Re: [VOTE] Release Apache Maven version 3.8.0

Previous Topic Next Topic
 
classic Classic list List threaded Threaded
10 messages Options
Reply | Threaded
Open this post in threaded view
|

Re: [VOTE] Release Apache Maven version 3.8.0

Elliotte Rusty Harold
I'm a weak -1 on this, solely because I don't find the reasoning for
not calling this 3.7.0 to be compelling. "Apache Maven 3.7.0 would be
the first release where you could optionally activate the
build/consumer feature. This version of this release has been renamed
to 4.0.0. Reusing 3.7.0 might lead to confusion, hence we picked the
next available minor version."

Are we sure? I certainly didn't expect 3.7.0 to be the first release
where you could optionally activate the build/consumer feature. I
can't say I expected anything in particular for 3.7.0. Did Maven ever
promise there would be a 3.7.0 with this feature?

If it were renamed 3.7.0 I'd be at +1.

On Mon, Mar 22, 2021 at 7:40 PM Robert Scholte <[hidden email]> wrote:

>
> Hi,
>
> For the details about this release, please read https://maven.apache.org/docs/3.8.0/release-notes.html
> Also please provide feedback on the release notes. (as you know, these are published separately from the release, so it doesn't have to block the release itself)
>
> We solved 5 issues:
> https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12316922&version=12350003&styleName=Text
>
> There are still a couple of issues left in JIRA:
> https://issues.apache.org/jira/issues/?jql=project%20%3D%2012316922%20AND%20resolution%20%3D%20Unresolved%20ORDER%20BY%20key%20DESC%2C%20priority%20DESC
>
> Staging repo:
> https://repository.apache.org/content/repositories/maven-1633/
>
> https://dist.apache.org/repos/dist/release/maven/maven-3/3.8.0/binaries/apache-maven-3.8.0-bin.zip
> https://dist.apache.org/repos/dist/release/maven/maven-3/3.8.0/source/apache-maven-3.8.0-src.zip
>
>
> Source release checksum(s):
> apache-maven-3.8.0-bin.zip sha512: b56da9a0efa45e084e4882b795787fc7b61970d19835635b2db099b91a9854f14e3776a01d569e3f7af9db946a05af91abbfad41cdc5ac09e90df25077dec01e
> apache-maven-3.8.0-src.zip sha512: 51a1570894e8fb1ef52cb19ce472866745ccae2720e45304edd3cabc212cdf105937c76502558fe87995aea81c41402d7f581cc8e9393af234b64696e9a45893
>
>
> Staging site:
> https://maven.apache.org/ref/3-LATEST/
>
> Guide to testing staged releases:
> https://maven.apache.org/guides/development/guide-testing-releases.html
>
> Vote open for at least 72 hours.
>
> [ ] +1
> [ ] +0
> [ ] -1



--
Elliotte Rusty Harold
[hidden email]

---------------------------------------------------------------------
To unsubscribe, e-mail: [hidden email]
For additional commands, e-mail: [hidden email]

Reply | Threaded
Open this post in threaded view
|

Re: [VOTE] Release Apache Maven version 3.8.0

Gary Gregory-2
You are acknowledging a CVE _before_ a release?

Gary


On Mon, Mar 22, 2021, 15:40 Robert Scholte <[hidden email]> wrote:

