
the path to committership.
- GitHub Discussions are now mirrored to dev@, so design conversation is
archived on the mailing list.
- New dev@ threads covered indexing across table formats,
xtable-spark-runtime, a Spark-free Java runtime, rotating release managers
and issues/bugs reported by community users running XTable in various
platforms.
- The developer sync continues every 2 weeks.
[https://xtable.apache.org/community/sync/#typical-agenda].

### How has the project developed since the last report?
- 26 pull requests merged across 7 contributors and 2 of them are
first-time contributors since May 2026.
- Delta Kernel conversion target merged (#801), removing the Spark
dependency for Delta targets - the major in-flight milestone from the last
report.
- Hudi 1.x upgrade merged (#772) with table version 9 support and tests
parameterized across versions 6 and 9 (#834, #835).
- New xtable-spark-runtime module (#843): a thin drop-in bundle for Spark
3.4 and 3.5, validated in CI against a real Spark distribution, so metadata
translation can run inside existing Spark pipelines.
- Parquet source matured further with incremental sync (#768).
- Release engineering hardened from 0.4.0-incubating rc1 validation
feedback.
- Website: required ASF navigation links added (#856), Docusaurus
upgraded (#863), CSP violations fixed (#764, #877).
- main moved to 0.5.0-SNAPSHOT and branch-0.4 was cut for the release.

### How would you assess the podling's maturity?
Please feel free to add your own commentary.

- [ ] Initial setup
- [ ] Working towards first release
- [X] Community building
- [ ] Nearing graduation
- [ ] Other:

The community is targeting a monthly release cadence once 0.4.0-incubating
ships, and nearing graduation in the next six months. More features are
planned as part 0.5.0, 0.6.0 etc., along with blog posts and meetup talks,
including from companies running XTable in production.

### Date of last release:

2025-06-04 (0.3.0-incubating). rc1 for 0.4.0-incubating was cancelled on
2026-07-27; rc2 is in preparation

### When were the last committers or PPMC members elected?

2025-11-09. A further PPMC vote was held on private@ this period; the
feedback was to wait for more concrete individual contributions, so no new
member was elected

### Have your mentors been helpful and responsive?

Our mentors have been helpful and responsive. They have opened the threads
on rotating release managers and on documenting committer/PPMC expectations.

### Is the PPMC managing the podling's brand / trademarks?

Yes. The required ASF navigation links flagged by the Clutch report were
added to the website this period.

### Signed-off-by:

- [ ] (xtable) Jesús Camacho Rodríguez
   Comments:
- [X] (xtable) Stamatis Zampetakis
   Comments:
- [ ] (xtable) Jean-Baptiste Onofré
   Comments:  I'm waiting the report to review and sign. As I'm on
   vacation, it's possible I will miss the sign off.

### IPMC/Shepherd notes:


-----------------------------------------
Attachment AL: Report from the Apache Johnzon Project  [Jean-Louis Monteiro]


-----------------------------------------
Attachment AM: Report from the Apache Juneau Project  [James Bognar]

## Description:
The mission of Apache Juneau is the creation and maintenance of software
related to a toolkit for marshalling POJOs to a wide variety of content types
using a common framework, and for creating sophisticated self-documenting REST
interfaces and microservices using VERY little code

## Project Status:
Current project status: Currently working on a 9.2.1 maintenance release and a
major 10.0.0 release with support for many new languages and MCP client/server
architecture. Issues for the board: None

## Membership Data:
Apache Juneau was founded 2017-10-17 (9 years ago)
There are currently 13 committers and 12 PMC members in this project.
The Committer-to-PMC ratio is roughly 7:6.

Community changes, past quarter:
- No new PMC members. Last addition was Gary D. Gregory on 2023-04-02.
- No new committers. Last addition was Aditya Kanthale on 2024-10-22.

## Project Activity:
9.2.0 was released on 2026-01-05.
9.2.1 will be release within the next 1-2 weeks.
10.0.0 will be released within the next 3-4 weeks.

## Community Health:
Community is small but still active.

dev@juneau.apache.org had a 187% increase
in traffic in the past quarter (377 emails compared to 131).

We expect an uptick in community activity once 10.0.0 is released.


-----------------------------------------
Attachment AN: Report from the Apache Kafka Project  [Mickael Maison]

## Description:
The mission of Kafka is the creation and maintenance of software related to
Distributed publish-subscribe messaging system

## Project Status:
Current project status: Ongoing
Issues for the board: None

## Membership Data:
Apache Kafka was founded 2012-11-21 (14 years ago)
There are currently 71 committers and 44 PMC members in this project.
The Committer-to-PMC ratio is roughly 3:2.

Community changes, past quarter:
- No new PMC members. Last addition was Christo Lolov on 2026-02-23.
- No new committers. Last addition was Sean Quah on 2026-04-29.

## Project Activity:
In the past quarter we released:
- 4.3.1 was released on 2026-06-23.
- 4.2.1 was released on 2026-05-30.
- 4.3.0 was released on 2026-05-22.
4.3.1 and 4.2.1 are bugfix releases to address CVEs

4.3.0 is a feature release that introduces significant improvements
 to all components:
- Mechanism to cordon brokers and log directories
- Improvements to share groups (queues)
- Monitoring improvements
- Improvements to GlobalKTable exceptions handling in Streams
- Support for headers in Streams state stores
- Support for KIP-877 metrics in MirrorMaker

We currently have 1 release in progress:
- 4.4.0 (expected for September)

## Community Health:
The project activity on mailing lists, Jira and GitHub remains high.
The number of opened pull requests is growing due to an increase new
PR creations while our merge velocity is stable.


-----------------------------------------
Attachment AO: Report from the Apache Knox Project  [Larry McCay]


-----------------------------------------
Attachment AP: Report from the Apache Kylin Project  [Yang Li]

## Description:
The mission of Apache Kylin is the creation and maintenance of software
related to a distributed and scalable OLAP engine

## Project Status:
Current project status: Ongoing Issues for the board: None

## Membership Data:
Apache Kylin was founded 2015-11-18 (11 years ago) There are currently 52
committers and 23 PMC members in this project. The Committer-to-PMC ratio is
roughly 7:3.

Community changes, past quarter:
- No new PMC members. Last addition was Xiaoxiang Yu on 2020-10-08.
- No new committers. Last addition was Pengfei Zhan on 2024-11-12.

## Project Activity:
- New release of 5.0.4 on 7/13, mainly security fixes.
- A few PMC members missed private mails in Jan and Feb 2026, including
  myself. I don't see the mails in my gmail, but they are in the
  'list.apache.org'. Have started to process those old mails, especially the
  vulnerability reports.
- Thinking of adding new features, 1) showing acceleration rate of
  pre-compute; 2) improve cube acceleration based on metric semantics like
  apache ossie.

## Community Health:
As discussed in the roll call, we are developing new members to improve the
project PMC activity.
https://lists.apache.org/thread/np41srhj6nm3ch8hs7zl0m113zlg4dc4

1 new committer and 1 new PMC member is under vote right now. Shall have 2 new
members in this week.
- https://lists.apache.org/thread/8kldb331p48j0ft1pvd4hdrkhtyg3826
- https://lists.apache.org/thread/4m849jjcfqcv805hl2ny5fyj9cxcnylc


-----------------------------------------
Attachment AQ: Report from the Apache Libcloud Project  [Miguel Caballer]

## Description

Libcloud is a Python library that abstracts away differences among cloud
provider APIs and provides a unified interface for interacting with
compute, storage, load balancing, DNS, container, and backup services.

## Project Status

Current project status: At risk

The project continues to suffer from a lack of active committers and PMC
members available to review contributions, process PRs, or shepherd
releases.

Since the last report the chair has changed from Tomaz Muraus to Miguel Caballer
and some PMC members are trying to reactivate the project.

## Project Activity

During recent months, the project has received few contributions on
GitHub (https://s.apache.org/h4y97). Activity has improved slightly in
the past month as newly added PMC members and chair have begun to re-engage.

A notable contribution was a long-standing community PR that removed
approximately 18 outdated drivers belonging to cloud providers that have
closed or are no longer active.

No releases have been launched since last report.

New major release is being prepared for the comming weeks.

## Community Health

As noted above, the project currently lacks sufficient active
maintainers (committers and PMC members) to reliably review community
contributions or handle the volume of incoming PRs.

Download and usage statistics indicate that the library still has a
significant user base: https://s.apache.org/k7tug

Like Apache jclouds, Libcloud faces the challenge of being a
"driver-oriented" project, where contributors often focus only on
drivers they personally use, and fewer volunteers are willing to review
or maintain drivers or core components unrelated to their own needs.
This makes long-term maintenance more difficult.

## Membership Data

* Apache Libcloud was founded on 2011-05-19 (almost 15 years ago).
* There are currently 26 committers and 18 PMC members.
* The Committer-to-PMC ratio is approximately 3:2.

Community changes in the past quarter:

* No new PMC members. Last PMC member addition were Zili Chen and Miguel
Caballer (2026-01-24).
* No new committer members. Last committer member addition was Chojan
Shang (2026-02-18).


-----------------------------------------
Attachment AR: Report from the Apache Livy Project  [Jean-Baptiste Onofré]

## Description:
The mission of Apache Livy is the creation and maintenance of software related
to web service that exposes a REST interface for managing long running Apache
Spark contexts in your cluster. With Livy, new applications can be built on top
of Apache Spark that require fine grained interaction with many Spark contexts

## Project Status:
Current project status: Ongoing, second month as a Top-Level Project
Issues for the board: No

## Membership Data:
Apache Livy was founded 2026-05-20 (2 months ago)
There are currently 25 committers and 21 PMC members in this project.
The Committer-to-PMC ratio is roughly 7:6.

Community changes, past quarter:
- No new PMC members (project graduated recently).
- No new committers were added.

## Project Activity:
Releases:
We are still working on the first TLP release. It should happen soon.

Development:
Spark 3.5.x support: merged prior to / around graduation.
Spark 4.x support work started.
JDK 17 support PR has been merged.
Migration from reload4j to log4j2
SASL/TLS support in Zookeeper


Post-graduation infrastructure migration:
The migration off the incubator namespace has been done.
The website, mailing lists, git, Jira references migration is now complete.

## Community Health:
We are still chasing several PMC members who are not following the
private@/dev@ mailing lists.
Now that the resources "post graduation" have been migrated, we will
start to focus on the community expansion and promote the project.


-----------------------------------------
Attachment AS: Report from the Apache Logging Services Project  [Jan Friedrich]

## Description:

The mission of the Apache Logging Services project is to create and maintain
software for managing the logging of application behavior, and for related
software components.

## Project Status:

Current project status: Ongoing

Issues for the board:
At the May board meeting, we were directed to continue
the discussion on the board mailing list. Three directors participated, along
with several ASF members and officers. The discussion surfaced important
questions around 501(c)(3) compliance and vendor neutrality, but ended without
a formal decision. As a result, we have been unable to use the HeroDevs
donation for its intended purposes - security triage and LTS release
management - and the policy ambiguity that affects all PMCs in a similar
situation remains unaddressed.

## Membership Data:

Changes since the last report:

- Founded: 2003-12-17 (22 years ago)
- Committers: 49 (21 active)
- PMC Members: 19 (15 active)
- Committer-to-PMC ratio: 7:3 overall; 1:1 among active members

Community changes, past quarter:
- No new PMC members. Last addition was Raman Gupta on 2025-11-21.
- No new committers. Last addition was Ramanathan Muthu on 2026-05-09
- Five PMC members decided to become emeritus (see Community Health)

## Project Activity:

During the June-August 2026 quarter, the three active components (Log4j,
Log4cxx, and Log4net) showed overall moderate activity.

### Log4cxx (activity: moderate)

- Releases:
  - 1.8.0 on July 28th, 2026

### Log4j (activity: moderate)

- The new committer, Ramanathan Muthu, is very active. He’s addressing
  existing issues, handling open pull requests, and tackling Dependabot
  tasks. He communicates very well and worked with Volkan to release the
  two Log4j versions. He’s a great addition to the team and will also be
  attending the CoC in October. We used part of the HeroDevs donation to
  make this possible.

- Releases:
  - 2.26.1 on July 2nd, 2026
  - 2.25.5 on July 6th, 2026

### Log4net (activity: moderate)

- Log4net was part of the ASVS scans at the end of May 2026. The scan found
  only three minor issues which were fixed in 3.3.2.
- There are active discussions and issues on GitHub regarding potential
  breaking changes in log4net 4.x (the next major release).
- Releases:
  - 3.3.2 on June 25th, 2026

## Community Health:

The community remains active, with issues and pull requests opened daily.

The flood of AI-generated reports stopped (we fixed everything the YWH reports
found and sharpened our threat model).

Upon taking office as the new chair, the chair attempted to contact all PMC
members from whom he had not heard in more than two years (i.e., since he
joined the ASF). Seven of the ten members contacted responded, and of those,
five decided to become emeritus members, as resuming activity in the PMC is
practically out of the question.


