Return-Path: X-Original-To: archive-asf-public-internal@cust-asf2.ponee.io Delivered-To: archive-asf-public-internal@cust-asf2.ponee.io Received: from cust-asf.ponee.io (cust-asf.ponee.io [163.172.22.183]) by cust-asf2.ponee.io (Postfix) with ESMTP id 97FF6200CC4 for ; Thu, 13 Jul 2017 18:48:21 +0200 (CEST) Received: by cust-asf.ponee.io (Postfix) id 9717216C599; Thu, 13 Jul 2017 16:48:21 +0000 (UTC) Delivered-To: archive-asf-public@cust-asf.ponee.io Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by cust-asf.ponee.io (Postfix) with SMTP id B78F216C596 for ; Thu, 13 Jul 2017 18:48:20 +0200 (CEST) Received: (qmail 24467 invoked by uid 500); 13 Jul 2017 16:48:20 -0000 Mailing-List: contact dev-help@mxnet.incubator.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: dev@mxnet.incubator.apache.org Delivered-To: mailing list dev@mxnet.incubator.apache.org Received: (qmail 24455 invoked by uid 99); 13 Jul 2017 16:48:19 -0000 Received: from pnap-us-west-generic-nat.apache.org (HELO spamd2-us-west.apache.org) (209.188.14.142) by apache.org (qpsmtpd/0.29) with ESMTP; Thu, 13 Jul 2017 16:48:19 +0000 Received: from localhost (localhost [127.0.0.1]) by spamd2-us-west.apache.org (ASF Mail Server at spamd2-us-west.apache.org) with ESMTP id 318FC1A04B0 for ; Thu, 13 Jul 2017 16:48:19 +0000 (UTC) X-Virus-Scanned: Debian amavisd-new at spamd2-us-west.apache.org X-Spam-Flag: NO X-Spam-Score: -0.02 X-Spam-Level: X-Spam-Status: No, score=-0.02 tagged_above=-999 required=6.31 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01] autolearn=disabled Authentication-Results: spamd2-us-west.apache.org (amavisd-new); dkim=pass (2048-bit key) header.d=weimo-de.20150623.gappssmtp.com Received: from mx1-lw-eu.apache.org ([10.40.0.8]) by localhost (spamd2-us-west.apache.org [10.40.0.9]) (amavisd-new, port 10024) with ESMTP id AIsMhZAC04Yc for ; Thu, 13 Jul 2017 16:48:16 +0000 (UTC) Received: from mail-ua0-f181.google.com (mail-ua0-f181.google.com [209.85.217.181]) by mx1-lw-eu.apache.org (ASF Mail Server at mx1-lw-eu.apache.org) with ESMTPS id 600105F6C6 for ; Thu, 13 Jul 2017 16:48:16 +0000 (UTC) Received: by mail-ua0-f181.google.com with SMTP id z22so37397786uah.1 for ; Thu, 13 Jul 2017 09:48:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=weimo-de.20150623.gappssmtp.com; s=20150623; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :content-transfer-encoding; bh=8w27JmbV5sotb6ZQOtfNG1qhpNTIUMJFepEWCJfIE2s=; b=Gl+WTSbf/1LT7uBWsLPRw/7L45EuUK9eTkkxpDRsJyHOJLztJL9QyWMQwYGZnAlaIU 62Vp+Edm1qdHwkQDQlHtQOM71aEwMQINFy/V/Zt1Czb2r0Dc0IQApIi/WWJrXYmuJms8 36DaBSssRTnEeq9Foh3Twl8BAbkZC5hK9mMgubjSWC8MYspGwYwyDdkjQFGFs1YjhaCT kQKxB4fWitfe1/RaAwJInoIg9z0dmRYvuYZH2UZzJ4NPkDCk8vzXPa8Rp5BHQudirc3t qQTyvg01R83f9QMdPO4hm8IISFrBMZSAG21yAcW1he85dU+klWV+WTZshn+8Juirsk0G hK6A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:content-transfer-encoding; bh=8w27JmbV5sotb6ZQOtfNG1qhpNTIUMJFepEWCJfIE2s=; b=fmegTv8f5v+YtMZxEY3l6flHRvcocYrYdNTdlSN2cbJ1q6fLE5HdrLkX5bRko6jBTD RaA7ne7ukkZqOwFeUSNzUFRw9SdALjqU+uiYf2yy4ZVSmf56urcPGyoY7VqdxqSRYB/K bPAPozVS4yLCKSp3Mc7OH+kG69230VoedgK+Vxdo7uxXYCYJb+n66LaRGDK84xGUOxo5 XQNAaqBlkaQ3gEeUvcgIl88u2ezWwBZx6wrngf+1uqU9eWDBYIoAces6MZ05nXTo88R8 4GTVk+2r3t6afJ0LskmqUvzxIaEh3S2/hUsJb2WiMS6U6b5TihHzR4PIH17Yd6X1MO8a yEiw== X-Gm-Message-State: AIVw112mLZDdDdz3e1IAF6XuIy8yAbeC2770FTy5fkTGY2EN0xH/z9jU MJIBMA1KhUGExnnDFGpf8cZph0YE8eYNZto= X-Received: by 10.176.83.216 with SMTP id l24mr3209947uaa.59.1499964495120; Thu, 13 Jul 2017 09:48:15 -0700 (PDT) MIME-Version: 1.0 Received: by 10.176.84.157 with HTTP; Thu, 13 Jul 2017 09:47:54 -0700 (PDT) X-Originating-IP: [50.46.125.202] In-Reply-To: References: From: Markus Weimer Date: Thu, 13 Jul 2017 09:47:54 -0700 Message-ID: Subject: Re: July 2017 Release To: dev@mxnet.incubator.apache.org Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable archived-at: Thu, 13 Jul 2017 16:48:21 -0000 Hi, thanks for sharing the plans! Is there a specific reason to skip the SHA hashes? Much of the integrity of Apache releases stems from having those SHAs in as many inboxes as possible, after all. Thanks, Markus On Tue, Jul 11, 2017 at 4:07 PM, Ly Nguyen wrote: > @mentors, we would like to hold a RC vote and release on Monday July 17th= . > > - Are there any blockers (i.e., licenses)? > - Can you validate the proposal below? > > > *PROPOSAL FOR JULY RELASE (version?):* > *Start voting THIS week. Release on Monday July 17th.