> Hi,
>
> For the details about this release, please read
> https://maven.apache.org/docs/3.8.0/release-notes.html
> Also please provide feedback on the release notes. (as you know, these are
> published separately from the release, so it doesn't have to block the
> release itself)
>
> We solved 5 issues:
>
> https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12316922&version=12350003&styleName=Text
>
> There are still a couple of issues left in JIRA:
>
> https://issues.apache.org/jira/issues/?jql=project%20%3D%2012316922%20AND%20resolution%20%3D%20Unresolved%20ORDER%20BY%20key%20DESC%2C%20priority%20DESC
>
> Staging repo:
> https://repository.apache.org/content/repositories/maven-1633/
>
>
> https://dist.apache.org/repos/dist/release/maven/maven-3/3.8.0/binaries/apache-maven-3.8.0-bin.zip
>
> https://dist.apache.org/repos/dist/release/maven/maven-3/3.8.0/source/apache-maven-3.8.0-src.zip
>
>
> Source release checksum(s):
>
> apache-maven-3.8.0-bin.zip sha512: b56da9a0efa45e084e4882b795787fc7b61970d19835635b2db099b91a9854f14e3776a01d569e3f7af9db946a05af91abbfad41cdc5ac09e90df25077dec01e
>
> apache-maven-3.8.0-src.zip sha512: 51a1570894e8fb1ef52cb19ce472866745ccae2720e45304edd3cabc212cdf105937c76502558fe87995aea81c41402d7f581cc8e9393af234b64696e9a45893
>
>
> Staging site:
> https://maven.apache.org/ref/3-LATEST/
>
> Guide to testing staged releases:
> https://maven.apache.org/guides/development/guide-testing-releases.html
>
> Vote open for at least 72 hours.
>
> [ ] +1
> [ ] +0
> [ ] -1
>
Reply | Threaded
Open this post in threaded view
|

Re: [VOTE] Release Apache Maven version 3.8.0

Brian Fox-2
The CVE is for documentation and the hardening of default behavior,
it's not your typical zero day.

On Mon, Mar 22, 2021 at 10:53 PM Gary Gregory <[hidden email]> wrote:

>
> You are acknowledging a CVE _before_ a release?
>
> Gary
>
>
> On Mon, Mar 22, 2021, 15:40 Robert Scholte <[hidden email]> wrote:
>
> > Hi,
> >
> > For the details about this release, please read
> > https://maven.apache.org/docs/3.8.0/release-notes.html
> > Also please provide feedback on the release notes. (as you know, these are
> > published separately from the release, so it doesn't have to block the
> > release itself)
> >
> > We solved 5 issues:
> >
> > https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12316922&version=12350003&styleName=Text
> >
> > There are still a couple of issues left in JIRA:
> >
> > https://issues.apache.org/jira/issues/?jql=project%20%3D%2012316922%20AND%20resolution%20%3D%20Unresolved%20ORDER%20BY%20key%20DESC%2C%20priority%20DESC
> >
> > Staging repo:
> > https://repository.apache.org/content/repositories/maven-1633/
> >
> >
> > https://dist.apache.org/repos/dist/release/maven/maven-3/3.8.0/binaries/apache-maven-3.8.0-bin.zip
> >
> > https://dist.apache.org/repos/dist/release/maven/maven-3/3.8.0/source/apache-maven-3.8.0-src.zip
> >
> >
> > Source release checksum(s):
> >
> > apache-maven-3.8.0-bin.zip sha512: b56da9a0efa45e084e4882b795787fc7b61970d19835635b2db099b91a9854f14e3776a01d569e3f7af9db946a05af91abbfad41cdc5ac09e90df25077dec01e
> >
> > apache-maven-3.8.0-src.zip sha512: 51a1570894e8fb1ef52cb19ce472866745ccae2720e45304edd3cabc212cdf105937c76502558fe87995aea81c41402d7f581cc8e9393af234b64696e9a45893
> >
> >
> > Staging site:
> > https://maven.apache.org/ref/3-LATEST/
> >
> > Guide to testing staged releases:
> > https://maven.apache.org/guides/development/guide-testing-releases.html
> >
> > Vote open for at least 72 hours.
> >
> > [ ] +1
> > [ ] +0
> > [ ] -1
> >

---------------------------------------------------------------------
To unsubscribe, e-mail: [hidden email]
For additional commands, e-mail: [hidden email]

Reply | Threaded
Open this post in threaded view
|

Re: [VOTE] Release Apache Maven version 3.8.0

Ralph Goers
In reply to this post by Elliotte Rusty Harold
If I were a user and expected the feature to be in 3.7.0 then I would certainly also expect it in 3.8.0. The only ways to avoid this are a) stay on 3.6.x.x until the feature is available, b) specifically say the promised features aren’t available yet.

That said I’m +0 on the version numbering.