-----------------------------------------
Attachment AT: Report from the Apache Lucene.Net Project  [Shad Storhaug]


-----------------------------------------
Attachment AU: Report from the Apache MADlib Project  [Ed Espino]


-----------------------------------------
Attachment AV: Report from the Apache Magpie Project  [Jarek Potiuk]

## Description:
Apache Magpie is responsible for the creation and maintenance of software
related to agent-assisted repository maintainership and development —
including issue and pull-request triage, contributor mentoring, agent-drafted
remediation, developer-side development-cycle skills, and narrowly-scoped
fix-and-merge automation. Magpie is deliberately governance-agnostic: it is
built to be adopted by ASF projects and by non-ASF open-source projects alike,
with no ASF-only assumption baked into the install path.

## Project Status:

- First committer votes succeded — three candidates, our first since
  establishment. These are committer votes only; whether committers should
  automatically join the PMC remains an open question the PMC is discussing
  separately. We are proceeding with inviting and formalising it.

- PMC/Committers: 22 members. Chair: Jarek Potiuk. No additions or removals in
  the period.

- Apache Magpie 0.1.0 — 2026-07-18. Our first release.
  - Cut via a hybrid path: the Apache Trusted Releases (ATR) platform with the
    traditional manual process as fallback. We used the fallback when ATR hit
    blocking issues, and fed that experience back to the ASF Tooling team.
  - Two release candidates were needed; rc1 was withdrawn after review
    feedback. We consider that the process working rather than a problem.
  - The release was itself driven by Magpie's own release skills — dogfooding
    that surfaced real defects we have since fixed.

No new issues. As noted last month, the PMC is exploring relationships with
other open-source organisations. These remain exploratory discussions only;
nothing formal will be done without first engaging VP Marketing & Publicity.
The initial discussions had shown that while there is interest - the
installation approach for Python Software Foundation use and other non-ASF
projects might be a blocker. Eclipse is more interested in having Enclave
embedded as part of the sandboxing. Both approaches are in the discussion
phase.

Thanks for clarifying our question from last month.

## Membership Data:
Apache Magpie was founded 2026-06-17 (2 months ago) There are currently 22
committers and 22 PMC members in this project. The Committer-to-PMC ratio is
1:1.

Community changes, past quarter:
- No new PMC members (project became TLP recently).
- Three new commmitters are already accepted, formalising the process was a
  little impaired due to PMC chair attending Community Over Code Asia.

## Project Activity:
Ongoing, medium activity. The project has shipped its first Apache release and
is now moving from bootstrapping into normal operation.

Discussion at Community Over Code Asia - where three PMC members (Jarek, Craig
and Justin) were speaking had shown that Magpie addresses the very problems
many of the PMCs in Asia are also struggling with. Magpie was mentioned
multiple times at Keynotes and other talks (alongside RAI initiative as well).
The discussions (also earlier ones) allowed to identify two main bottlenecks
for adoption:

* Installation process
* Too many interruptions due to security / permissions

Luckily those are common industry problems and industry is converging on
solutions: Marketplace and Plugin standards have just been released by Open AI
and Anthropic, and permission models for CLI is changing to "auto-approve by
default". We are going to leverage both in the next version - while we are
going to build addional security layer, which will maintain current security
level while avoiding too frequent interruptions.

- 162 pull requests merged in the period, across roughly 37 contributors.
- Governance tightened. Approval-before-merge is now enforced by branch
  protection; the project no longer self-merges without review. This was a
  deliberate slowdown following the release.
- 0.2.0 focus is adoption friction.
- Trusted external skill sources (RFC-AI-0006) landed, allowing skills to be
  pulled from trusted external repositories — the mechanism the PSF
  conversation depends on.
- Vendor neutrality remains automatically measured and published at 100%
  across capability contracts, skills, and agent harnesses:
  https://magpie.apache.org/#vendor-neutrality
- Framework now at 70 skills and 45 tools.
- A read-only repo-health audit family shipped: Actions workflow security,
  dependency vulnerabilities, licence and NOTICE compliance, and flaky-test
  patterns. These skills observe and report only; they make no changes,
  consistent with the project's human-in-the-loop discipline.


## Community Health:

Healthy and broadening, with some caveats.

Contribution is still concentrated: Jarek and Justin account for a large share
of commits. But the tail has grown — several contributors now show sustained,
substantive activity, and the three committer votes now running are the first
step in converting that into shared responsibility. Enforcing
review-before-merge was the other half of that deliberately, since it forces
work through more than one pair of hands.

Interest continues from outside the ASF, including a contributor with
professional AI-security and privacy background who approached the list
directly.

The Chair was presenting a Magpie talk and the security keynote at Community
Over Code Asia, We are also discussing an ASF blog post intended to carry
perspectives from adopters rather than only from the PMC. Further events that
are coming where we can get further feedback are Airflow Summit and Community
Over Code Glasgow.

Ongoing community discussion: ASF Slack requires guest invites for non-ASF
participants, which conflicts with our goal of being open to adopters outside
the foundation. The PMC is deciding between Matrix and Discord for an open
channel.

Onboarding investment has improved. An 11-lesson AI tutor curriculum now ships
in the repository, giving new contributors and adopting maintainers a
structured path into the framework.

Also for the upcoming release (0.2.0) we are reviewing all the SKILLs, docs
onboarding docs for consistency. While Agentic driven development is great to
move fast, it also breaks some consistency, miscount things and hallucinates
sometimes, we are not only fixing the inconsistencies but adding harnesses to
avoid those in the future.

A sustained good first issue programme has raised around 60 curated newcomer
issues, with 45 closed and roughly 25 distinct external contributors, with
several now repeat contributors.


-----------------------------------------
Attachment AW: Report from the Apache ManifoldCF Project  [Piergiorgio Lucidi]

## Description:
The mission of ManifoldCF is the creation and maintenance of software related
to Framework for connecting source content repositories to target repositories
or indexes.

## Issues:
Receiving any kind of feedback from the community and the PMC remains difficult.

## Membership Data:
Apache ManifoldCF was founded 2012-05-15 There are currently 25
committers and 15 PMC members in this project. The Committer-to-PMC ratio is
roughly 5:3.

Community changes, since last report in August:
- No new PMC member.  Last addition was made on 2023-08-03.
- No new committers. Last addition was on 2019-08-17.

## Project Activity:
Version 2.31 released in July represents a major milestone in modernization,
focusing on upgrading the runtime environment to Java 25, adopting Java Virtual Threads
for scalable concurrent processing, upgrading core dependencies and refining automated
container release workflows.

Now have a dedicated LinkedIn page to promote the project and attract new contributors.
The website is also improved with a brand new blog section to share project updates and insights.

Recent releases:
2.31 was released on 2026-07-30
2.30 was released on 2026-04-11
2.29 was released on 2025-09-12
SDK 1.02 released on 2025-02-10

## Community Health:
The project is still active but the community is very small and not so much responsive.
I'm continuing to implement the new roadmap in order to attract new contributors and to improve the project visibility.


-----------------------------------------
Attachment AX: Report from the Apache Maven Project  [Hervé Boutemy]

## Description:
The mission of Maven is the creation and maintenance of software related to
Java project management and comprehension tools

## Project Status:
Current project status: ongoing with high activity.
Issues for the board: none.

## Membership Data:
Apache Maven was founded 2003-03-01 (23 years ago)
There are currently 74 committers and 31 PMC members in this project.
The Committer-to-PMC ratio is roughly 5:2.

Community changes, past quarter:
- Matthias Bünger was added to the PMC on 2026-06-07
- Gerd Aschemann was added as committer on 2026-06-22

## Project Activity:
Releases since last report:
- Maven Resolver Ant Tasks 2.0.0 was released on 2026-08-06
- Apache Maven 4.0.0-rc-6 was released on 2026-08-03
- Maven Resolver 2.0.21 was released on 2026-07-24
- Maven JAR Plugin 3.5.1 was released on 2026-07-22
- Maven Resolver Ant Tasks 1.6.1 was released on 2026-07-21
- Maven Toolchains Plugin 3.3.0 was released on 2026-07-21
- Apache Maven 3.10.0-rc-1 was released on 2026-07-13
- Maven Filtering 3.5.1 was released on 2026-07-03
- Maven Help Plugin 3.5.2 was released on 2026-07-03
- Maven Resolver 2.0.20 was released on 2026-07-03
- Apache Maven Parent POMs 49 was released on 2026-06-28
- Apache Parent POM 39 was released on 2026-06-28
- Maven Executor 1.0.0 was released on 2026-06-15
- Apache Maven Surefire 3.6.0-M1 was released on 2026-06-05
- Apache Maven Daemon 1.0.6 was released on 2026-05-30
- Apache Maven Surefire 3.5.6 was released on 2026-05-28
- Apache Maven Dependency Plugin 3.11.0 was released on 2026-05-24
- Maven Site Plugin 3.22.0 was released on 2026-05-23
- Apache Maven Build-cache-extension 1.2.3 was released on 2026-05-22
- Apache Maven Changelog Plugin 3.0.0-M2 was released on 2026-05-19
- Apache Maven Enforcer Plugin 3.6.3 was released on 2026-05-18
- Maven Resolver 2.0.18 was released on 2026-05-18
- Apache Maven 3.9.16 was released on 2026-05-17
- Maven Reporting Executor 2.0.1 was released on 2026-05-17
- Apache Maven Dependency Analyzer 1.17.1 was released on 2026-05-12

Maven Doxia Book Maven Plugin was retired

We mostly use ATR for our releases, with the addition of the ATR Maven Plugin
in Apache Parent POM 39 that makes upload to ATR even easier than earlier.

Our plan on Maven 3.10 + 4.0 focused on Maven 3 plugins compatibility is
progressing well: we were able to release 3.10.0-RC1 and 4.0.0-RC6, with a
good hope of releasing final versions soon.

## Community Health:
Users mailing list activity remains quite low: Maven 3 is quite stable,
probably the situation will evolve when Maven 4.0.0 is out.
Development discussions happen both on mailing-list for taking decisions, and
a lot on Slack on many unstructured topics.


-----------------------------------------
Attachment AY: Report from the Apache Mynewt Project  [Szymon Janc]


-----------------------------------------
Attachment AZ: Report from the Apache OpenWebBeans Project  [Mark Struberg]

## Description:
 Apache OpenWebBeans is an ALv2-licensed implementations of the
 "Contexts and Dependency Injection for the Java EE platform"
 specifications which are defined as JSR-299 (CDI-1.0), JSR-346
 (CDI-1.1 and CDI-1.2 MR), JSR-365 (CDI-2.0) and
 Jakarta CDI (CDI-4.0, CDI-4.1).

 The OWB community also maintains a small server as
 Apache Meecrowave subproject. Meecrowave bundles latest releases of
 the ASF projects Tomcat + OpenWebBeans + CXF + Johnzon + log4j2.

## Issues:
 There are no issues requiring board attention at this time.

## Activity:
 We just did a new OWB-4.1.1 release which focuses on performance improvements.
 OWB is a good example why JavaEE projects are a bit different than others in
 terms of activity. After a phase of low activity we now had 4 committers actively
 working on the project again.
 We are also currently voting on a new meecrowave-2.1.1 release which incorporates
 the latest Apache Tomcat, CXF, Johnzon, OWB, etc

## PMC changes:
 - Currently 13 PMC members, 20 committers
 -  No new PMC members. Last addition was Reinhard Sandtner on 2017-10-09.
 -  Jonathan Gallimore was added as committer on 2025-12-04

## Recent releases:
 - 4.1.1 was released on 2026-08-07.
 - 4.1.0 was released on 2026-05-03.
 - meecrowave-2.0.0 was released on 2025-10-21.


-----------------------------------------
Attachment BA: Report from the Apache OpenWhisk Project  [Dave Grove]

## Description:
The mission of Apache OpenWhisk is the creation and maintenance of software
related to a platform for building serverless applications with functions

## Project Status:
Current project status: Dormant
Issues for the board: None

## Membership Data:
Apache OpenWhisk was founded 2019-07-16 (7 years ago)
There are currently 54 committers and 22 PMC members in this project.
The Committer-to-PMC ratio is roughly 7:3.

Community changes, past quarter:
- No new PMC members. Last addition was Cosmin Stanciu on 2022-02-22.
- No new committers. Last addition was Luke Roy on 2023-03-06.

## Project Activity:

Since the last board report, the project successfully made a minor release of
one component.  The content of the release was fairly minimal (replacement of
a deprecated node.js API + package updates), but we had no problem mustering
sufficient PMC votes to carry out the release process in a timely manner.

We also had several PRs from contributors (non-committers) that bumped
dependencies to supported versions.

An Apache OpenServerless committer also made a nice contribution of an upgrade
to a modern version of Apache Zookeeper that included a number of additional
dependency updates to enable our CI to pass on his PR.

We were also able to respond to an Apache security report and within 72 hours
of initial report merge a PR to handle the reported issue, and determine that
no CVE was warranted.

Recent releases:
- openwhisk-client-js-3.21.9: 2026-05-20

## Community Health:

Overall the project is dormant with no real new development activity for the
last couple of years. But we are still able to respond to questions, and to
review and merge contained PRs from downstream users and communities.  To the
extent OpenServerless (incubating) is able to leverage the existing codebase,
I don't see a serious problem with continuing in the current state: dormant,
but not in the Attic.


-----------------------------------------
Attachment BB: Report from the Apache ORC Project  [William Hyun]


-----------------------------------------
Attachment BC: Report from the Apache Ozone Project  [Sammi Chen]

## Description
Apache Ozone is a scalable, redundant, and distributed object and file store,
designed to scale to billions of objects/files and run on clusters of
thousands of nodes. Ozone supports S3 compatible object APIs as well as a
Hadoop Compatible File System implementation.

