Return-Path: Delivered-To: apmail-legal-discuss-archive@www.apache.org Received: (qmail 25053 invoked from network); 21 Dec 2007 07:58:35 -0000 Received: from hermes.apache.org (HELO mail.apache.org) (140.211.11.2) by minotaur.apache.org with SMTP; 21 Dec 2007 07:58:35 -0000 Received: (qmail 32507 invoked by uid 500); 21 Dec 2007 07:58:23 -0000 Delivered-To: apmail-legal-discuss-archive@apache.org Received: (qmail 32351 invoked by uid 500); 21 Dec 2007 07:58:23 -0000 Mailing-List: contact legal-discuss-help@apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Delivered-To: mailing list legal-discuss@apache.org Received: (qmail 32340 invoked by uid 99); 21 Dec 2007 07:58:23 -0000 Received: from athena.apache.org (HELO athena.apache.org) (140.211.11.136) by apache.org (qpsmtpd/0.29) with ESMTP; Thu, 20 Dec 2007 23:58:23 -0800 X-ASF-Spam-Status: No, hits=-0.0 required=10.0 tests=SPF_PASS X-Spam-Check-By: apache.org Received-SPF: pass (athena.apache.org: domain of hyandell@gmail.com designates 209.85.146.182 as permitted sender) Received: from [209.85.146.182] (HELO wa-out-1112.google.com) (209.85.146.182) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 21 Dec 2007 07:58:01 +0000 Received: by wa-out-1112.google.com with SMTP id m28so353715wag.13 for ; Thu, 20 Dec 2007 23:58:05 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:received:received:message-id:date:from:sender:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references:x-google-sender-auth; bh=f+cWqHuKxWA9k0inPFh+UDryay/EVq/Yxomc6PxXY5M=; b=QJBqE6hR3zAOC2kOIowh+ADIAQs/9zz1oHWKzvY6ddbs2ZJ6YkRzWr7jZ7Jx/MNlDpjKRLe/iH5jihaUaO8UMfgayBOhv6G4iTg4rvTRnhddju6R4r9OpUiLM6XomfzYPuqenxQE5QvyD5vmhndEU9JrUrEbvAGs4NVx7BB7OLk= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=message-id:date:from:sender:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references:x-google-sender-auth; b=Im+7XpXp7mUkOjZPCYJgdV5hwdvZMlkYikmbKZxtj0Wi5frfLLI7CmBDQD/ZVuAggv7lULW8g63buJJ9iIqWn4SCeDCG+srN+CC2pl+gjr5wQvTXhxlYQiGBgy1zoeX01Zv62VGRaHMQTLNLeF34+zq3cM0xsNkkKDkyj0qH23o= Received: by 10.114.166.1 with SMTP id o1mr1098851wae.71.1198223884876; Thu, 20 Dec 2007 23:58:04 -0800 (PST) Received: by 10.114.89.15 with HTTP; Thu, 20 Dec 2007 23:58:04 -0800 (PST) Message-ID: <2d12b2f00712202358j57d10186u4e5e4f0a3f0a3874@mail.gmail.com> Date: Thu, 20 Dec 2007 23:58:04 -0800 From: "Henri Yandell" Sender: hyandell@gmail.com To: "Roland Weber" Subject: Re: LICENSE and NOTICE files and SVN Cc: "Legal Discuss" In-Reply-To: <476B40F7.8060209@dubioso.net> MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Content-Disposition: inline References: <25aac9fc0712171137q67c3a7cfu5012b10da9f52725@mail.gmail.com> <18B50A19-3D3B-49ED-A459-17CD3BFA69DB@yahoo.com> <25aac9fc0712191719m1b004b2et5969d718e6e0bc75@mail.gmail.com> <510143ac0712192051n32bb4c3ckf51c3bdcf4aba98d@mail.gmail.com> <5c902b9e0712192216w3a23ac5fh131121bc27e8dae2@mail.gmail.com> <802B7BC1-D956-45B3-B68B-CC89522FC606@gbiv.com> <476B40F7.8060209@dubioso.net> X-Google-Sender-Auth: a76907125c8f83d5 X-Virus-Checked: Checked by ClamAV on apache.org On Dec 20, 2007 8:28 PM, Roland Weber wrote: > Roy T. Fielding wrote: > > PMCs can vote on just about anything. However, a release vote is on > > a packaged artifact containing the complete source code and signed > > by the release manager. If you haven't voted on that, the PMC has > > not performed a valid release. > > > > Binaries are generated from release source packages. If the PMC is > > doing something else, then it has seriously screwed the pooch and > > may not even be releasing open source. > > Are there any plans to fix Maven? AFAIK, Maven tags the source in > the repository, then builds binary and source release packages from > that tag. It does not build a source package that is signed before > or after the binary gets built from that source. It builds both > from the same tag, and both are signed afterwards. > Either my understanding of Maven is wrong, or you are saying that > every Apache project that uses Maven to generate the release > packages is making invalid releases. The various Ant builds I've used do the same thing. You tag trunk, then run 'dist' (etc) and get a source and binary build. Thanks for pointing out that part of Roy's reply - it hadn't sunk in when I read it the first time. Hen --------------------------------------------------------------------- DISCLAIMER: Discussions on this list are informational and educational only. Statements made on this list are not privileged, do not constitute legal advice, and do not necessarily reflect the opinions and policies of the ASF. See for official ASF policies and documents. --------------------------------------------------------------------- To unsubscribe, e-mail: legal-discuss-unsubscribe@apache.org For additional commands, e-mail: legal-discuss-help@apache.org