Ralph

> On Mar 22, 2021, at 3:09 PM, Robert Scholte <[hidden email]> wrote:
>
> There were enough tweets and conference talks were I demonstrated the idea behind build/consumer.
> Of course the audience wanted to hear a version, so the best possible answer was "most likely 3.7.0"
> First Google hit: Maven 3.7 to Include Default Wrapper - InfoQ[1] and you can find much more.
> Several PMC members discussed about what would be the proper value, the result was in the end 3.8.0.
> Most important: it is beyond 3.6.3 and before 4.
>
> Robert
>
> [1] https://www.infoq.com/news/2020/04/maven-wrapper/
>
> On 22-3-2021 21:14:10, Elliotte Rusty Harold <[hidden email]> wrote:
> I'm a weak -1 on this, solely because I don't find the reasoning for
> not calling this 3.7.0 to be compelling. "Apache Maven 3.7.0 would be
> the first release where you could optionally activate the
> build/consumer feature. This version of this release has been renamed
> to 4.0.0. Reusing 3.7.0 might lead to confusion, hence we picked the
> next available minor version."
>
> Are we sure? I certainly didn't expect 3.7.0 to be the first release
> where you could optionally activate the build/consumer feature. I
> can't say I expected anything in particular for 3.7.0. Did Maven ever
> promise there would be a 3.7.0 with this feature?
>
> If it were renamed 3.7.0 I'd be at +1.
>
> On Mon, Mar 22, 2021 at 7:40 PM Robert Scholte wrote:
>>
>> Hi,
>>
>> For the details about this release, please read https://maven.apache.org/docs/3.8.0/release-notes.html
>> Also please provide feedback on the release notes. (as you know, these are published separately from the release, so it doesn't have to block the release itself)
>>
>> We solved 5 issues:
>> https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12316922&version=12350003&styleName=Text
>>
>> There are still a couple of issues left in JIRA:
>> https://issues.apache.org/jira/issues/?jql=project%20%3D%2012316922%20AND%20resolution%20%3D%20Unresolved%20ORDER%20BY%20key%20DESC%2C%20priority%20DESC
>>
>> Staging repo:
>> https://repository.apache.org/content/repositories/maven-1633/
>>
>> https://dist.apache.org/repos/dist/release/maven/maven-3/3.8.0/binaries/apache-maven-3.8.0-bin.zip
>> https://dist.apache.org/repos/dist/release/maven/maven-3/3.8.0/source/apache-maven-3.8.0-src.zip
>>
>>
>> Source release checksum(s):
>> apache-maven-3.8.0-bin.zip sha512: b56da9a0efa45e084e4882b795787fc7b61970d19835635b2db099b91a9854f14e3776a01d569e3f7af9db946a05af91abbfad41cdc5ac09e90df25077dec01e
>> apache-maven-3.8.0-src.zip sha512: 51a1570894e8fb1ef52cb19ce472866745ccae2720e45304edd3cabc212cdf105937c76502558fe87995aea81c41402d7f581cc8e9393af234b64696e9a45893
>>
>>
>> Staging site:
>> https://maven.apache.org/ref/3-LATEST/
>>
>> Guide to testing staged releases:
>> https://maven.apache.org/guides/development/guide-testing-releases.html
>>
>> Vote open for at least 72 hours.
>>
>> [ ] +1
>> [ ] +0
>> [ ] -1
>
>
>
> --
> Elliotte Rusty Harold
> [hidden email]
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [hidden email]
> For additional commands, e-mail: [hidden email]
>



---------------------------------------------------------------------
To unsubscribe, e-mail: [hidden email]
For additional commands, e-mail: [hidden email]

Reply | Threaded
Open this post in threaded view
|

Re: [VOTE] Release Apache Maven version 3.8.0

Hervé BOUTEMY
In reply to this post by Elliotte Rusty Harold
I'm not worried about attempt to download: the issue you found proves that the value of the mirror url blocks anything, even if not really the ideal way

but you're right that it's hard to understand from a user perspective...