## Issues
None.

## Membership Data
- Apache Ozone was founded 2020-10-21.
- There are currently 91 committers and 44 PMC members in this project. The
  Committer-to-PMC ratio is roughly 2:1.
- In the past quarter, Chu Cheng Li was added to the PMC on 2026-06-26 Priyesh
  Karatha was added as committer on 2026-07-20 Shilun Fan was added as
  committer on 2026-07-05

## Project Activity
- Apache Ozone 2.2.0 is released on July 16, 2026. It adds 914 new features,
  improvements, and bug fixes on top of Ozone 2.1. Refer to
  https://ozone.apache.org/release-notes/2.2.0 for more detailed info.
- Apache Ozone 2.1.1 patch release shipped on June 21, 2026, addressing
  critical JDK 11 OM failures, ozone-filesystem-shaded protobuf corruption,
  Recon pipeline display bugs, S3 - multipart ACL gaps, and Ranger/STS S3
  action–aware authorization. Upgrade is strongly recommended for 2.1.0 users.
- S3 Compatibility
   - Ozone S3 Gateway Phase 4 (HDDS-12716) shipped in 2.2.0, including broad
     S3 API compatibility, request handling, metrics, and correctness
     improvements.
   - S3 conditional requests (HDDS-13117) landed with PutObject
     conditional-write support, conditional delete (HDDS-14907) followed.
   - S3 Object Lifecycle Management (HDDS-8342) feature branch is merged into
     master, with recent commits like resumable scan state (HDDS-15447), abort
     incomplete MPU action (HDDS-13474), and linked-bucket lifecycle support.
- Snapshot Feature
   - Snapshot Defragmentation (HDDS-13003) completed in 2.2.0, reducing
     snapshot storage footprint and improving local-data, locking, and diff
     handling.
   - Snapshot bootstrapping race fix (HDDS-12090) and follow-on hardening
     (HDDS-15860, HDDS-15888) continues.
   - Snapshot phase-four scale-up work (HDDS-13747 lineage) continues.
- Security Token Service (HDDS-13323) development, per-S3-action authorization
  for Ranger (HDDS-15064) is added, waiting for the Ranger release to finish
  Ozone side pending tasks.
- Zero Downtime Upgrade (HDDS-14498) development continues, acceptance-test
  ZDU flow (HDDS-14751), Grafana dashboard and metrics (HDDS-14825), core
  runtime SCM+OM work (HDDS-15084), legacy prepare-for-upgrade removal
  (HDDS-14580), and ZDU cleanup upgrade action (HDDS-14754) are finished.
- Storage Capacity Distribution (HDDS-13177) shipped in 2.2.0, expanding
  storage- and namespace-wise data distribution visibility on Recon and SCM.
- Disk Balancer (HDDS-5713) feature branch is merged into master, and shipped
  in 2.2.0.
- Implement a Client Datanode API to stream a block (HDDS-10338) is shipped in
  2.2.0. There are optimizations continued on master, Ratis write-streaming
  pipeline prioritization (HDDS-15969) and client-side PutBlock optimization
  (HDDS-15758).
- OM HA: Support Follower Read (HDDS-14424) Phase 1 shipped in 2.2.0, with
  gRPC client follower-read support (HDDS-15492) on master.
- Upgrade proto2 to proto3 (HDDS-5404). Ozone continues removing older
  protobuf compilation paths and Hadoop RPC dependency.
- Iceberg RewriteTablePath (HDDS-14937) native Ozone support and Interactive
  Ozone CLI (HDDS-11825) shipped in 2.2.0.
- Distributed tracing (HDDS-13679) with OpenTelemetry configuration landed in
  2.2.0.
- Ozone Event Notification Support (HDDS-13513) groundwork continued with S3
  schema/strategy event generation (HDDS-14009).
- Recon improvements: manual OM DB rebuild for bootstrapping (HDDS-15863), LLM
  gateway for Recon chatbot (HDDS-15906), and cluster capacity error handling
  (HDDS-15764).
- Security threat model (HDDS-15526) published: THREAT_MODEL.md, SECURITY.md,
  and AGENTS.md added to guide vulnerability assessment.
- ozone-csi module removed (HDDS-15876) as part of dependency and module
  cleanup.
- IPv6 support(HDDS-15763) improvements across OM admin CLI and HDDS host/port
  utilities resumed this quarter.
- Apache CoC Asia 2026 August, two sessions accepted
  - Apache Ozone: Auto File Expiration and Removing through S3 Lifecycle
    Configuration
  - Scaling Apache Ozone at Didi: Operating 100PB+ Storage and Billions of
    Files in Production
- New features and proposals
  - Ozone Storage Policy Support(HDDS-11233)
  - Support S3-compatible object versioning in Ozone(HDDS-15728)
  - Common authentication/authorization service(HDDS-15845)

## Releases Data
- 2.0.0 was released on 2025-04-30.
- 2.1.0 was released on 2025-12-31.
- 2.1.1 was released on 2026-06-21.
- 2.2.0 was released on 2026-07-16.

## Community Health
Last board report was sent on 7th May 2026. Since last report,
- 70 code contributors who have commits in the past quarter (+94%)
- dev@ozone.apache.org had 122 emails(including replies) in the past quarter
  (-8%)
- 641 PRs opened on GitHub, past quarter(+52%)
- 588 PRs closed on GitHub, past quarter(+22%)
- 527 commits in the past quarter(+44%)
Note:
- The commit & PR count excludes the ones from user "app/dependabot", who has
  many commits for dependency jar version upgrade.
- The Copilot user is excluded.


-----------------------------------------
Attachment BD: Report from the Apache PDFBox Project  [Andreas Lehmkühler]

## Description:
The mission of PDFBox is the creation and maintenance of software related to
Java library for working with PDF documents

## Project Status:
Current project status: Ongoing with moderate activity
Issues for the board: none

## Membership Data:
Apache PDFBox was founded 2009-10-21 (17 years ago)
There are currently 21 committers and 21 PMC members in this project.
The Committer-to-PMC ratio is 1:1.

Community changes, past quarter:
- No new PMC members. Last addition was Matthäus Mayer on 2017-10-16.
- No new committers. Last addition was Joerg O. Henne on 2017-10-09.

## Project Activity:
Recent releases:

    2.0.37 was released on 2026-07-15.
    3.0.8 was released on 2026-07-11.
    3.0.5 JBIG2 was released on 2026-05-20.

## Community Health:
- there is a steady stream of contributions, bug reports and questions on the
  mailing lists
- 3.0.5 of the JBIG2 plugin was released. We  increased our decoder
  compatibility with the serenity tests up to 100%, see
  https://s.apache.org/jbig2_serenity_test
- 3.0.8 and 2.0.37 were released. The most important change is to no longer
  provide binaries for our examples subproject. We did so accidentically at
  least via maven. Some users are using them in production and complained
  about (security) issues and expected some soon bugfix release. Those
  examples were never meant to be production ready. They are examples on how
  to use pdfbox, nothing more, nothing less.
- we defined a security model for PDFBox to support anybody who tries to
  analyze our code using some sort of AI or something similar
- we received some security reports through security@apache and already
  benefited from our security model as our friends from security are using
  some AI to triage the reports before they reach us. The results are looking
  promising
- most of the reports don't meet our requirements for a security issue and are
  already handled and/or fixed


-----------------------------------------
Attachment BE: Report from the Apache Perl Project  [Steve Hay]

## Description:
The mission of Perl is the creation and maintenance of software related to
Dynamic websites using Perl

## Project Status:
Current project status: At risk
Issues for the board: The project may not have sufficient oversight from the PMC

## Membership Data:
Apache Perl was founded 2000-03-10 (26 years ago)
There are currently 21 committers and 11 PMC members in this project.
The Committer-to-PMC ratio is roughly 2:1.

Community changes, past quarter:
- No new PMC members. Last addition was Steve Hay on 2012-03-01.
- No new committers were added.

## Project Activity:
The last release was mod_perl-2.0.13 on 2023-10-21.

No activity to report in the last quarter. Nothing further has occurred on the
GitHub fork I mentioned last time either. It is indeed under the same LICENSE,
but I haven't merged its PR into trunk: it's not clear whether it would be a
wise move, I doubt we have the expertise left to review and test it properly,
and we certainly wouldn't want to merge in its README revision with its
reference to the "dead software product from Apache" even if that's sadly quite
accurate by now.

## Community Health:
Mailing list traffic is also back to its very quiet normal state of being -
just a few questions popping up on the users list but nothing on the
development side.

Most of the 21 committers have long been inactive. Other than the last commit
(from jorton) every commit back to 2015 has been from me. The last time we had
any sort community effort going on, with commits from jkaluza, gozer, phred,
torsten and others was around 2013/2014. The project needs fresh blood to
continue, but with no patches arriving from any would-be committers the project
has stalled.


-----------------------------------------
Attachment BF: Report from the Apache Phoenix Project  [Viraj Jasani]

## Description:
The mission of Phoenix is the creation and maintenance of software related to
High performance relational database layer over Apache HBase for low latency
applications

## Project Status:
Current project status: Ongoing
Issues for the board: None

## Membership Data:
Apache Phoenix was founded 2014-05-20 (12 years ago)
There are currently 60 committers and 39 PMC members in this project.
The Committer-to-PMC ratio is roughly 5:4.

Community changes, past quarter:
- Lokesh Khurana was added to the PMC on 2026-08-02
- Palash Chauhan was added to the PMC on 2026-06-02
- No new committers. Last addition was Nihal Jain on 2025-08-05.

## Project Activity:
Development activity remains average. Feature development is concentrated on
the consistent HA failover feature, improving CDC and
eventually consistent GSIs, as well as support for the Phoenix DynamoDB
adapter.

Lots of efforts to improve the flaky tests, and critical bug fixes are in
progress.

Recent releases:

5.2.2 was released on 2026-07-04.
5.3.2 was released on 2026-07-04.
5.3.1 was released on 2026-05-18.


## Community Health:
Overall community health is acceptable. Most of the development is done by our
core team of about a dozen active developers.


-----------------------------------------
Attachment BG: Report from the Apache Pinot Project  [Kishore G]


-----------------------------------------
Attachment BH: Report from the Apache POI Project  [Dominik Stadler]

Report from the Apache POI committee [Dominik Stadler]

## Description:
 - Apache POI is a Java library for reading and writing Microsoft Office file
   formats.

   The Apache POI PMC also handles bugfixes for the XMLBeans project: XMLBeans
   is a tool that allows you to map XML files to generated Java classes via
   XML Schema definitions.

## Project Status:
 - Overall: Low activity/Mostly maintenance only
 - Some good PR influx both on Apache POI and XMLBeans on GitHub
 - Activity on the project is low with no-one willing/able to invest time to
   look for new committers. This project is in a mostly-maintenance mode
   unless someone new starts to invest time.
 - Note: None of the active committers wants to spend time looking for new
   people, so suggesting to reach out to others or invest in "marketing" will
   likely not lead to much improvement.
 - The project still has enough active PMC members to vote on issues and
   perform releases

## Membership Data:
   Apache POI was founded 2007-05-16 (19 years ago) There are currently 42
   committers and 35 PMC members in this project. The Committer-to-PMC ratio
   is 6:5.

   Community changes, past quarter:
   - Jacobo Aragunde Pérez was added to the PMC on 2026-06-26
   - Jacobo Aragunde Pérez was added as committer on 2026-06-26

## Project Activity:
  - Upgraded to minimum Java 17 for the next major release 6.x
  - Various bug-fixes and smaller enhancements, a number of them from external
    contributors via GitHub PRs

## Project Release Activity:
  - 5.5.1 was released on 2025-11-30.
  - 5.5.0 was released on 2025-11-15.
  - 5.4.1 was released on 2025-04-06.
  - XMLBeans-5.3.0 was released on 2024-12-13.

## Community Health:
 - There are a few bug-reports and pull-requests which indicates that Apache
   POI is still in use. Questions via email or on Stackoverflow usually get
   answers.

 - Bug-numbers slowly increase over time. Some newly reported issues are
   fixed, but we usually get more bugs/questions reported than are addressed
   by the small number of active committers, so some bugs do not get attention
   any more.

 - We have a very small number of active committers. There are very few
   potential candidates and no-one plans to spend effort to go looking for new
   ones.

### XMLBeans
 - It seems there are is a small but active set of users of XMLBeans besides
   Apache POI itself.

 - Bug influx for XMLBeans is very low in general because it is a stable
   project in maintenance-only mode, there was one external active contributor
   who contributed many stability fixes. We plan to invite him to join Apache
   POI/XMLBeans as a committer.

