FINAL DO NOT EDIT

NOTE that the content for this month report is in markdown format- please do not remove any formatting characters when adding your reports.

If your report is missing please use the clutch2report.py script to generate your report.

It also best to:

  • Do not change existing formatting. Especially do not change the formatting of the sign-off area.
  • Keep all lines under 76 characters long.

  • All content under the ### headings should be indented by two spaces. Do not use tabs.

  • Please don't change the text in the headings or add new ones.
  • Include one space after a bullet point or full stop on a numbered list.
  • Use [X] (X and no spaces) to sign off reports.
  • Do not include long URLs and use the apache URL shortener https://s.apache.org.
  • Please note that some lines have two spaces at the end. Do not remove these spaces.

Please make sure you use the current report and don't copy an old one, the headings do change from time to time.

A script will be run on this report before it is submitted to the board. If your lines are too long it may insert line breaks in unexpected places.

Reflow
fold -w 76 -s $1 | cat -s


Timeline

Wed July 01Podling reports due by end of day
Sun July 05Shepherd reviews due by end of day
Sun July 05Summary due by end of day
Tue July 07Mentor signoff due by end of day
Wed July 08

Report submitted to Board

Wed July 15Board meeting


Shepherd Assignments

Calvin KirsAmoro
Dave Fishernone
Drew FarrisPony Mail
Justin McleanResilientDB
P. Taylor GoetzPegasus
PJ FanningFluss
Timothy ChenCaldera
Willem JiangCasbin
XuanwoHugeGraph

Incubator PMC report for July 2026

The Apache Incubator is the entry path into the ASF for projects and codebases wishing to become part of the Foundation's efforts.

There are currently 27 podlings under incubation. In June, the Incubator made two releases, and some release votes are currently underway. There were two additions and no removals to IPMC membership.

Mailing list discussion focused primarily on release voting activity and two graduation discussions: a vote to graduate Apache Fluss is currently underway, and an early discussion on graduating Apache ResilientDB has begun on the general list. A new podling, Ossie, a data semantic specification and framework, was accepted into the Incubator. Three project did not report in time and will be asked to report next month.

During the Fluss graduation discussion, significant concerns were raised about the composition of the proposed PMC, which largely reflected work done prior to donation and contributors' company titles rather than merit earned during incubation. After considerable discussion and encouragement from the IPMC, this was resolved before the vote was called. Apache Fluss' graduation vote has passed, and a board resolution to graduate has been posted.

Caldera is showing very low mailing-list and code activity, and a slow incubator start.

Casbin has 249 GitHub repositories, which is highly unusual for a podling. The podling's response to questions about IP clearance conflated ICLA signing with software grants, and it is not clear that proper software grants have been completed for all repositories. The IPMC is following up.

Baremaps was retired in March 2026. Some post-retirement cleanup is still outstanding.

OpenServerless has not yet made an ASF release despite over two years of incubation. The IPMC has significant concerns about the project and is discussing whether retirement is appropriate.

OzHera released version 2.2.6-incubating in June, addressing the concern raised last month.

PouchDB has yet to correct the redirection of the legacy pouchdb.com site.

Toree has been incubating since December 2015. There was no dev list activity in June. A new release candidate was being prepared in May but there has been no visible progress since.

Pony Mail, which has been incubating since 2016, intends to start graduation discussions. The IPMC continues to monitor long-running podlings and will follow up on any community concerns as needed.

All submitted reports have mentor signoff.

Community

New IPMC members:

  • Danica Fine
  • Russell Spitzer

People who left the IPMC:

  • none

New Podlings

  • Ossie

Podlings that failed to report, expected next month

  • Amoro
  • HugeGraph
  • Pegasus

Graduations

  • none

The board has motions for the following:

  • none

Releases

The following releases entered distribution during the month of June:

  • GeaFlow 0.8.0
  • OzHera 2.2.6

IP Clearance

  • none
  • N/A

Infrastructure

  • N/A

Table of Contents

Caldera
Casbin
Fluss
PonyMail
ResilientDB


Caldera

Caldera provides a modular platform for modeling, scripting, and executing adversary behavior. It allows users to construct emulation plans, provides agents for communicating with the command and control server, and enables users to evaluate security detections in a structured, scalable, and repeatable way. With the use of plug- ins and community-contributed features, Caldera supports a range of use cases including adversary emulation, purple teaming, detection engineering, and continuous security validation. Using Caldera, defenders can emulate known threat actor behavior and perform other red team activity to evaluate their organization’s defensive capabilities, test analytics, and find detection gaps. As a modular tool based on the MITRE ATT&CK framework, Caldera is designed to be extensible, intelligence-driven, and automation-friendly.