I just managed to fix the issue:
https://github.com/apache/maven/commit/d295dc362fe7d7b189b4976a5742a17362eb51a1

perhaps we should respin 3.8.1

Regards,

Hervé

Le mercredi 24 mars 2021, 20:51:10 CET Maarten Mulders a écrit :

> A 0-vote from my side. As far as I can tell, non-TLS repos are indeed
> blocked. That is the main reason for cutting this release, and it works,
> which is good.
>
> But if I understood Hervé correctly, the message that appears when Maven
> attempts download of an artifact over a non-TLS connection differs
> depending on which component attempted the download. This has two
> consequences:
>
> 1. The message is sometimes pretty clear, but sometimes rather vague. An
> example of the latter one: "Checksum validation failed, expected Lorem
> but is a0a3234b13da255645808f53efb387d26ae441db". One must be quite
> clever to deduce that Maven attempted to download something over HTTP.
>
> 2. I am worried that we may have missed a component that also attempts
> to download artifacts, and still allows non-HTTP connections.
>
>
> Maybe I didn't understand correctly - I actually hope so. In that case,
> please explain me where my understanding is wrong.
>
> Thanks,
>
>
> Maarten
>
> On March 24th, 2021 at 18:54, Gary Gregory wrote:
> > Whenever I have to explain to colleagues that Maven "burns" version
> > numbers
> > when a release candidate fails or some other obtuse reason, they are just
> > as baffled as I am. In the end it does not matter it's just bizarre.
> >
> > Gary
> >
> > On Tue, Mar 23, 2021, 20:58 Olivier Lamy <[hidden email]> wrote:
> >> +0
> >> Same reason as Ralph, the versioning seems weird to me.
> >> I don't understand the reasoning of version number. Our version number
> >> doesn't have to be managed by some tweet or google links.
> >>
> >>
> >> On Wed, 24 Mar 2021 at 09:17, Ralph Goers <[hidden email]>
> >>
> >> wrote:
> >>> If I were a user and expected the feature to be in 3.7.0 then I would
> >>> certainly also expect it in 3.8.0. The only ways to avoid this are a)
> >>
> >> stay
> >>
> >>> on 3.6.x.x until the feature is available, b) specifically say the
> >>
> >> promised
> >>
> >>> features aren’t available yet.
> >>>
> >>> That said I’m +0 on the version numbering.
> >>>
> >>> Ralph
> >>>
> >>>> On Mar 22, 2021, at 3:09 PM, Robert Scholte <[hidden email]>
> >>>
> >>> wrote:
> >>>> There were enough tweets and conference talks were I demonstrated the
> >>>
> >>> idea behind build/consumer.
> >>>
> >>>> Of course the audience wanted to hear a version, so the best possible
> >>>
> >>> answer was "most likely 3.7.0"
> >>>
> >>>> First Google hit: Maven 3.7 to Include Default Wrapper - InfoQ[1] and
> >>>
> >>> you can find much more.
> >>>
> >>>> Several PMC members discussed about what would be the proper value, the
> >>>
> >>> result was in the end 3.8.0.
> >>>
> >>>> Most important: it is beyond 3.6.3 and before 4.
> >>>>
> >>>> Robert
> >>>>
> >>>> [1] https://www.infoq.com/news/2020/04/maven-wrapper/
> >>>>
> >>>> On 22-3-2021 21:14:10, Elliotte Rusty Harold <[hidden email]>
> >>
> >> wrote:
> >>>> I'm a weak -1 on this, solely because I don't find the reasoning for