## Bug Statistics:

### Apache POI

 - 637 bugs are open overall (+-0)
 - Having 148 enhancements (+2)
 - Thus having 489 actual bugs (-2)
 - 118 of these are waiting for feedback (-2)
 - Thus having 371 actual workable bugs (+-0)
 - 4 of the workable bugs have patches available (+-0)
 - Distribution of workable bugs across components: {XSSF=107, HSSF=79, SS
   Common=48, HWPF=35, XSLF=33, XWPF=18, POI Overall=15, POIFS=7, SXSSF=7,
   HSMF=6, OPC=6, HPSF=4, HSLF=3, HPBF=1, SL Common=1, XDDF=1}
 - GitHub: Open Issues: 16 Open Pull-Requests: 30

### Apache XMLBeans

 - 165 open issues (-3)
 - 118 Bug (-2)
 - 28 Improvement (+-0)
 - 15 New Feature (+-0)
 - 2 Task (-1)
 - 2 Wish (+-0)


-----------------------------------------
Attachment BI: Report from the Apache Polaris Project  [Jean-Baptiste Onofré]

## Description:
The mission of Apache Polaris is the creation and maintenance of software
related to a catalog for data lakes. It provides new levels of choice,
flexibility and control over data, with full enterprise security and Apache
Iceberg interoperability across a multitude of engines and infrastructure

## Project Status:
Current project status: Healthy and active.
This is Apache Polaris's first quarterly board report, following the
initial monthly
reports filed after the project graduated to a Top-Level Project on 2026-02-18.
The transition out of incubation has been smooth: the project has established
and sustained a monthly release cadence, the PMC is operating independently
and in the Apache Way, development activity remains high, and several
substantial feature proposals are under active discussion on the dev list.

Compared with the previous report(s): the most notable change is the shift from
monthly to quarterly reporting itself, marking the project's settling into a
normal TLP rhythm. The release train established immediately post-graduation has
continued without slippage (two feature releases plus a patch this period). The
character of activity has also evolved (where the earlier reports centered on
the graduation transition and post-graduation stabilization), this quarter the
community has moved toward expanding the catalog's scope, with major design
proposals (Data Sharing, OpenLineage, Polaris Directory) now under active
discussion. Committer growth continued with one addition.

Issues for the board: None

## Membership Data:
Apache Polaris was founded 2026-02-18 (5 months ago)
There are currently 32 committers and 19 PMC members in this project.
The Committer-to-PMC ratio is roughly 8:5.

Community changes, past quarter:
- No new PMC members. Last addition was Sung Yun on 2026-04-27.
- Nándor Kollár was added as committer on 2026-06-30

## Project Activity:
The project maintained its monthly release cadence throughout the quarter,
continuing the train established right after graduation:
- 1.6.0 released 2026-07-08
- 1.5.0 released 2026-05-18
- (1.4.1, a patch release, shipped 2026-05-01 at the start of the period)

Development throughput on GitHub (apache/polaris) remained high over the
reporting window (May–July 2026):
- Pull requests: 761 opened, 651 merged
- Issues: 90 opened, 91 closed
- Currently open: 102 pull requests, 256 issues The high merge count relative
  to issues reflects a fast-moving, PR-driven workflow with a healthy review
  throughput.

Recent release work has focused on hardening the project for production use,
including running event listeners on a dedicated configurable executor, an
updated MaintenanceService API, and stricter REST-layer validation of entity
names. Broader ongoing themes include catalog federation, credential vending,
and governance/policy integration.

Several notable feature proposals and design discussions are active on the dev
list this quarter, reflecting a shift from stabilization toward expanding the
catalog's scope:
- Data Sharing / Catalog Sharing: a design for securely sharing catalog
  namespaces and tables (metadata pointers) with external accounts and partner
  engines without copying data, including recipient credentials and
  revocation.
- OpenLineage: a sustained proposal thread exploring how Polaris should emit
  and integrate lineage information, positioning the catalog as a lineage/
  observability plane. This pairs with related discussions on REST endpoints
  exposing table metrics and events.
- Polaris Directory: a proposal for a directory/volume-style abstraction to
  organize files and unstructured data within the catalog, extending Polaris
  beyond Iceberg tables toward broader data-asset management.
- Polaris Semantic: we are discussing how to "integrate" Apache Ossie
  (incubating) in Polaris and the concrete valuable use cases.
- Polaris Tagging: it has been discussed quickly last year, it's now back in
  discussion. The purpose is to be able tag Polaris entities to facilitate the
  discover and usage.

Release voting, discussion, and decision-making continue to take place on the
public dev@ list in accordance with the Apache Way.

## Community Health:
Community health is good. Development is broadly distributed: 58 distinct
authors opened pull requests against apache/polaris during the quarter, a
strong contributor-diversity signal for a project only a few months past
graduation. The project added one new committer this quarter (Nándor Kollár,
2026-06-30), reflecting continued growth of the contributor base on merit. The
committer and PMC rolls remain diverse, spanning multiple cloud providers,
engine and governance vendors, and independent contributors, which keeps the
project vendor-neutral and resilient to any single contributor's departure.

The volume and substance of design discussion on the dev list (spanning data
sharing, lineage, and unstructured-data support) indicates an engaged
community debating the project's direction openly. There were no new PMC
members this quarter; the PMC will continue to watch for sustained contributors
who are candidates for invitation.


-----------------------------------------
Attachment BJ: Report from the Apache Pony Mail Project  [Rich Bowen]

# Apache Pony Mail — Board Report, August 2026

## Description

Apache Pony Mail provides mail-archiving, archive browsing, and mailing list
interaction services.

## Project Status

Current project status: New (recently graduated)

Issues for the board: None.

## Graduation Summary

Apache Pony Mail entered the Apache Incubator in May 2016 and graduated to a
Top-Level Project by Board resolution on July 15, 2026 — just over ten years
in incubation.

The community vote on dev@ponymail.apache.org (July 6–10) passed with 7 +1
(binding), 1 +0, and 0 -1. The IPMC vote was subsequently held on
general@incubator.apache.org and also passed. The Board approved the
establishment resolution at the July 15 meeting.

## Post-Graduation Progress

The project has been working through the standard post-graduation checklist
since July 16. Completed items include:

- Updated committee-info.txt and foundation/officers/affiliations.txt
- Updated podlings.xml (status=graduated)
- Removed "Incubating" disclaimers from website and source
- Filed INFRA request for Git repository rename (incubator-ponymail-* →
  ponymail-*): INFRA-28133 (Now resolved)

## Membership Data

Apache Pony Mail was established 2026-07-15 (5 weeks ago). There are currently
11 committers and 6 PMC members in this project.

No new committers or PMC members have been added since graduation.

## Project Activity

Development activity has been healthy during and after the graduation period.
54 commits were made between June and July 2026.

Notable development work in this period:

- **Database schema documentation** — Complete architecture.md documenting the
  full database schema (#320)
- **API token authentication** — Long-term API tokens for programmatic
  authentication (#312), contributed by Jarek Potiuk
- **UI improvements** — Encode query/header values in pushState URLs (#315),
  filter stopwords from word cloud results (#318), make author names clickable
  as search items (#322)
- **Bug fixes** — Partial fixes for issue #323 (lao-refs), scope fix for
  dedup+dry mode
- **Dependency updates** — certifi, multipart, google-auth, aiosmtplib all
  updated to current versions
- **Branch protection** — Default protection rulesets set up for default and
  release branches (#311)
- **Post-graduation cleanup** — Removed incubation disclaimers from website
  and code, updated site build instructions, enabled GitHub Issues for
  website, documented how to raise website issues

## Releases

No releases have been made since graduation. The most recent release was
0.10-incubating. The PMC plans to make the first TLP release once the
repository rename is complete and remaining graduation housekeeping is
finished.

## Community Health

The dev@ mailing list saw 70 messages across 22 threads in June–July 2026,
with active participation from 10+ individuals including both PMC members and
external contributors (notably Jarek Potiuk contributing the API token
feature). The users@ list has been quiet — this is expected given the
project's niche audience (mailing list administrators and the ASF
infrastructure itself).

The project acknowledges that it will likely never have a large contributor
community given its specialized domain. However, the existing PMC has
sufficient depth — multiple active committers from different organizations —
to sustain and develop the software.

## Plans

Near-term priorities:

1. Complete remaining graduation housekeeping (repo rename, security contacts,
   graduation announcement)
2. Prepare first TLP release under the new project identity
3. Continue improving documentation and contributor onboarding

## Reporting Schedule

This is the first of three required monthly reports following graduation
(August, September, October 2026). After October, the project will move to its
assigned quarterly rotation.


-----------------------------------------
Attachment BK: Report from the Apache Qpid Project  [Robbie Gemmell]

Apache Qpid is a project focused on creating software based on the
Advanced Message Queuing Protocol (AMQP), currently providing a protocol
engine library, message broker, and client libraries for C, C++, .Net,
Go, Java/JMS, Python, and Ruby.

# Releases:

- Qpid Proton-J 0.35.0 was released on August 4th.
- Qpid Broker-J 10.1.0 was released on August 4th.
- Qpid ProtonJ2 1.2.0 was released on August 4th.
- Qpid Proton Dotnet 1.1.0 was released on August 4th.
- Qpid JMS 1.17.0 was released on August 11th.
- Qpid JMS 2.11.0 was released on August 11th.

# Community:

- The main user and developer mailing lists continue to be active and
  JIRAs are being raised and addressed in line with prior activity levels.

- There were no new PMC member additions in this quarter.
  The most recent new PMC member is Daniil Kirilyuk, added 22nd January 2024

- There were no new committer additions in this quarter.
  The most recent new committer is Daniil Kirilyuk, added 17th February 2023

# Development:

- Broker-J had its 10.1.0 release, with various bug and security fixes,
  dependency updates, and improvements including support for running on
  Java 25. Work progresses on more improvements and bug fixes.

- ProtonJ2 had its 1.2.0 release with various improvements and bug fixes,
  including some security fixes. Work continues on more improvements and bug
  fixes, including towards a 2.0.0 release with a raised Java 17 minimum
  requirement and various code cleanup / improvements.

- Proton Dotnet had its 1.1.0 release addressing some security fixes. Work
  continues on more improvements and bug fixes.

- Proton-J had a 0.35.0 release with some security fixes and improvements.
  Work will continue as needed to support Qpid JMS and other components.

- Updates continue towards a Proton 0.41.0 release in the near future,
  including an updated version of initial transaction support for the C++
  binding which has been landed, plus other improvements and bug fixes.

# Issues:

There are no Board-level issues at this time.


-----------------------------------------
Attachment BL: Report from the Apache Ranger Project  [Selvamohan Neethiraj]


-----------------------------------------
Attachment BM: Report from the Apache RocketMQ Project  [Xiaorui Wang]


-----------------------------------------
Attachment BN: Report from the Apache Roller Project  [Dave Johnson]

## Description:
Apache Roller is a full-featured, Java-based blog server that works
well on Tomcat, Postgres and MySQL, and is known to run on other
Java servers and relational databases. Latest release is 6.1.5 on 2025-04-05.

## Project Status:
The project remains in low-activity maintenance mode. Development is
limited to dependency updates, keeping the code building on current
Java releases, and responding to security reports. Security response
was the dominant activity this quarter by a wide margin.

## Membership Data:
Apache Roller was founded 2007-02-20 (19 years ago)
There are currently 11 committers and 7 PMC members in this project.
The Committer-to-PMC ratio is roughly 3:2.

Community changes, past quarter:
- No new PMC members. Last addition was Michael Bien on 2021-05-24.
- No new committers. Last addition was Yash Maheshwari on 2021-09-01.

## Project Activity:
No release this quarter. The last release was Roller 6.1.5 on
2025-04-05. Planning for a 6.1.6 maintenance release is underway,
and the security fixes will likely determine its scope and timing.

## Community Health:
Community health is unchanged: quiet, but sufficient to keep Roller
maintained and to get security fixes out. Mailing list traffic
is low and concentrated on the security discussions above.


-----------------------------------------
Attachment BO: Report from the Apache Samza Project  [Jagadish Venkatraman]


-----------------------------------------
Attachment BP: Report from the Apache Santuario Project  [Colm O hEigeartaigh]

## Description:
The mission of Santuario is the creation and maintenance of software related to
XML Security in Java and C++

## Project Status:
Current project status: The Java project is actively maintained and PRs are
getting merged and releases made
Issues for the board: Nothing to report

## Membership Data:
Apache Santuario was founded 2006-06-27 (20 years ago)
There are currently 18 committers and 7 PMC members in this project.
The Committer-to-PMC ratio is roughly 9:4.

Community changes, past quarter:
- No new PMC members. Last addition was Daniel Kulp on 2018-10-01.
- No new committers. Last addition was Joze Rihtarsic on 2024-05-14.

## Project Activity:
We have some new contributions to the project that were merged, and some
awaiting review. We expect new releases in the next quarter.

Last releases:

 - Apache Santuario - XML Security for Java 3.0.6 was released on 2025-04-11.
 - Apache Santuario - XML Security for Java 4.0.4 was released on 2025-04-11.

## Community Health:
Apache Santuario is a mature and stable project that has reached a point
where not too many fixes are required, as it is a set of implementations
of some specifications that are quite old now. It is actively managed by
the PMC


-----------------------------------------
Attachment BQ: Report from the Apache SDAP Project  [Nga Thien Chung]

## Description:
The mission of Apache SDAP is the creation and maintenance of software related
to an integrated data analytic center for Big Science problems

## Project Status:
Current project status: Ongoing
Issues for the board: none

## Membership Data:
Apache SDAP was founded 2024-04-16 (2 years ago)
There are currently 23 committers and 16 PMC members in this project.
The Committer-to-PMC ratio is roughly 3:2.

Community changes, past quarter:
- No new PMC members. Last addition was Joshua Garde on 2026-01-12.
- No new committers. Last addition was Joshua Garde on 2026-01-08.

