Return-Path: X-Original-To: apmail-maven-dev-archive@www.apache.org Delivered-To: apmail-maven-dev-archive@www.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id D357810E52 for ; Tue, 10 Sep 2013 13:19:19 +0000 (UTC) Received: (qmail 62686 invoked by uid 500); 10 Sep 2013 13:19:18 -0000 Delivered-To: apmail-maven-dev-archive@maven.apache.org Received: (qmail 62227 invoked by uid 500); 10 Sep 2013 13:19:14 -0000 Mailing-List: contact dev-help@maven.apache.org; run by ezmlm Precedence: bulk List-Unsubscribe: List-Help: List-Post: List-Id: "Maven Developers List" Reply-To: "Maven Developers List" Delivered-To: mailing list dev@maven.apache.org Received: (qmail 62216 invoked by uid 99); 10 Sep 2013 13:19:14 -0000 Received: from nike.apache.org (HELO nike.apache.org) (192.87.106.230) by apache.org (qpsmtpd/0.29) with ESMTP; Tue, 10 Sep 2013 13:19:14 +0000 X-ASF-Spam-Status: No, hits=2.6 required=5.0 tests=HTML_MESSAGE,RCVD_IN_DNSWL_LOW,SPF_PASS,TRACKER_ID X-Spam-Check-By: apache.org Received-SPF: pass (nike.apache.org: local policy) Received: from [66.111.4.27] (HELO out3-smtp.messagingengine.com) (66.111.4.27) by apache.org (qpsmtpd/0.29) with ESMTP; Tue, 10 Sep 2013 13:19:07 +0000 Received: from compute1.internal (compute1.nyi.mail.srv.osa [10.202.2.41]) by gateway1.nyi.mail.srv.osa (Postfix) with ESMTP id 9954320A3B for ; Tue, 10 Sep 2013 09:18:46 -0400 (EDT) Received: from frontend2 ([10.202.2.161]) by compute1.internal (MEProxy); Tue, 10 Sep 2013 09:18:46 -0400 DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=tesla.io; h=from :content-type:message-id:mime-version:subject:date:references:to :in-reply-to; s=mesmtp; bh=7oJIxdxTQGLFualg8LMM6bqnqNY=; b=BUnFi DugFbdvM1jPkcHPSmAzPJ0wud+Q/PbemUwGxrxwdr468o/h41nu9PVRPCbO8EZwl JmjiIDzRlbFsDpXa4veIx6cSb1q9FOvRa1KqEvMvk44A5YdFH2ctnMEByjfq/DvI yoVMVysBH07Z92syWzZhyb3cOSC6YERV6BywmE= DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d= messagingengine.com; h=from:content-type:message-id:mime-version :subject:date:references:to:in-reply-to; s=smtpout; bh=7oJIxdxTQ GLFualg8LMM6bqnqNY=; b=r4ngNoXDDOC8lDFboDY6/hUlNRgRiAh2yC/p0P6vv AhjrLzXCjHNPxjYRmOZMXUzYvwhCHzEBfD+gG2M60SWffsyySUibvE0iVtAnGKnh 0JZOW2Fu4I2B1dOH0wpwSyJS4qGaCG6ZqCEDoWbKEbO3HwlR5Rrz7/FDHGybjM7L vQ= X-Sasl-enc: /KYO1jCIAfZkVL/nXlZqeiQaprYIzebORt5vTZT61BM7 1378819126 Received: from [192.168.0.13] (unknown [72.137.151.46]) by mail.messagingengine.com (Postfix) with ESMTPA id 480EE6800C5 for ; Tue, 10 Sep 2013 09:18:46 -0400 (EDT) From: Jason van Zyl Content-Type: multipart/alternative; boundary="Apple-Mail=_9A897EE0-C05A-47BA-A761-3778C9F2C384" Message-Id: <23C62DF5-AF44-47E3-A79B-8D116D10629A@tesla.io> Mime-Version: 1.0 (Mac OS X Mail 6.5 \(1508\)) Subject: Re: [VOTE] Release Maven 3.1.1 Date: Tue, 10 Sep 2013 09:18:45 -0400 References: <268EC617-8A49-4A5E-972A-FCD5ABA36447@tesla.io> <2FFB8CC0-9215-4B60-BF63-BC41E0CDBA66@tesla.io> To: "Maven Developers List" In-Reply-To: X-Mailer: Apple Mail (2.1508) X-Virus-Checked: Checked by ClamAV on apache.org --Apple-Mail=_9A897EE0-C05A-47BA-A761-3778C9F2C384 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=iso-8859-1 Sure, I can remake the email, but the binaries are fine. I made a little = tool for myself and I'll just use the template from the website. The SHA1 I took was for the release which is the value that's = interpolated into the build.properties. On Sep 9, 2013, at 3:56 PM, Stephen Connolly = wrote: > On 8 September 2013 18:51, Jason van Zyl wrote: >=20 >>=20 >> On Sep 8, 2013, at 1:12 PM, sebb wrote: >>=20 >>> I thought you were going to include the SCM coordinates used to = create >>> the tarballs? >>>=20 >>=20 >> Sorry, not intentional. I forgot. >>=20 >>> It's