← Back to all sparks
A

Apereo CAS

INFRA · APIS
Velocity2.5

Enterprise single sign-on and identity federation server

Apereo CAS opens an 8.1 line while 8.0 is still working through release candidates.

identityssoopen-sourcerelease-candidatessecurity-patching
Current state
CAS is running a long release-candidate train. The 8.0.0 line reached RC6 in late June after RC4 and RC5 in spring, and 8.1.0-RC1 has now appeared in August. A 7.3.7.1 patch in June addressed a published OIDC vulnerability on the maintenance branch. The release entries themselves carry only navigation links and contributor credits, so feature detail is not visible here.
Where it's heading
Two lines are moving at once, which suggests 8.0 is close enough to final that work has begun branching forward rather than that the RC train has stalled. The contributor lists stay small and consistent across releases - a handful of recurring maintainers - and security handling happens on the older supported branch, as it should.
Prediction
An 8.0.0 final is the obvious next milestone given RC6 was three months ago and an 8.1 branch is already open. The release bodies do not describe features, so what it contains cannot be read from this feed.

Recent moves

  1. 19d ago

    v8.1.0-RC1

    The first release candidate of the 8.1.0 line, arriving while 8.0.0 is still in its own RC train. Opening a forward branch is the notable part; the entry itself is the project's standard template of documentation links and contributor thanks, with no feature detail.

    View source ↗
  2. 2mo ago

    v8.0.0-RC6

    The sixth 8.0 release candidate, published with the same boilerplate as the others and no description of its changes. Its only readable content is the contributor list, which stays small and consistent across the series.

    View source ↗
  3. 2mo ago

    Patch release for a published OIDC vulnerability

    The only entry in this window carrying real substance: a v7 patch whose notes point directly at an OIDC vulnerability advisory. For a single sign-on server, a flaw in the OIDC path is the category of issue that forces an unscheduled upgrade.

    View source ↗
  4. 3mo ago

    v8.0.0-RC5

    The fifth 8.0 candidate, following the same template with no described changes. The roughly monthly gap to the next candidate is the only signal it carries.

    View source ↗
  5. 4mo ago

    v8.0.0-RC4

    The fourth 8.0 candidate, again documented only by links and contributor thanks. It has the widest contributor list of the series, which is the sole differentiator visible in the notes.

    View source ↗