## Project Activity:
Last SDAP release was 1.4.0 on 2024-11-04.

There was some progress in getting SDAP components updated to python3.11 last
quarter, but overall progress is still slow. There was also some progress made
in updating SDAP components to uv for environment and dependency management.

## Community Health:
Since last quarter, dev@sdap.apache.org had 0 new threads.

Since last quarter, sdap slack channel had 2 new threads.

### Contributors
Since last quarter, the SDAP community has merged 2 PR and created/updated
2 Jira issues.


-----------------------------------------
Attachment BR: Report from the Apache Sedona Project  [Jia Yu]

## Description:
The mission of Apache Sedona is the creation and maintenance of software
related to a big geospatial data processing engine. It provides an easy to use
APIs for spatial data scientists to manage, wrangle, and process geospatial
data

## Project Status:
Current project status: Ongoing, with high activity.
Issues for the board: No issues.

## Membership Data:
Apache Sedona was founded 2022-12-20 (4 years ago)
There are currently 26 committers and 20 PMC members in this project.
The Committer-to-PMC ratio is roughly 7:5.

Community changes, past quarter:
- No new PMC members. Last addition was Dewey Dunnington on 2026-04-28.
- James Willis was added as committer on 2026-07-08

## Project Activity:
Apache Sedona 1.9.1 was released on August 5, 2026. This minor release
includes bug fixes, new features, and improvements, with eight first-time
contributors. Highlights include broad Geography support across core SQL
functions and spatial joins; new Box2D and Box3D types with predicates,
aggregates, spatial joins, and Parquet filter pushdown; GeoTIFF and NetCDF
metadata data sources; raster distance joins and Python raster UDF support;
expanded SedonaFlink Geography and Box3D support; a larger distributed
GeoPandas API; and Chinese documentation.

SedonaDB 0.4.0 was released on June 21, 2026. The release resolved 187 issues,
added 26 spatial functions, and included work from 15 contributors. Major
additions include GPU-accelerated spatial joins, a Python DataFrame API, an R
dplyr interface, expanded Geography support, GeoParquet write support, and
N-dimensional raster and Zarr support. The GPU spatial join work was also
accepted to VLDB 2026 Industry Track.

## Community Health:
The community remains very healthy, with an Apache Reporter Community Health
Score (Chi) of 10.00 (Super Healthy). James Willis joined as a new committer
this quarter, and both the Sedona and SedonaDB releases included broad
contributor participation.

Traffic on issues@ increased 24% quarter-over-quarter (2,753 vs. 2,215
emails), reflecting continued activity on GitHub issues and pull requests.
Direct traffic on dev@ decreased 46% (23 vs. 42 emails), consistent with the
project's ongoing shift toward GitHub for technical collaboration. JIRA
activity remains low by design following the transition to GitHub Issues in
2025; 6 JIRA tickets were opened and 0 were closed this quarter.


-----------------------------------------
Attachment BS: Report from the Apache Serf Project  [Daniel Sahlberg]

## Description:

The mission of the Apache Serf project is creating and maintaining of
software related to HTTP and associated protocols.

## Project Status:

The project has sufficient PMC oversight.

There are no threats to the sustainability or resilience of the project,
although the project is in general very much dormant due to lack of
need/requirements from our users.

The project has no requests for the Foundation.

## Membership Data:

Apache Serf was founded 2015-08-18 (11 years ago)

There are currently 17 committers and 15 PMC members in this project.
The Committer-to-PMC ratio is roughly 9:8.

Community changes, past quarter:
- No new PMC members. Last addition was Graham Leggett on 2025-06-27.
- No new committers. Last addition was Graham Leggett on 2025-06-28.

## Project Activity:

Added support for OpenSSL 4.0.

Recent releases:
* 1.3.10 was released on 2023-05-31.
* 1.3.9 was released on 2016-08-31.

## Community Health:

Serf and Subversion have a significant overlap of committers and PMC
members and Subversion is the only (known) open source project using
Serf. New features in Subversion are therefore the primary driver for
development in Serf.

After significant activity last quarter, activity died down due to
lack of time.

There are still plans for making a new minor release in the near
future.

Our community is fully volunteer-driven and we would like to thank
everyone for their support.


-----------------------------------------
Attachment BT: Report from the Apache ServiceComb Project  [Zhangjian He]


-----------------------------------------
Attachment BU: Report from the Apache ShardingSphere Project  [Liang Zhang]

## Description:
The mission of Apache ShardingSphere is the creation and maintenance of
software related to a database clustering system providing data sharding,
distributed transactions, and distributed database management

## Project Status:
Current project status: None Issues for the board: None

## Membership Data:
Apache ShardingSphere was founded 2020-04-15 (6 years ago) There are currently
62 committers and 22 PMC members in this project. The Committer-to-PMC ratio
is roughly 8:3.

Community changes, past quarter:
- No new PMC members. Last addition was Longtao Jiang on 2024-03-28.
- No new committers. Last addition was Chenyang Ma on 2024-05-27.

## Project Activity:
No new release was published during this reporting period. Development
continued toward Apache ShardingSphere 5.5.4, which remains under active
development.

Software development activity:

- Added a standalone ShardingSphere-MCP Server, providing controlled database
  access for AI applications, including metadata discovery, SQL operations,
  and rule-management workflows.
- Added DistSQL support for managing sharding key generators and enhanced
  column-level and global auto-increment configuration.
- Expanded SQL parser and binder coverage for MySQL, Oracle, Hive, PostgreSQL,
  openGauss, Doris, MariaDB, and SQL Server.
- Continued improving Proxy and JDBC compatibility, particularly for the
  MySQL, PostgreSQL, openGauss, and Firebird protocols.
- Improved stability across metadata loading, data pipelines, cluster mode,
  sharding, read/write splitting, and SQL federation.
- Extended runtime and build compatibility, including OpenJDK 26 and GraalVM
  Community Edition on JDK 25.

## Community Health:
With AI-assisted development tools increasingly used for issue analysis, code
implementation and refactoring, unit test development, and pull request
review, the community has significantly improved its development and
maintenance efficiency, resulting in more active code contributions.

AI-assisted development has reduced the cost of addressing accumulated issues
and repetitive maintenance work, allowing maintainers to focus more on new
features, compatibility improvements, and code quality. The project remains
stable, with healthy community collaboration and contribution activity.


-----------------------------------------
Attachment BV: Report from the Apache ShenYu Project  [Yu Xiao]

## Description:
The mission of Apache ShenYu is the creation and maintenance of software
related to a Java native API Gateway for service proxy, protocol conversion and
API governance

## Project Status:
Current project status: Good Healthy.

Issues for the board: There are no issues requiring board attention.


## Membership Data:
Apache ShenYu was founded 2022-07-20 (4 years ago)
There are currently 60 committers and 26 PMC members in this project.
The Committer-to-PMC ratio is roughly 2:1.

Community changes, past quarter:
- No new PMC members. Last addition was Hongyu Liu on 2025-05-15.
- Zemin Gu was added as committer on 2026-07-07

## Project Activity:

2.7.1 was released on 2026-07-13.

Software development activity:

- We added new role search criteria .
- We added CORS support with configurable allowed headers in MCP server  .
- We fixed mcp server real url error.
- We fixed field-sqlmap.xml database reserved.
- We fixed the selector and rule pagination non-functional.
- We fixed mcp tool sample error.
- We fixed nettyHttpClientPlugin doRequest response unique headers error.
- We refactored etcdClient for improved readability and maintainability.
- We refactored ai proxy enhanced module to ai proxy and update related .

Meetups and Conferences:

 - Community meetings(2) to discuss development tasks and how to
 build an open governance community.


## Community Health:
Overall community health is good.

Since the last report, add +9 contributors added (currently:436).

add +1 subscribers to dev@shenyu.apache.org mailing (currently:513)


-----------------------------------------
Attachment BW: Report from the Apache SIS Project  [Martin Desruisseaux]

## Description:
The mission of Apache SIS is the creation and maintenance of software providing
data structures for developing geospatial applications compliant with the model
of OGC/ISO international standards.

## Project Status:
Current project status: ongoing with high activity.
Issues for the board: no new issue. A topic raised in last February report
("cooperation with other projects") is still partially unresolved (except
maybe the licensing aspect), but it is not clear if it should be an issue
for the board.

## Membership Data:
Apache SIS was founded 2012-09-19 (14 years ago)
There are currently 22 committers and 17 PMC members in this project.
The Committer-to-PMC ratio is roughly 6:5.

Community changes, past quarter:
- No new PMC members. Last addition was Alexís Manin on 2021-05-27.
- No new committers. Last addition was Bruno P. Kinoshita on 2021-06-23.

## Project Activity:
Apache SIS will have a talk in the FOSS4G conference in Hiroshima
in September [1], and in Community Over Code conference in October.
A release is in preparation with the goal to publish it before the
FOSS4G conference. That release will introduce a "GEOINT Imagery Media
for Intelligence" module which was developed during the Open Geospatial
Consortium (OGC) Testbeds of the last two years.

5 minor security issues have been reported since the last release, but none of
them seem threatening enough for deserving a CVE. They either require user not
following installation instructions (but we will harden Apache SIS anyway),
cause OutOfMemoryError or cause attempts to read files on the local system
that are very likely to fail with a parsing error. Therefore, the possibility
of data leak is low. We plan to fix all these issues in the next release anyway.

Apache SIS is divided in 3 groups of modules: "endorsed" which contains the core
modules included in releases, "optional" which contains modules that depend on
GPL libraries (JavaFX) or other non-free data, and "incubator" which contains
work in progress not yet released. The above cited GEOINT module for example was
developed in "incubator" for the last 2 years and graduated to "endorsed" last
month. The "incubator" modules are receiving increasing activity lately.

The build system of Apache SIS is a precursor in the sense that it uses
Java Module Source Hierarchy [2], a standard feature of the JDK for more than
10 years but still not well supported by neither Maven or Gradle. Because of
that, it is uneasy to build SIS and yet more difficult to open it in an IDE and
to run it within a debugger. This difficulty is an impediment to contributions.
Instead of making the build more classical at the cost of losing the Java Module
Source Hierarchy, we rather contributed to Maven 4 for bringing Java Module
Source Hierarchy support in build tools. It has been a 3 years effort which
is coming close to completion. The recent Maven 4.0.0-rc-6 release provides
the foundation that we need, the Maven Compiler Plugin is already ready for
a few months, and the Maven JAR Plugin is on track. The main remaining work
is the Maven Surefire Plugin. After that, we should be able to migrate the
Apache SIS build to Maven 4, hopefully during the next 6 months.
It will hopefully make contributions to SIS easier.

[1] https://2026.foss4g.org/
[2] https://sis.apache.org/release-notes/Modularization.html

## Community Health:
Apache SIS is still developed mostly by two developers of the same company,
but the activity is high and the activity of the second developer is increasing.
Other developers, will not developing directly, are watching and provide tests
and votes for releases.


-----------------------------------------
Attachment BX: Report from the Apache Solr Project  [Alessandro Benedetti]

## Description:
The mission of Apache Solr is the creation and maintenance of software related
to highly scalable distributed document search and analytics

## Project Status:
Current project status: Ongoing with moderate activity.
Issues for the board: none.

## Membership Data:
Apache Solr was founded 2021-02-17 (5 years ago)
There are currently 103 committers and 62 PMC members in this project.
The Committer-to-PMC ratio is roughly 7:4.

Community changes, past quarter:
- No new PMC members. Last addition was Christos Malliaridis on 2025-11-23.
- Anna Ruggero was added as committer on 2026-06-16

## Project Activity:
Recent releases: No new release in the quarter.

Areas of development & interest:
* API renovation and migration continue
* Dense vector search improvements and new features are catching up with
  Apache Lucene (thanks to various sponsors)
* Preparing Case Studies to be added to the Solr website
* Apache Solr MCP server
* Solr orbit  - Performance benchmarking

## Community Health:

dev@solr.apache.org had a 1% increase in traffic in the past quarter (285
emails compared to 280)
users@solr.apache.org had a 43% decrease in traffic in
the past quarter (88 emails compared to 152)
96 JIRA tickets opened and 83
closed in the past quarter.
The quarter has been quite active thanks to
various initiatives:
- Conferences: Haystack US (https://archive.haystackconf.com/2026/) Berlin
  Buzzwords (https://2026.berlinbuzzwords.de/schedule/)
- Apache Solr 10: What's Coming up for Vector Search (Alessandro Benedetti,
  Ilaria Petreti, Anna Ruggero)
- OSS Security: Lessons from 10+ Years at Apache Solr (Jason Gerlowski)
- Zero downtime index upgrade in Apache Solr (Rahul Goswami) MICES
  (https://mices.co/#programme)
- Precision vs. Recall: When Good Enough Beats Perfect (Arne Vogt)

On top of the explicit talks in Berlin, Apache Solr was at the centre of many
offline discussions during dinners and networking sessions of all such
conferences. The community feels healthy, active and with new contributors
(that hopefully will become committers).


-----------------------------------------
Attachment BY: Report from the Apache Spark Project  [Matei Zaharia]

## Description:
The mission of Spark is the creation and maintenance of software related to
large-scale data processing and machine learning.

## Project Status:
- Project state: Ongoing, with high activity. We made six software releases in
  the last quarter and added four committers and one PMC member.
- Issues for the board: None.
- We started using https://reporter.apache.org/ instead of the Board Agenda
  Tool to organize our report, so hopefully it will have the expected sections
  now, but let us know if anything is missing.