Caldera has been incubating since 2025-12-19.

Three most important unfinished issues to address before graduating:

  1. Community Growth
  2. Grow the PPMC

Are there any issues that the IPMC or ASF Board need to be aware of?

No.

How has the community developed since the last report?

Petitioned for an additional PPMC member; in process of vetting and voting on them. Github Stars are over 7.1k.

How has the project developed since the last report?

9 new pull requests were opened on the GitHub repo.

How would you assess the podling's maturity?

Please feel free to add your own commentary.

  •  Initial setup
  •  Working towards first release
  •  Community building
  •  Nearing graduation
  •  Other:

Date of last release:

No Apache release yet.

When were the last committers or PPMC members elected?

At founding/incubation.

Have your mentors been helpful and responsive?

Yes.

Is the PPMC managing the podling's brand / trademarks?

Still working to update third-party references and branding references, including documentation and website references as well as plugin repository mentions and references.

Signed-off-by:

  •  (caldera) Kevin Ratnasekera
    Comments:
  •  (caldera) Francis Chuang
    Comments:
  •  (caldera) PJ Fanning
    Comments: Mailing list traffic is close to non-existent. Git commit activity is minimal. No sign of any momentum.
  •  (caldera) Gordon King
    Comments:

IPMC/Shepherd notes:


Casbin

Casbin is a powerful, efficient open-source access control framework that provides a unified, model-driven approach to authorization. Built on the PERM (Policy, Effect, Request, Matchers) metamodel and its domain-specific language, Casbin brings ACL, RBAC, and ABAC together under one model so that policies can be expressed flexibly and enforced at a fine-grained level. It offers high-performance enforcement and a broad multi-language ecosystem spanning Go, Java, Node.js, Python, .NET, C++, and Rust.

Casbin has been incubating since 2026-02-07.

Three most important unfinished issues to address before graduating:

  1. Complete the first official Apache incubating release.
  2. Clarify repository scope, release plans, and IP/grant coverage for the large set of Casbin repositories under the Apache GitHub organization.
  3. Continue building a diverse, public, mailing-list-centered community and keep project decisions visible on dev@casbin.apache.org.

Are there any issues that the IPMC or ASF Board need to be aware of?

The podling is clarifying repository scope, IP/grant coverage, and release policy expectations for its 249 GitHub repositories. This includes deciding which repositories are intended for ASF releases, which should be archived, and how current GitHub snapshot releases should be handled under ASF release policy.

No board action is requested at this time. The discussion is happening on the public dev list with mentor involvement.

How has the community developed since the last report?

  • dev@ had 10 messages across 3 threads, with 8 participants.
  • The main public discussion was about repository scope, IP/grant coverage, archive decisions, and ASF release policy for snapshot artifacts.
  • The community has also moved the first Apache Casbin release review onto the public dev list. This first RC is for the Go core repository apache/casbin; Apache Casbin 3.11.0-incubating RC1 is currently in the dev@ release vote and review stage.
  • The main apache/casbin repository reached about 20.2k GitHub stars.

How has the project developed since the last report?

  • Across the tracked Casbin Apache GitHub repositories, there were 3 merged PRs and 5 closed issues from 2026-06-01 to 2026-06-28.
  • Main repository work focused on CI workflow cleanup, README updates, CSV policy persistence, and temporal-role behavior fixes.
  • Ecosystem maintenance included casbin-ex crash handling, jCasbin keyGet3 support, Casbin.NET KeyMatch5 compatibility, and node-casbin Node/Vite import and release automation issues.
  • The first official Apache release moved from preparation to the RC review stage for the Go core repository, apache/casbin.

How would you assess the podling's maturity?

The podling has completed initial setup and is actively working through release preparation and public governance questions. It is not yet nearing graduation.

  •  Initial setup
  •  Working towards first release
  •  Community building
  •  Nearing graduation
  •  Other:

Date of last release:

No official Apache release yet.

When were the last committers or PPMC members elected?

2026-02-07

Have your mentors been helpful and responsive?

Yes, mentors have been helpful and responsive. Mentors have helped with reporting and have participated in governance and release-policy discussions.

Is the PPMC managing the podling's brand / trademarks?

The project name has been approved in PODLINGNAMESEARCH-251. The PPMC is continuing to review release, website, and repository materials for Apache branding and trademark requirements.

Signed-off-by:

  •  (casbin) Hao Ding
    Comments:
  •  (casbin) Huajie Wang
    Comments:
  •  (casbin) Hulk Lin
    Comments:
  •  (casbin) Jerry Shao
    Comments:
  •  (casbin) Zili Chen
    Comments:

IPMC/Shepherd notes:

None


Fluss

Fluss is a streaming storage built for real-time analytics which can serve as the real-time data layer for Lakehouse architectures.