particularly important here, because AFAICT the SCM coordinates >>> are not present in the POM. >>> If true, then it's not possible to verify the files in the source >> tarballs. >>>=20 >>=20 >> I hash is always in the distribution, it's how we show where it comes = from >> when you type "mvn -v". It's in the build properties in the core JAR = and >> the hash in there is: >>=20 >> c9950d777c7368e51431500c29aecf1e11e3d2c6 >>=20 >=20 > Is that the SHA1 of the src.zip and src.tar.gz or is it the SHA1 of = the git > commit. >=20 > What we are looking for on the vote emails is the SHA1 and MD5 of the > src.zip and src.tar.gz so that interested parties can verify that the = vote > was against the source distribution that ends up in dist and central. = Since > the staging repository is deleted as part of the release process, and = since > what the PMC is voting on is the source bundles, we need the vote = email to > specify the hashes of the source bundle *for the record*... >=20 > Of course this is really easy to do as Maven helpfully uploads the = hashes > to the staging repository, but since "it didn't happen if it wasn't on = a > mailing list" (stephenc rolls his eyes) we need the release manager to > ensure that the vote has this required information. >=20 > Note: The commit hash is really nice to have, but is not part of the > minimum set of required information, and we are trying to stick to = minimum > procedure. So we don't look for that *even* if other people think we = should. >=20 >=20 >>=20 >>> Also, AFAIK, the PMC agreed to include hashes of the tarballs in = vote >> e-mails? >>>=20 >>> On 8 September 2013 14:07, Jason van Zyl wrote: >>>> Hi, >>>>=20 >>>> Here is a link to Jira with 6 issues resolved: >>>>=20 >> = https://jira.codehaus.org/secure/ReleaseNote.jspa?projectId=3D10500&versio= n=3D18968 >>>>=20 >>>> Staging repo: >>>> https://repository.apache.org/content/repositories/maven-016/ >>>>=20 >>>> The distributable binaries and sources for testing can be found = here: >>>>=20 >> = https://repository.apache.org/content/repositories/maven-016/org/apache/ma= ven/apache-maven/3.1.1/ >>>>=20 >>>> Specifically the zip, tarball, and source archives can be found = here: >>>>=20 >> = https://repository.apache.org/content/repositories/maven-016/org/apache/ma= ven/apache-maven/3.1.1/apache-maven-3.1.1-bin.zip >>>>=20 >> = https://repository.apache.org/content/repositories/maven-016/org/apache/ma= ven/apache-maven/3.1.1/apache-maven-3.1.1-bin.tar.gz >>>>=20 >> = https://repository.apache.org/content/repositories/maven-016/org/apache/ma= ven/apache-maven/3.1.1/apache-maven-3.1.1-src.zip >>>>=20 >> = https://repository.apache.org/content/repositories/maven-016/org/apache/ma= ven/apache-maven/3.1.1/apache-maven-3.1.1-src.tar.gz >>>>=20 >>>> Vote open for 72 hours. >>>>=20 >>>> [ ] +1 >>>> [ ] +0 >>>> [ ] -1 >>>>=20 >>>> Thanks, >>>>=20 >>>> The Maven Team >>>>=20 >>>>=20 >>>>=20 >>>>=20 >>>>=20 >>>>=20 >>>>=20 >>>=20 >>> = --------------------------------------------------------------------- >>> To unsubscribe, e-mail: dev-unsubscribe@maven.apache.org >>> For additional commands, e-mail: dev-help@maven.apache.org >>>=20 >>=20 >> Thanks, >>=20 >> Jason >>=20 >> ---------------------------------------------------------- >> Jason van Zyl >> Founder, Apache Maven >> http://twitter.com/jvanzyl >> --------------------------------------------------------- >>=20 >>=20 >>=20 >>=20 >>=20 >>=20 >>=20 >>=20 Thanks, Jason ---------------------------------------------------------- Jason van Zyl Founder, Apache Maven http://twitter.com/jvanzyl --------------------------------------------------------- --Apple-Mail=_9A897EE0-C05A-47BA-A761-3778C9F2C384--