## Membership Data:
Apache Spark was founded 2014-02-18 (12 years ago)
There are currently 103 committers and 65 PMC members in this project.
The Committer-to-PMC ratio is roughly 7:5.

Community changes, past quarter:
- Peter Toth was added to the PMC on 2026-05-20
- Tian Gao was added as committer on 2026-05-28
- Szehon Ho was added as committer on 2026-05-28
- Uroš Bojanić was added as committer on 2026-06-02
- Yicong Huang was added as committer on 2026-05-26

## Project Activity:
- The Spark 4.3 release branch has been cut. Spark 4.3 is the first feature
  release under the new quarterly release cadence, with QA planned for
  mid-August and release candidates planned for late August.
- The following major Spark Improvement Proposals (SPIPs) were accepted
  through public discussions and votes. a. NEAREST BY Top-K Ranking Join b.
  Faster queries in local laptop mode for Apache Spark c. Timestamps with
  nanosecond precision d. OIDC Credential Propagation e. Write schema
  narrowing for column-level UPDATE and MERGE in DSv2 f. Cloud Credential
  Refresh and Distribution Without Kerberos
- Releases in the past quarter:
   - Apache Spark Kubernetes Operator 1.0.0 was released on Jul 26, 2026. This
     was the first stable release of the Kubernetes operator.
   - Apache Spark Connect Swift Client 0.7.0 was released on Jul 25, 2026.
   - Apache Spark 3.5.9 was released on Jul 16, 2026.
   - Apache Spark 4.1.3 was released on Jul 15, 2026.
   - Apache Spark 4.0.4 was released on Jul 15, 2026.
   - Apache Spark 4.2.0 was released on Jul 14, 2026.

## Community Health:
- Overall community health is good.
- Development and governance activity remained high during the reporting
  period. Apache Spark 4.2.0 addressed more than 1,700 JIRA tickets, with
  contributions from more than 250 individuals.
- New contributors also continued to engage on the development mailing list
  and receive guidance from established contributors. No community health
  concerns were identified.
- The project added four new committers (Szehon Ho, Yicong Huang, Tian Gao,
  and Uroš Bojanić), and one new PMC member (Peter Toth).
- The project made 6 releases and voted to accept 6 major Spark Improvement
  Proposals (SPIPs), as described in the previous section.
- Mailing list stats:
   - dev@spark.apache.org had a 17% increase in traffic in the past quarter
     (635 emails compared to 539)
   - issues@spark.apache.org had a 31% increase in traffic in the past quarter
     (9630 emails compared to 7306)
   - reviews@spark.apache.org had a 30% increase in traffic in the past
     quarter (16179 emails compared to 12438)
   - 1841 JIRA tickets opened and 1733 closed in the past quarter.

## Trademarks:
- No changes since the last report.


-----------------------------------------
Attachment BZ: Report from the Apache Steve Project  [Greg Stein]


-----------------------------------------
Attachment CA: Report from the Apache StormCrawler Project  [Richard Zowalla]

## Description:
The mission of Apache StormCrawler is the creation and maintenance of software
related to an open source collection of resources for building low-latency,
scalable web crawlers on Apache Storm.

## Project Status:
Current project status: Active
Issues for the board: None

## Membership Data:
Apache StormCrawler was founded 2025-05-21 (a year ago)
There are currently 12 committers and 6 PMC members in this project.
The Committer-to-PMC ratio is 2:1.

Community changes, past quarter:
- No new PMC members. Last addition was Dávid Szigecsán on 2026-03-03.
- Davide Polato was added as committer on 2026-05-11.

## Project Activity:
External contributions continue to arrive at a steady pace. A new release
manager has stepped up and is currently working on getting the next release
out. In parallel, discussions around StormCrawler 4.0.0 are underway, with
the current proposal targeting Apache Storm 3.0.0 as the baseline and moving
to Java 25 in order to take advantage of virtual threads.

Recent releases:
stormcrawler-3.7.0 was released on 2026-08-01.
stormcrawler-3.6.0 was released on 2026-05-26.
stormcrawler-3.5.1 was released on 2026-01-25.

## Community Health:
The StormCrawler community remains active and stable. External contributions
continue to arrive, and the addition of Davide Polato as a new committer
during the quarter is a positive signal of community growth. He also stepped
up as  release manager and prepared his first StormCrawler release. Early
discussions around a 4.0.0 release, including a modernized baseline on Storm
3.0.0 and Java 25, indicate healthy forward planning within the community.


-----------------------------------------
Attachment CB: Report from the Apache StreamPipes Project  [Philipp Zehnder]

## Description:
The mission of Apache StreamPipes is the creation and maintenance of software
related to a self-service Industrial IoT toolbox which enables non-technical
users to connect, analyze and explore IoT data streams

## Project Status:
Current project status: Ongoing
Issues for the board: None

## Membership Data:
Apache StreamPipes was founded 2022-11-16 (4 years ago)
There are currently 35 committers and 16 PMC members in this project.
The Committer-to-PMC ratio is roughly 9:4.

Community changes, past quarter:
- No new PMC members. Last addition was Sven Oehler on 2025-10-30.
- Jacqueline Höllig was added as committer on 2026-06-08

## Project Activity:
- Extended the functionality of the Python client
- Continued harmonizing functionality and user interaction across different
  StreamPipes resource types to provide a more consistent user experience.
- Added support for shortcuts to enable faster navigation and more efficient
interaction with frequently used functionality.

## Community Health:
- Community activity remains stable, with ongoing contributions and discussions.


-----------------------------------------
Attachment CC: Report from the Apache Subversion Project  [Nathan Hartman]

## Description:

The Apache Subversion® version control system exists to be universally
recognized and adopted as an open-source, centralized version control
solution characterized by its reliability as a safe haven for valuable
data; the simplicity of its model and usage; and its ability to
support the needs of a wide variety of users and projects, from
individuals to large-scale enterprise operations.

## Project Status:

Current project status: Ongoing, mature.
Issues for the board: None at this time.

## Membership Data:

Apache Subversion was founded 2010-02-16 (16 years ago). Prior to
joining ASF, the project began in February of 2000 (26 years ago).

There are currently 92 committers and 50 PMC members in this project.
The Committer-to-PMC ratio is roughly 3:2.

Community changes, past quarter:
- No new PMC members. Last addition was Ivan Zhakov on 2026-04-19.
- Jordan Peck was added as committer on 2026-06-22

## Project Activity:

This has been one of the busiest quarters in recent memory, in the run
up to the long-awaited 1.15.0 release. This release is coming soon!

Release management activities are ongoing and the third Release
Candidate (RC) artifacts, 1.15.0-rc3, were published on 20 July 2026.
The RC artifacts are provided for testing by the wider community for
the duration of a "soak" period. We estimate the final 1.15.0 release
could be published in August.

Though 1.15.0 is considered a "minor" release in the technical terms
of semantic versioning (semver), it is quite a major event for the
Subversion community. The new features coming in 1.15.0, a culmination
of six years of hard work, build on Subversion's existing strengths,
such as its ability to handle huge repositories and huge files, to
make Subversion even more effective at these use cases. We have heard
from users who have multi-terabyte repositories containing multi-
gigabyte files.

The earlier 1.14.x release line continues to be maintained and will
remain supported until six months after 1.15.0 is released, per our
new release support roadmap:
  https://subversion.apache.org/roadmap.html#support-period

During this quarter, the codebase has been improved in numerous areas.
Some of the following items have been backported to the 1.15.x branch
or proposed for backport. Others are scheduled for a future 1.16.0
release.

Codebase improvements:
- Updated JavaHL bindings
- svnbrowse, an upcoming Text User Interface (TUI) repository browser
- Test suite: XML schema validation
- Test suite: Many new tests added
- Improved UTF8 and codepage conversion
- Build system improvements (Autoconf, CMake, vcproj/vcxproj)
- UX improvements for 'svn ls', 'svn blame', 'svn --version --verbose'
- mod_dav_svn improvements and bugfixes
- Improved release manager tooling
- Improved backport management tooling
- Numerous code correctness fixes
- Updated Chinese and Swedish translations

Other activities:
- Backport management
- Ideas are being pursued on several experimental branches
- Improved testing in GitHub Actions CI
- Documentation improvements
- Website improvements
- Work on the 1.15 release notes

Significant housecleaning has been taking place, including the removal
of obsolete tooling, scripts, branches, and the unmaintained ctypes
bindings.

In addition, an important discussion is taking place about the future
removal of Subversion's Berkeley DB (BDB)-based repository backend.
This backend has been deprecated since Subversion 1.8 (released in
2013) and was superseded as the default by the newer FSFS backend
since Subversion 1.2 (released in truly ancient times). So far, no one
has disputed that the BDB backend should be (eventually) removed. The
discussion has been mostly about whether to remove it in a 1.16.0
release, or whether its removal necessitates bumping the major version
number. For now, the impending removal of the BDB backend is
documented in the 1.15 release notes, without committing to removing
it by a specific version. The discussion is archived here:
  https://lists.apache.org/thread/xxbwf4ltkq3zl04w03kc8o2jsgs5nmfo
(and in other public archives). Interested parties are encouraged to
participate.

## Community Health:

Activity tends to be especially strong in the run-up to releases. This
has been even more noticeable for the 1.15.0 release, with activity
increasing noticeably in every quarter for the last three quarters.
The codebase, website, and project infrastructure continue to be
improved. Altogether, the community appears healthy for a mature and
stable project.

Our community is fully volunteer-driven and we would like to thank
everyone for their support.


-----------------------------------------
Attachment CD: Report from the Apache Superset Project  [Maxime Beauchemin]

## Description:
The mission of Apache Superset is the creation and maintenance of software
related to data exploration, analysis, visualization, and dashboarding

## Project Status:
Current project status: Ongoing, high activity. More
contributors/contributions than ever, and the project is still aspiring to
reach many new potential future opportunities in the market. Still struggling
with limited support from a small number of the large Committer/PMC roster
members, but that's not new.

Issues for the board: None

## Membership Data:
Apache Superset was founded 2020-11-17 (6 years ago) There are currently 78
committers and 39 PMC members in this project. The Committer-to-PMC ratio is
2:1.

Community changes, past quarter:
- Pedro Sousa was added as committer on 2026-06-01, then added to the PMC on
  2026-08-12

## Project Activity:
Security fixes are being reviewed now, hoping to have it all behind us soon.

Since the last report, we've gone from around 600 Issues and 600 open PRs to
220 open Issues and 364 open PRs (95 of which target those Issues)

CI is consuming FAR less ASF resources, and we're continuing to dial in both
stability and efficiency.

Kubernetes operator is fully operational, and we're deprecating the legacy
Helm chart support slowly but surely. kubernetes-operator-0.2.0 was released
on 2026-08-11. kubernetes-operator-0.1.1 was released on 2026-06-29.
kubernetes-operator-0.1.0 was released on 2026-06-10.

Superset 7.0 is well underway, we're cutting the release imminently. We
anticipate it will ship with lots of goodies:
• All legacy visualizations migrated to the newer chart architecture and
  endpoints and viz frameworks
• Full translation of existing languages, and a few new ones
• Migration to SQLAlchemy 2.0
• Asset versioning, soft deletion
• Core library upgrades like AntD V6, ECharts v6, and others
• ...and much more!

Extensions architecture/implementation continues to build speed and show
massive potential for the next era of the project as an AI-driven analytics
platform.

## Community Health:
Github's going bonkers... a few of us trying to conquer the legacy backlog,
mainly, but also lots of new work happening in parallel.

Slack growth and GitHub stars have both slowed down... not quite sure why, but
I expect it's global attention toward AI madness, more so than any practice
that's changed among the PMC or the community itself.

dev@superset.apache.org had a 59% increase in traffic in the past quarter (129
emails compared to 81) notifications@superset.apache.org had a 62% increase in
traffic in the past quarter (32440 emails compared to 19921)

All is well, and improving.


-----------------------------------------
Attachment CE: Report from the Apache Syncope Project  [Francesco Chicchiriccò]

## Description:
The mission of Syncope is the creation and maintenance of software related to
Managing digital identities in enterprise environments

## Project Status:
Current project status: healthy.
Issues for the board: none.

## Membership Data:
Apache Syncope was founded 2012-11-21 (14 years ago)
There are currently 27 committers and 13 PMC members in this project.
The Committer-to-PMC ratio is roughly 7:4.

Community changes, past quarter:
- No new PMC members. Last addition was Lorenzo Di Cola on 2023-05-22.
- No new committers. Last addition was Alberto Bogi on 2025-11-07.

## Project Activity:
We are maintaining the 4_0_X and 4_1_X branches. The master branch is hosting
the next development phase.

Security:
* CVE-2026-63071
* CVE-2026-62418
* CVE-2026-62183
* CVE-2026-57308
* CVE-2026-53421
* CVE-2026-53405

Recent releases:
* 4.1.2 was released on 2026-07-20
* 4.0.6 was released on 2026-07-20
* 4.1.1 was released on 2026-03-31
* 4.0.5 was released on 2026-03-31

## Community Health:
We are observing the user@ mailing list traffic slowing down, possibly because
of the holiday season.

On the opposite side, dev@ keeps steady, especially because of JIRA, Pull
Requests and commit notifications.