Fluss has been incubating since 2025-06-04.

Three most important unfinished issues to address before graduating:

None. Earlier graduation-readiness concerns raised during the discussion on general@incubator have been addressed. In particular, the PPMC has refreshed the proposed PMC roster through a structured review and formal vote, including only active members with governance contributions during incubation, adding active committers to the proposed PMC, and confirming forward-looking governance commitments.

Are there any issues that the IPMC or ASF Board need to be aware of?

None at this time. The concerns raised during the graduation discussion have been resolved or adopted, including the proposed PMC roster review, download page verification improvements, release/disclaimer updates, Docker Hub and Maven POM description updates, and branding/documentation corrections.

How has the community developed since the last report?

  1. Elected 1 new committer: Anton Borisov.
  2. Held regular Monthly Community Calls in April, May. (June was postponed to 3rd July)
  3. Participated in Google Summer of Code 2026 through the Fluss project and mentored a GSoC contributor.
  4. Community presentations and outreach continued:
    • Flink Forward Asia 2026 was held on June 26-27 in Shenzhen, China, with many Fluss-related talks.
    • OpenXData 2026 included Fluss talks and panels, including a Fluss presentation by Mehul Batra and a community panel involving Yuxia Luo from the Fluss PPMC.
    • Anton Borisov presented a Fluss talk at a Data Streaming meetup in London on May 7.

How has the project developed since the last report?

  • Released Apache Fluss 0.9.1-incubating on 2026-05-04. Apache Fluss 0.9.1 is currently the latest stable release.
  • Completed the Apache release of fluss-rust 0.1.0-incubating, the first official Rust, Python, and C++ client release for Apache Fluss.
  • Completed the Fluss website redesign.
  • Continued development toward Apache Fluss 1.0.0, including real-time AI use cases, real-time lakehouse integrations, streaming analytics, client SDKs, and security improvements.
  • Published more technical and user-facing content, including articles on pruning, real-time deduplication, Taobao Instant Commerce, storage hierarchy, and tiering service operations.

How would you assess the podling's maturity?

  •  Initial setup
  •  Working towards first release
  •  Community building
  •  Nearing graduation
  •  Other:

Commentary: The project has established a regular Apache release cadence and has completed the maturity model. As summarized in the graduation discussion, the community has 20 committers including mentors, from more than 8 companies, with 14 PPMC members and 121 contributors. During incubation, Fluss made 5 releases in 11 months with 4 different release managers, and reported 10+ known production users. The project has opened 1,533 issues with 1,041 resolved, and 1,796 PRs with 1,551 merged or closed. The PPMC has also refreshed the proposed PMC roster through a structured review and formal vote, adding active committers to the proposed PMC and confirming forward-looking governance commitments.

Date of last release:

2026-05-04 (Apache Fluss 0.9.1-incubating)

When were the last committers or PPMC members elected?

The most recent committer was Anton Borisov, elected in May. No new PPMC member has been elected since the April report. Two existing committers, Anton Borisov and Keith Lee, have been included in the updated proposed PMC roster for graduation.

Have your mentors been helpful and responsive?

Yes. The mentors have been helpful and responsive. The mentors provided guidance during the graduation discussion, including on the proposed PMC roster review and graduation-readiness follow-up items. No open issues at this time.

Is the PPMC managing the podling's brand / trademarks?

Yes. The PPMC is actively managing the Apache Fluss (Incubating) brand and trademarks. The PPMC has fixed several branding issues related to external blogs and content, including pages on Alibaba Cloud and Ververica websites. During the graduation-readiness follow-up, the community also updated the download page, release notes, Docker Hub descriptions, Maven POM description, and related documentation/disclaimer text. There are no known open brand or trademark issues at this time.

Signed-off-by:

  •  (fluss) Jean-Baptiste Onofré
    Comments: The vote to graduate passed. The resolution proposal for the board can be added.
  •  (fluss) Becket Qin
    Comments: Glad to see the project passing the graduation voting and ready to become a new TLP!
  •  (fluss) Yu Li
    Comments: We had a constructive discussion on graduation and the vote has passed with the updated PMC roster afterwards. I will submit the resolution for the next board meeting.
  •  (fluss) Jingsong Lee
    Comments:
  •  (fluss) Zili Chen
    Comments:

IPMC/Shepherd notes:


PonyMail

Pony Mail is a mail-archiving, archive viewing, and interaction service, that can be integrated with many email platforms.

Pony Mail has been incubating since 2016-05-27.