* > > 1. Create signing keys > 1. SKIP web of trust linking and upload to public keyserver this ti= me > 2. Create RC in > https://dist.apache.org/repos/dist/dev/incubator/podlingName > 1. Currently missing a DISCLAIMER file - do we need that? > 2. SKIP creating SHA checksum this time > 3. Start a vote on dev@ list > 4. svn mv RC to the release location > > > > > *NOTES FROM DOCS FOR REFERENCE:* > http://incubator.apache.org/guides/releasemanagement.html > > - 3 +1 votes from IPMC members (these are the votes that count but we > should open up to the whole podling community) > - For podlings, 2 additional constraints: > - Release artifacts must include =E2=80=9Cincubating=E2=80=9D in fi= nal file name (ex: > apache-mxnet-src-0.10.1-incubating.tar.gz) > - Release artifacts must include disclaimer in the release artifact= s > > > - The Incubator PMC expects the source releases to be staged on > https://dist.apache.org/repos/dist/dev/incubator/podlingName so that > they can easily be moved to the release location via svn mv ( > http://www.apache.org/dist/incubator/) > - After graduating, RC=E2=80=99s go into https://dist.apache.org/repos= /dist/dev/ > and official releases go into https://dist.apache.org/repos/dist/relea= se/ > > > http://incubator.apache.org/guides/branding.html#disclaimers > > - Apache Press Team [http://www.apache.org/press/index.html#whoweare] > must review and coordinate releases for branding > - On website and in release DISCLAIMER file: > - Apache Podling-Name is an effort undergoing incubation at The Apache > Software Foundation (ASF), sponsored by the name of Apache TLP spon= sor. > Incubation is required of all newly accepted projects until a furth= er > review indicates that the infrastructure, communications, and decis= ion > making process have stabilized in a manner consistent with other > successful > ASF projects. While incubation status is not necessarily a reflecti= on of > the completeness or stability of the code, it does indicate that th= e > project has yet to be fully endorsed by the ASF. > - Website should include Apache Incubator logo: > http://incubator.apache.org/guides/press-kit.html > > > - Release should include: > - DISCLAIMER > - LICENSE > - NOTICE - attribution notices > > > http://www.apache.org/legal/release-policy.html > > - A release must contain source package which is cryptographically > signed by Release Manager with detached signature. It must be tested p= rior > to voting for release. > - Release must only contain appropriately licensed code > - Please ensure you wait >=3D24 hours after uploading a release before > making announcements so mirrors catch up > - Releases of more than 1GB of artifacts require a heads-up to > Infrastructure in advance. > - Which directory for what build? > http://www.apache.org/legal/release-policy.html#build-directories > > > http://www.apache.org/dev/release-distribution.html > > - Artifacts MUST be accompanied by: > - apache-mxnet-src-0.10.1-incubating.asc - contains OpenPGP > compatible ASCII armored detached signature > - apache-mxnet-src-0.10.1-incubating.md5 - MD5 checksum > - apache-mxnet-src-0.10.1-incubating.sha - SHA checksum (SHOULD) > - Publish KEYS file in distribution directory root > - Signing keys MUST be published in KEYS file, SHOULD be available = in > global public keyserver > http://www.apache.org/dev/release-signing#keyserver, SHOULD be link= ed > into web of trust > - Keys MUST be RSA & 4096 bits > > > http://www.apache.org/dev/release-publishing.html > > - Apache RAT can assist in checking license compliance > http://creadur.apache.org/rat/ > - Eventually we should set up a build system to sign our releases with > cryptographic signatures. For now we=E2=80=99ll do it manually. > > > http://www.apache.org/dev/release-signing.html > > - Create a signature and sign releases as mentioned above