-----------------------------------------
Attachment CF: Report from the Apache SystemDS Project  [Matthias Boehm]

## Description:
Apache SystemDS is a machine learning (ML) system for the end-to-end
data science lifecycle from data preparation and cleaning, over
efficient ML model training, to scoring and debugging. ML algorithms
or pipelines are specified in a high-level language with R-like syntax,
or related Python and Java APIs, and the system automatically generates
hybrid runtime plans of local, in-memory operations and distributed
operations on Apache Spark.

## Project Status:
- Just released SystemDS 3.4 and in process of definining GenAI policy
- Current work focuses on adding the missing primitives for a number
  benchmarks, a new API for the alignment of multimodal datasets (scuro),
  a new backend for singlenode out-of-core operations, and incremental
  refinements of major internal components for compression, GPUs,
  federated operations, and the use of the Java vector API.

## Membership Data:
- Apache SystemDS was founded 2017-05-16 (incubator process entered
  2015-11-02)
- Last PMC members added 2026-01-07 (Christina Dionysio)
- Last committers added 2026-01-07 (Jannik Lindemann, Rene Enjilian)
- There are currently 39 committers and 29 PMC members in the project.

## Project Activity:
- Code activity is healthy with 89 commits (+82%) in the last 3 months.
- Community growth is healthy with 13 active contributors (-35%)
  in the last 3 months
- Releases
  Apache SystemDS 3.4.0 was released on 2026-07-24.
  Apache SystemDS 3.3.0 was released on 2025-04-22.
  Apache SystemDS 3.2.0 was released on 2024-03-17.
  Apache SystemDS 3.1.0 was released on 2023-03-13.
  Apache SystemDS 3.0.0 was released on 2022-06-20.
  Apache SystemDS 2.2.2 was released on 2022-06-25.
  Apache SystemDS 2.2.1 was released on 2021-12-02.
  Apache SystemDS 2.2.0 was released on 2021-10-30.
  Apache SystemDS 2.1.0 was released on 2021-06-28.
  Apache SystemDS 2.0.0 was released on 2020-10-14.
  Apache SystemML 1.2.0 was released on 2018-08-24.

## Community Health:
- Communication is healthy, mailing list activity is improving,
  additional work on better documentation.


-----------------------------------------
Attachment CG: Report from the Apache Tcl Project  [Georgios Petasis]


-----------------------------------------
Attachment CH: Report from the Apache TomEE Project  [David Blevins]

## Description:

The mission of TomEE is the creation and maintenance of software related to
the Jakarta EE Web Profile and Platform built on Apache Tomcat

## Project Status:

Current project status: Ongoing
Issues for the board: None

## Membership Data:
Apache TomEE was founded 2007-05-15 (19 years ago)
There are currently 36 committers and 13 PMC members in this project.
The Committer-to-PMC ratio is roughly 9:4.

Community changes, past quarter:
- No new PMC members. Last addition was Markus Jung on 2025-07-27.
- No new committers. Last addition was Markus Jung on 2024-09-12.

## Project Activity:

Jakarta EE 11 is the current focus on main, with Jakarta EE 10 and TomEE 10 in
maintenance mode.

The TCK setup for the Jakarta EE 11 Platform and WebProfile was largely
rewritten from the legacy JavaTest framework that had existed in the Platform
TCK for 25 years to a newer stack based on  Arquillian, JUnit 5 and Maven.
This rendered our tck setup for the Platform and WebProfile to be obsolete.
The project created a new TCK setup in the tomee-tck repository and can now
run the new Jakarta EE 11 Web Profile TCK.  TomEE Plus and Plume are
effectively Jakarta EE Platform implementations, so we would have need of a
Platform harness eventually.  The new setup is significantly simpler and about
a 1/3 the size of the old tck setup code.  It's a pleasure to see it go.

TomEE 11.0.0-M1, our first milestone targeting Jakarta EE 11 and MicroProfile
7.1, was released June 16th.  The 10.x line is in maintenance mode: TomEE
10.2.0 was released July 17th, bumped to a new minor version because the
Johnzon upgrade carried behavioral changes. The same question is open again
for Johnzon 2.2.0 and a potential 10.3.x.

## Community Health:

Overall contributions are still low for a project of our scope, but this
is our most active period in a few years.  Roughly 210 commits from 6
contributors in the 2 months since June 10th, about half of which are
automated dependency upgrades.  Our February report noted 30 commits
from 4 committers over 3 months.  Nearly all substantive work is on
TomEE 11 and the new TCK harness; the 10.x branch received just 9
substantive commits.


-----------------------------------------
Attachment CI: Report from the Apache Traffic Server Project  [Bryan Call]

## Description:
The mission of Traffic Server is the creation and maintenance of a
high-performance, scalable HTTP/1.1 and HTTP/2 caching proxy server that
powers major CDNs worldwide.

## Project Status:
Current project status: Ongoing
Issues for the board: none

## Membership Data:
Apache Traffic Server was founded 2010-04-20 (16 years ago)
There are currently 72 committers and 58 PMC members in this project.
The Committer-to-PMC ratio is roughly 9:8.

Community changes, past quarter:
- No new PMC members. Last addition was Mo Chen on 2024-04-15.
- No new committers. Last addition was Jake Champion on 2026-04-06.

## Project Activity:
This was our most active quarter in over a year.

Traffic Server now builds against OpenSSL 4.0. That migration ran across
two quarters and let us delete a large amount of code the new library no
longer supports. We added HTTP/3 over TCP, so operators can offer HTTP/3 on
networks that block the UDP traffic QUIC needs. The in-memory cache index
now survives a restart instead of being rebuilt from disk, which turns a
multi-minute startup into milliseconds on a large cache.

We shipped four releases this quarter. 9.2.14 and 10.1.3 were announced on
July 15 and fixed a single denial of service issue. 9.2.15 and 10.1.4
followed on July 28 and 29 and resolved 151 security findings, published as
38 CVEs. This was by a wide margin the largest security release the project
has done.

The volume of that security work pushed our feature releases back. 10.2.0
is in vote this week. ATS 11.0.0 has been deferred and does not have a
target date.

Development activity grew by every measure. Comparing the 15 weeks since
the last report against the 15 weeks before it, contributors went up 14%
(22 -> 25) and pull requests merged to master went up 26% (199 -> 250).
Commits went up 92% (208 -> 399), growing faster than pull requests because
the security fixes were prepared privately and landed in batches.

## Community Health:
We held a virtual ATS Summit on May 20-21, 2026, over two half-days. Topics
covered the release roadmap, the OpenSSL migration, the state of HTTP/3,
and a proposal to improve our logging.

We continue to hold weekly bug and issue scrubs every Monday.

The issue backlog shrank sharply, mostly from a deliberate effort to work
through the oldest issues rather than a change in incoming volume. Issues
closed went up 243% (60 -> 206) while issues opened held flat (44 -> 44).
That leaves 217 issues and 67 pull requests open.


-----------------------------------------
Attachment CJ: Report from the Apache TsFile Project  [Jialin Qiao]


-----------------------------------------
Attachment CK: Report from the Apache Turbine Project  [Georg Kallidis]

## Description:

The mission of Turbine is the creation and maintenance of software related to A
Java Servlet Web Application Framework and associated component library

## Project Status:
Current project status: Ongoing
Issues for the board: None

## Membership Data:
Apache Turbine was founded 2007-05-16 (19 years ago)
There are currently 12 committers and 9 PMC members in this project.
The Committer-to-PMC ratio is 4:3.

Community changes, past quarter:
- No new PMC members. Last addition was Jeffery Painter on 2017-11-12.
- No new committers. Last addition was Youngho on 2021-12-06.

## Project Activity:

No releases up to now this year. Major release process is taking usually for
Turbine about 18 months to be completed, starting with the first components
(parent, core dependencies) about after one year. We are now about half a year
after the last major release component was published, with currently having
already one major change almost finished (decoupling logging) and more
smaller changes to be expected. ATR checking at least for some release
candidates is in consideration.

## Community Health:

Activity in contributions and mailing lists continue on a low level. Latest
issues and changes are about completing logging decoupling, which may still
get some attention/discussion before the next release.

With the release of the last component end of December Apache Trusted Releases
(ATR) were mentionend in the turbine-dev mailing list. This will
probably discussed again, due to security considerations, when starting with
the first next release components.


-----------------------------------------
Attachment CL: Report from the Apache Uniffle Project  [He Qi]

## Description:
The mission of Apache Uniffle is the creation and maintenance of software
related to a unified remote shuffle service

## Project Status:
Current project status: Ongoing Issues for the board: No

## Membership Data:
Apache Uniffle was founded 2025-02-19 (a year ago) There are currently 24
committers and 14 PMC members in this project. The Committer-to-PMC ratio is
roughly 3:2.

Community changes, past quarter:
- No new PMC members. Last addition was Xianjing Feng on 2025-05-07.
- No new committers. Last addition was Lu Yuan on 2025-04-10.

## Project Activity:

Development activity continued at a steady maintenance pace during the
quarter. From 2026-05-10 to 2026-08-10, the project merged 14 pull requests,
created 11 issues, closed 11 issues, and recorded 14 commits on GitHub.

The main technical work this quarter focused on:
- Spark compatibility improvements, including support for Spark 4.0.2, Spark
  4.1, and Spark 4.2.
- Spark shuffle client fixes and cleanup, including failed-block handling,
  unregister behavior, synchronization cleanup, and spill-ratio handling.
- CI and test stability improvements, including fixes for Kubernetes operator
  envtest downloads, flaky ShuffleBufferManagerTest behavior, and RPC random
  port fallback reliability.
- Dependency and build maintenance, including switching to the Hadoop shaded
  client and updating GitHub Actions usage to comply with Apache allow-list
  requirements.

## Community Health:

The community remains healthy and responsive. Development discussions and code
reviews continue to happen through the normal Apache channels and GitHub pull
requests. The project handled user-facing compatibility work for newer Spark
versions and continued to address CI reliability and maintenance issues.

There were no changes to PMC or committer membership during the quarter, but
external contributor activity is still visible in the issue and pull request
flow. The project has no board-level concerns at this time.


-----------------------------------------
Attachment CM: Report from the Apache Velocity Project  [Nathan Bubna]


-----------------------------------------
Attachment CN: Report from the Apache Wayang Project  [Zoi Kaoudi]

## Description:
The mission of Apache Wayang is the creation and maintenance of software
related to cross-engine data processing that aims at (i) decoupling
applications from underlying data processing engines, such as Apache Flink,
Apache Spark, databases, or ML systems, and (ii) automatically determining the
optimal combination of engines to execute a given data pipeline using an
optimizer

## Project Status:
Current project status:Apache Wayang graduated from the Apache Incubator and
became a Top-Level Project (TLP) on 2025-11-19. The graduation was preceded by
the 1.0.0 (early 2025) and 1.1.0 (mid-2025) releases, the latter of which was
explicitly aimed at meeting graduation requirements. The project is now
operating under its own PMC.

The last release (a minor/point release) shipped in February 2026. Since then
the community has merged a substantial number of PRs, and in late May the PMC
began discussing a major 1.2.0 release to ship a new spatial data processing
plugin along with other accumulated work

Notable in-progress/landed work this quarter includes a new JDBC driver
(WAYANG-55, PR #719) enabling standard SQL-tooling access to Wayang, and
continued work toward a datalake-friendlier platform support
— both originating as Google Summer of Code project ideas.

Issues for the board: None at this time.

## Membership Data:
Apache Wayang was founded 2025-11-19 (8 months ago)
There are currently 18 committers and 9 PMC members in this project.
The Committer-to-PMC ratio is 2:1.

Community changes, past quarter:
- No new PMC members.
- No new committers were added.

## Project Activity:
Development activity remained steady this quarter, with enough PRs merged
since the February release that the community is now planning a major 1.2.0
release. Highlights:
- A new JDBC driver for Wayang (WAYANG-55 / PR #719), begun as a GSoC-inspired
  contribution and continued independently by the contributor afterward.
- Continued design discussion and early implementation work on a DataFrame API
  (proposed as a new wayang-dataframe module) and on making Wayang more
  datalake-friendly, both active topics on the dev list.
- Apache Wayang is participating in Google Summer of Code 2026 as a mentoring
  project under the ASF umbrella, with project ideas published for a DataFrame
  API, a datalake backend, and additional execution-engine backends.
- New PRs (#772,#773, and #774) for adding BigQuery, Presto, and Trino and new
  computation engines.
- Talk and hackathon is being prepared for the CoC at Glasgow in October.


## Community Health:
The mailing list saw healthy prospective-contributor traffic this quarter,
driven largely by GSoC 2026 interest: at least five prospective contributors
(from India, the US, and elsewhere) introduced themselves on dev@ between
February and March 2026, several proposing concrete project ideas (DataFrame
API, datalake support) and at least one already landing a merged PR (#710,
for issue #649) before formally applying to GSoC. This is a healthy pipeline
of potential new committers, though it hasn't yet converted into new
committers or PMC members this quarter. We hope this changes after the GSoC is
finalized.


-----------------------------------------
Attachment CO: Report from the Apache Whimsy Project  [David Fisher]

## Description:
The mission of Apache Whimsy is the creation and maintenance of software
related to tools that help automate various administrative tasks or
information lookup activities

## Project Status:
Current project status: Dormant Issues for the board: None

## Membership Data:
Apache Whimsy was founded 2015-05-19 (11 years ago) There are currently 13
committers and 11 PMC members in this project. The Committer-to-PMC ratio is
roughly 7:6.