> >>>> not calling this 3.7.0 to be compelling. "Apache Maven 3.7.0 would be
> >>>> the first release where you could optionally activate the
> >>>> build/consumer feature. This version of this release has been renamed
> >>>> to 4.0.0. Reusing 3.7.0 might lead to confusion, hence we picked the
> >>>> next available minor version."
> >>>>
> >>>> Are we sure? I certainly didn't expect 3.7.0 to be the first release
> >>>> where you could optionally activate the build/consumer feature. I
> >>>> can't say I expected anything in particular for 3.7.0. Did Maven ever
> >>>> promise there would be a 3.7.0 with this feature?
> >>>>
> >>>> If it were renamed 3.7.0 I'd be at +1.
> >>>>
> >>>> On Mon, Mar 22, 2021 at 7:40 PM Robert Scholte wrote:
> >>>>> Hi,
> >>>>>
> >>>>> For the details about this release, please read
> >>>
> >>> https://maven.apache.org/docs/3.8.0/release-notes.html
> >>>
> >>>>> Also please provide feedback on the release notes. (as you know, these
> >>>
> >>> are published separately from the release, so it doesn't have to block
> >>
> >> the
> >>
> >>> release itself)
> >>>
> >>>>> We solved 5 issues:
> >> https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12316922
> >> &version=12350003&styleName=Text>>
> >>>>> There are still a couple of issues left in JIRA:
> >> https://issues.apache.org/jira/issues/?jql=project%20%3D%2012316922%20AND
> >> %20resolution%20%3D%20Unresolved%20ORDER%20BY%20key%20DESC%2C%20priority%
> >> 20DESC>>
> >>>>> Staging repo:
> >>>>> https://repository.apache.org/content/repositories/maven-1633/
> >>
> >> https://dist.apache.org/repos/dist/release/maven/maven-3/3.8.0/binaries/a
> >> pache-maven-3.8.0-bin.zip
> >>
> >>
> >> https://dist.apache.org/repos/dist/release/maven/maven-3/3.8.0/source/apa
> >> che-maven-3.8.0-src.zip>>
> >>>>> Source release checksum(s):
> >>
> >>>>> apache-maven-3.8.0-bin.zip sha512:
> >> b56da9a0efa45e084e4882b795787fc7b61970d19835635b2db099b91a9854f14e3776a01
> >> d569e3f7af9db946a05af91abbfad41cdc5ac09e90df25077dec01e>>
> >>>>> apache-maven-3.8.0-src.zip sha512:
> >> 51a1570894e8fb1ef52cb19ce472866745ccae2720e45304edd3cabc212cdf105937c7650
> >> 2558fe87995aea81c41402d7f581cc8e9393af234b64696e9a45893>>
> >>>>> Staging site:
> >>>>> https://maven.apache.org/ref/3-LATEST/
> >>
> >>>>> Guide to testing staged releases:
> >> https://maven.apache.org/guides/development/guide-testing-releases.html
> >>
> >>>>> Vote open for at least 72 hours.
> >>>>>
> >>>>> [ ] +1
> >>>>> [ ] +0
> >>>>> [ ] -1
> >>>>
> >>>> --
> >>>> Elliotte Rusty Harold
> >>>> [hidden email]
> >>>>
> >>>> ---------------------------------------------------------------------
> >>>> To unsubscribe, e-mail: [hidden email]
> >>>> For additional commands, e-mail: [hidden email]
> >>>
> >>> ---------------------------------------------------------------------
> >>> To unsubscribe, e-mail: [hidden email]
> >>> For additional commands, e-mail: [hidden email]
> >>
> >> --
> >> Olivier Lamy
> >> http://twitter.com/olamy | http://linkedin.com/in/olamy
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [hidden email]
> For additional commands, e-mail: [hidden email]