Three most important unfinished issues to address before graduating:

  1. Cut the first formal ASF release of the Foal (Python) rewrite.
  2. Start the graduation discussion on general@incubator.
  3. Migrate the project website to reflect current Foal documentation.

Are there any issues that the IPMC or ASF Board need to be aware of?

CVE-2026-41873 (critical severity) was published 2026-04-28 disclosing an admin account takeover via HTTP request smuggling in the legacy Lua implementation. The Lua version is retired and unsupported; the Python Foal rewrite — which is the active development line and powers lists.apache.org — is not affected. This CVE is resolved from the project's perspective.

ASF Infrastructure requested confirmation on the foal-demo.ponymail.apache.org DNS entry (INFRA-27692). The PPMC will respond.

How has the community developed since the last report?

Active contributors this quarter: rbowen, wave (Dave Fisher), sbp (Sean Palmer), sebb, jmclean (Justin Mclean), Bob Thomson, Arnout Engelen. Code review activity increased in June with multiple PRs reviewed and merged collaboratively. The project continues to benefit from the existing committer base who are familiar with the codebase and operational deployment at the ASF.

How has the project developed since the last report?

Significant documentation and code activity this quarter:

Merged PRs:

  • #313: API documentation for all Foal HTTP endpoints
  • #314: Search query syntax documentation
  • #316: Configuration reference for all ponymail.yaml options
  • #317: Comprehensive documentation suite (installation, architecture, operator guide, user guide, admin guide, plugin guide, API client guide, release process, AGENTS.md)

Open PRs:

  • #315: URL-encode search queries in pushState URLs
  • #318: Filter stopwords from word-cloud results
  • #319: Expanded database schema documentation

Infrastructure:

  • sebb fixed CI workflows (pinned Actions, mypy, indentation)
  • ASF Infra applied branch protection rulesets to all repos
  • Transitioned documentation from ElasticSearch to OpenSearch

How would you assess the podling's maturity?

Please feel free to add your own commentary.

  •  Initial setup
  •  Working towards first release
  •  Community building
  •  Nearing graduation
  •  Other:

Commentary: Pony Mail Foal is the production system powering lists.apache.org for the entire ASF. The codebase is mature, actively maintained, and has a robust PPMC. The project is ready to begin the graduation process.

Date of last release:

No formal ASF release yet. The software is deployed in production at the ASF from the main branch.

When were the last committers or PPMC members elected?

The PPMC roster has been stable. Current PPMC (11 members): humbedooh, wave, jim, johndament, rbowen, rubys, sbp, sebb, curcuru, pctony, ucb.

Have your mentors been helpful and responsive?

Yes.

Are things falling through the cracks? If so, please list any open

issues that need to be addressed.

No. The project intends to start the graduation discussion following this report.

Is the PPMC managing the podling's brand / trademarks?

Yes. The Pony Mail name and brand are managed by the PPMC. No known third-party misuse.

Are 3rd parties respecting and correctly using the podlings name and

brand? If not what actions has the PPMC taken to correct this? Has the VP, Brand approved the project name?

Yes. No issues. VP, Brand has approved the project name.

Signed-off-by:

  •  (ponymail) John D. Ament
  •  (ponymail) Dave Fisher

Comments:

IPMC/Shepherd notes:

We see no reason not to graduate. Thanks Rich for creating this report.


ResilientDB

ResilientDB is a distributed blockchain framework that is open-source, lightweight, modular, and highly performant.

ResilientDB has been incubating since 2023-10-21.

Three most important unfinished issues to address before graduating:

  1. Graduate
  2. Graduate
  3. Graduate

Are there any issues that the IPMC or ASF Board need to be aware of?

No

How has the community developed since the last report?

Add 3 new Committers

How has the project developed since the last report?

We are precessing the graduation process.

How would you assess the podling's maturity?

Please feel free to add your own commentary.

  •  Initial setup
  •  Working towards first release
  •  Community building
  •  Nearing graduation
  •  Other:

Date of last release:

2026-3-10

When were the last committers or PPMC members elected?

Have your mentors been helpful and responsive?

Are things falling through the cracks? If so, please list any open issues that need to be addressed.

JB is very helpful.

Is the PPMC managing the podling's brand / trademarks?

Are 3rd parties respecting and correctly using the podlings name and brand? If not what actions has the PPMC taken to correct this? Has the VP, Brand approved the project name?

There are no known brand and naming issues as reported here.

Signed-off-by:

  •  (resilientdb) Junping Du
    Comments:
  •  (resilientdb) Kevin Ratnasekera
    Comments:
  •  (resilientdb) Jean-Baptiste Onofré
    Comments: I think the podling is ready to graduate. I will help on this (sorry for being late on that).

IPMC/Shepherd notes:

  • No labels