Community changes, past quarter:
- No new PMC members. Last addition was Dave Fisher on 2025-07-15.
- No new committers. Last addition was Dave Fisher on 2025-07-16.

## Project Activity:
A few minor fixes during the quarter including work on listing and
pre-commits. Org chart is surfaced. Petri cultures are retired. Perparations
for code removal due to Board Agenda Tool being in production.

## Community Health:
Commits from three contributors this month. Otherwise the usual sporadic
changes.


-----------------------------------------
Attachment CP: Report from the Apache Xalan Project  [Gary D. Gregory]

## Description:
Apache Xalan exists to promote the use of XSLT. We view XSLT (Extensible
Stylesheet Language Transformations) as a compelling paradigm that transforms
XML documents, thereby facilitating the exchange, transformation, and
presentation of knowledge. The ability to transform XML documents into usable
information has great potential to improve the functionality and use of
information systems. We intend to build freely available XSLT processing
components in order to engender such improvements.

## Project Status:
Current project status: Ongoing.
Issues for the board: None.

## Membership Data:
Apache Xalan was founded 2004-09-30 (22 years ago)
There are currently 57 committers and 5 PMC members in this project.
The Committer-to-PMC ratio is roughly 8:1.

Community changes, past quarter:
- No new PMC members. Last addition was Joseph Kessselman on 2023-08-07.
- No new committers. Last addition was Joseph Kessselman on 2023-06-29.

## Project Activity:
Our project activity is low but there is technical progress being made, albeit
slowly. There have not been new releases but we've published a
presentation "XSLT 3.0 xsl:fork instruction" to our website from the Balisage
Conference 2026, Open Micfrom August 6:
https://xalan.apache.org/xalan-j/xsl3/xsl_fork_balisage_conf_2026.pdf.
Work towards XSLT 3.0 support continues.

## Community Health:
I would rate our health as low due to the small number of active participants
and lack of releases. There is a small decrease in messages on the mailing
list from an amount of traffic that is already low. A handful of Jira ticket
have been opened. I remain hopeful and the desire exists amonst the PMC to
continue work and pupblish releases.


-----------------------------------------
Attachment CQ: Report from the Apache Xerces Project  [Michael Glavassevich]


-----------------------------------------
Attachment CR: Report from the Apache XML Graphics Project  [Clay Leeds]

## Description:
Apache XML Graphics exists to promote the use of XML. We view XML as a
compelling paradigm that structures data as information, thereby facilitating
the exchange, transformation, and presentation of knowledge. The ability to
transform raw data into usable information has great potential to improve the
functionality and use of information systems. We intend to build freely
available products for the conversion of XML to graphical output and closely
related technologies in order to engender such improvements.

## Project Status:
Current project status:
* No new releases since the last Board Report

Issues for the board: We are still working to resolve a trademark issue for
FOP was identified related to a NuGet package name[1] and we are working
through resolution with help from trademarks@.

[1] FOP.dll 1.1.0 https://www.nuget.org/packages/FOP.dll


## Membership Data:
Apache XML Graphics was founded 2004-10-19 (22 years ago)
There are currently 22 committers and 12 PMC members in this project.
The Committer-to-PMC ratio is 2:1.

The latest versions of Apache XML Graphics Project subprojects were released 2025-05-06:

* Apache Batik 1.19
* Apache FOP 2.11
* Apache FOP PDF Images 2.11
* Apache XML Graphics Commons 2.11

## Community changes, past quarter:

* Newest PMC member Joao Andre Goncalves added 2026-04-08.
* No new committers. Last addition was Joao Goncalves on 2024-11-12.

## Project Activity:

* Latest versions are Apache Batik 1.19, Apache FOP 2.11, Apache FOP PDF Images 2.11 and
  Apache XML Graphics Commons 2.11
* All XMLGraphics project repositories have been migrated from Subversion to
  GitHub/GitBox: https://github.com/apache/xmlgraphics-fop.git
* A proposal to migrate XMLGraphics projects from Jira to GitHub issues was
  passed. Preliminary work to effect this migration has started. The migration
  is ongoing.

Latest Versions of Apache XML Graphics Project Sub Projects:

* Apache Batik 1.19 2025-05-06
* Apache FOP 2.11 released 2025-05-06
* Apache FOP PDF Images 2.11 released 2025-05-06
* Apache XML Graphics Commons 2.11 released 2025-05-06

We have migrated the Apache XML Graphics repositories for Apache XML Graphics
Commons, FOP, FOP PDF Images and Batik to GitHub:

https://github.com/apache/xmlgraphics-commons.git
https://github.com/apache/xmlgraphics-fop.git
https://github.com/apache/xmlgraphics-fop-pdf-images.git
https://github.com/apache/xmlgraphics-batik.git

## Community Health:
The level of community and developer activity remains at a consistent,
moderate, level with respect to the previous reporting period.


-----------------------------------------
Attachment CS: Report from the Apache YuniKorn Project  [Wilfred Spiegelenburg]

## Description:
The mission of Apache YuniKorn is the creation and maintenance of software
related to a standalone resource scheduler responsible for scheduling batch
jobs and long-running services on large scale distributed systems running in
on-premises environments as well as different public clouds

## Project Status:
Current project status: Ongoing, with high activity.
Issues for the board: none

## Membership Data:
Apache YuniKorn was founded 2022-03-16 (4 years ago)
There are currently 39 committers and 29 PMC members in this project.
The Committer-to-PMC ratio is roughly 5:4.

Community changes, past quarter:
- No new PMC members. Last addition was Chia-Ping Tsai on 2024-03-07.
- No new committers. Last addition was Mit Desai on 2025-11-12.

## Project Activity:
Recent releases:
1.9.0 was released on 2026-07-29.
1.8.0 was released on 2026-02-04.
1.7.0 was released on 2025-07-28.

Release 1.9.0 was just finished and will shortly be followed by the next minor
release 1.10.0 to add the current Kubernetes version and prepare for a further
release before Christmas to support the next Kubernetes release due out in
November.

## Community Health:
12 new Jira accounts created. Part of the new interest is coming from the
open-source community in Taiwan via Chia-Ping our PMC member.

72 new Jiras created and 86 resolved, with corresponding GitHub PRs:
113 created and 95 resolved. An increase compared to the last quarter as
features and fixes landed for the 1.9 beta and 1.9.0 release.

Planning for the major items part of the 1.10.0 release has been finished.
Code changes for some major items have already landed. The release will be
focussed on Kubernetes support to catch up with the upstream Kubernetes
releases.
Next two planned releases: 1.10 (Aug/Sep) and 1.11 (late Nov)


-----------------------------------------
Attachment CT: Apache Software Foundation Code of Conduct  [None]

## Our Pledge

We, as participants in the Apache Software Foundation, including contributors,
committers, Project Management Committee (PMC) members, ASF Members, and
officers, pledge to make participation in our community a harassment-free
experience for everyone, regardless of age, body size, visible or invisible
disability, ethnicity, sex characteristics, gender identity and expression,
level of experience, education, socio-economic status, nationality, personal
appearance, race, caste, color, religion, or sexual identity and orientation.

We pledge to act and interact in ways that contribute to an open, welcoming,
diverse, inclusive, and healthy community.

## Our Standards

Examples of behavior that contributes to a positive environment for our
community include:

* Demonstrating empathy and kindness toward others
* Being respectful of differing opinions, viewpoints, and experiences
* Giving and gracefully accepting constructive feedback
* Accepting responsibility and apologizing to those affected by our mistakes,
  and learning from the experience
* Focusing on what is best not just for us as individuals, but for the ASF and
  the overall community

Examples of unacceptable behavior include:

* The use of sexualized language or imagery, and unwelcome sexual attention
  or advances
* Trolling, insulting or derogatory comments, and personal or political attacks
* Public or private harassment
* Publishing others’ private information (such as a physical or email address)
  without explicit permission
* Other conduct which could reasonably be considered inappropriate in a
  professional or open source setting

## Enforcement Responsibilities

Each ASF Project Management Committee (PMC) is responsible for clarifying and
enforcing standards of acceptable behavior within their community, and may
take appropriate and fair corrective action in response to any behavior that
is inconsistent with this Code of Conduct.

PMC members have the right and responsibility to remove or reject comments,
commits, code, wiki edits, issues, and other contributions that are not
aligned with this Code of Conduct, and to communicate reasons for their
decisions when appropriate.

For matters that go beyond the scope of a single project or raise
Foundation-wide concerns, the ASF President (or their designee) may investigate
and take appropriate action, or escalate to the ASF Board or an ASF Officer if
necessary.

## Recusal

To preserve fairness and avoid conflicts of interest, any PMC member,
ASF officer, or Member who is directly involved in or personally connected to
a reported incident must recuse themselves from participating in the review,
decision-making, or enforcement process. This includes cases where the
individual is a party to the report, has a close personal or professional
relationship with one of the parties, or may otherwise be perceived as lacking
impartiality. In such circumstances, responsibility for handling the report
should be delegated to uninvolved PMC members or escalated as appropriate.

## Scope

This Code of Conduct applies to all ASF projects, mailing lists, source code
repositories, issue trackers, events, chat services and community spaces,
whether official or unofficial, and also applies when individuals are
representing ASF or its projects in public spaces. Representation may include
using an official ASF email address, posting via an official project or
Foundation social media account, or serving as a delegate at an online or
offline event. It also applies to ASF-wide channels, including the
members@apache.org mailing list, ASF chat services, and other internal
platforms.

## Reporting Guidelines

While all participants should adhere to this Code of Conduct, we recognize that
people may have a bad day or be unaware of the guidelines. When that happens,
you may respond by pointing out the Code of Conduct. This can be done in public
or private, as appropriate, but all responses should themselves remain
respectful and constructive.

Assume good faith: it's more likely someone is unaware of how their behavior
was received than intentionally trying to be harmful.

For issues that are specific to a single ASF project, reports may be directed
to that project’s Project Management Committee (PMC), typically via its private
mailing list (e.g., `private@project.apache.org`).

If you are unable to resolve the situation, or feel unsafe or uncomfortable
addressing it, you may report compliance issues in confidence to:

* **President of The Apache Software Foundation** (`president@apache.org`)
* **Executive Vice President of The Apache Software Foundation**
* Or one of the ASF’s designated volunteers

The President (or a designated officer) may refer a report to the relevant PMC
if the issue is project-specific, or handle it directly in Foundation-wide
cases. Privacy and discretion will be respected in all cases.

If the concern is about inappropriate content in documentation or code (e.g.,
inappropriate language), please report it privately to the project’s private
mailing list (e.g., `private@project.apache.org`). If you have the necessary
access, consider resolving or removing the concerning material with sensitivity
to the perspective of the reporter.

## Enforcement Process

When a Code of Conduct concern is raised, ASF officers or PMCs will assess the
issue and determine the appropriate response using the following guidelines.

**Note on Frivolous or Malicious Complaints**
The ASF values and encourages good-faith reporting of concerns. While most
reports are raised constructively, knowingly filing false or malicious
complaints, or repeatedly misusing the reporting process, may itself be
treated as a violation of this Code of Conduct.

**1\. No Action**
*Community Impact*: Concerns raised do not represent a violation or do not rise
to the level of requiring intervention.
*Consequence*: No formal correction steps; may include an informational
clarification for awareness.

**2\. Correction**
*Community Impact*: Use of inappropriate language or other behavior deemed
unprofessional or unwelcome in the community.
*Consequence*: A private, written warning, providing clarity around the nature
of the violation and an explanation of why the behavior was inappropriate. A
public apology may be requested.

**3\. Warning**
*Community Impact*: A violation through a single incident or series of actions.
*Consequence*: A warning with consequences for continued behavior. No
interaction with the people involved, including unsolicited interaction with
those enforcing the Code of Conduct, for a specified period of time. This
includes avoiding community spaces and external channels like social media.
Violating these terms may lead to a temporary or permanent ban.

**4\. Temporary Ban**
*Community Impact*: A serious violation of community standards, including
sustained inappropriate behavior.
*Consequence*: A temporary ban from any public interaction with the community.
No public or private interaction with the people involved, including
unsolicited interaction with those enforcing the Code of Conduct, is allowed
during this period. Violating these terms may result in a permanent ban.

**5\. Permanent Ban**
*Community Impact*: A pattern of violating community standards, including
sustained inappropriate behavior, harassment of an individual, or aggression
toward or disparagement of classes of individuals.
*Consequence*: A permanent ban from any form of public interaction within
the community.

In the case of ASF Members, any such action must be consistent with
[ASF Bylaw 4.7](https://www.apache.org/foundation/bylaws.html#termination),
which requires a vote of the Membership to terminate ASF membership. A PMC or
ASF Officer may recommend a temporary exclusion from specific channels or
events pending that process.

## Attribution

This Code of Conduct is adapted from the Contributor Covenant, version 2.1,
available at [https://www.contributor-covenant.org/version/2/1/code\_of\_conduct.html](https://www.contributor-covenant.org/version/2/1/code_of_conduct.html).

Community Impact Guidelines were inspired by Mozilla’s code of conduct
enforcement ladder.


------------------------------------------------------
End of minutes for the August 19, 2026 board meeting.

Index