---------------------------------------------------------------------
To unsubscribe, e-mail: [hidden email]
For additional commands, e-mail: [hidden email]

Reply | Threaded
Open this post in threaded view
|

Re: [VOTE] Release Apache Maven version 3.8.0

Gary Gregory-2
In reply to this post by Elliotte Rusty Harold
It's pretty clear to me that the Maven release process is broken when
people are getting new versions they think are real and valid when in fact
it is a release candidate vote in in progress.

Gary


On Thu, Mar 25, 2021, 19:17 Nick Stolwijk <[hidden email]> wrote:

> Also +1 (non-binding) for me. I ran a chocolatey upgrade and I also have
> Maven 3.8.0.
>
> nicks@DESKTOP-HHAT2G9 (voyager) ~
> 00:15:29 $ mvn --version
> Apache Maven 3.8.0 (6aa1f4acf5d6323e9aa08b763cb9933dc96749b9)
> Maven home: C:\ProgramData\chocolatey\lib\maven\apache-maven-3.8.0
> Java version: 16, vendor: Oracle Corporation, runtime: C:\Program
> Files\OpenJDK\jdk-16
> Default locale: en_GB, platform encoding: UTF-8
> OS name: "windows 10", version: "10.0", arch: "amd64", family: "windows"
>
> It seems such installers are (too) quick to upgrade.
>
> With regards,
>
> Nick Stolwijk
>
> ~~~ Try to leave this world a little better than you found it and, when
> your turn comes to die, you can die happy in feeling that at any rate you
> have not wasted your time but have done your best ~~~
>
> Lord Baden-Powell
>
>
> On Fri, Mar 26, 2021 at 12:05 AM Mark Derricutt <[hidden email]> wrote:
>
> > +1 non-binding from me, tho I have (potential) concerns.
> >
> > I’d missed seeing the emails about the release vote, but DID notice that
> > Mac Homebrew had upgraded me magically to 3.8.0.
> >
> > Which led me to tweeting that it seemed the download page wasn’t updated
> (
> > then a followup about home-brew jumping the gun):
> >
> > https://twitter.com/talios/status/1374188445380214784
> >
> > Carlo Cabrera responded that he reverted the change in Homebrew:
> >
> > https://twitter.com/carlocab_/status/1374230372112867330
> >
> > tho, anyone who happened to download the update, still has that update
> > installed.
> >
> > Downloading the zip here, and checking:
> >
> > ~/Downloads/Download Sync/apache-maven-3.8.0 ❯ ./bin/mvn -version
> > Apache Maven 3.8.0 (6aa1f4acf5d6323e9aa08b763cb9933dc96749b9)
> > Maven home: /Users/amrk/Downloads/Download Sync/apache-maven-3.8.0
> > Java version: 1.8.0_282, vendor: Azul Systems, Inc., runtime:
> >
> >
> /Users/amrk/.sdkman/candidates/java/8.0.282-zulu/zulu-8.jdk/Contents/Home/jre
> > Default locale: en_NZ, platform encoding: UTF-8
> > OS name: "mac os x", version: "10.16", arch: "x86_64", family: "mac"
> > ~/Downloads/Download Sync/apache-maven-3.8.0 took 3s ❯ mvn --version
> > Apache Maven 3.8.0 (6aa1f4acf5d6323e9aa08b763cb9933dc96749b9)
> > Maven home: /usr/local/Cellar/maven/3.8.0/libexec
> > Java version: 1.8.0_282, vendor: Azul Systems, Inc., runtime:
> >
> >
> /Users/amrk/.sdkman/candidates/java/8.0.282-zulu/zulu-8.jdk/Contents/Home/jre
> > Default locale: en_NZ, platform encoding: UTF-8
> > OS name: "mac os x", version: "10.16", arch: "x86_64", family: "mac"
> >
> > both releases have the same SHA1 for the build - so in this instance I’m
> > happy for a +1.
> >
> > Tho I wonder what the recourse would be if needing to respin the release
> -
> > 3.8.1 version bump or?
> >
> > Is there anyway to prevent this happening again? ( Probably off-thread
> > replies would be best ).
> >
> > Mark
> >
> >
> >
> >
> > From: Tibor Digana <[hidden email]> <[hidden email]>
> > Reply: Maven Developers List <[hidden email]> <
> [hidden email]>
> > Date: 26 March 2021 at 8:05:51 AM
> > To: Maven Developers List <[hidden email]> <[hidden email]>
> > Subject:  Re: [VOTE] Release Apache Maven version 3.8.0
> >
> > here is mine +1.
> > The amount of work means more for me than the version 3.7.0 we skipped.
> We
> > can improve it in the future of course!
> > Regarding the issues found with the Warning on the console, these issues
> > can be fixed as always, right after.
> > T
> >
> > On Mon, Mar 22, 2021 at 8:40 PM Robert Scholte <[hidden email]>
> > wrote:
> >
> > > Hi,
> > >
> > > For the details about this release, please read
> > > https://maven.apache.org/docs/3.8.0/release-notes.html
> > > Also please provide feedback on the release notes. (as you know, these
> > are
> > > published separately from the release, so it doesn't have to block the
> > > release itself)
> > >
> > > We solved 5 issues:
> > >
> > >
> >
> >
> https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12316922&version=12350003&styleName=Text
> > >
> > > There are still a couple of issues left in JIRA:
> > >
> > >
> >
> >
> https://issues.apache.org/jira/issues/?jql=project%20%3D%2012316922%20AND%20resolution%20%3D%20Unresolved%20ORDER%20BY%20key%20DESC%2C%20priority%20DESC
> > >
> > > Staging repo:
> > > https://repository.apache.org/content/repositories/maven-1633/
> > >
> > >
> > >
> >
> >
> https://dist.apache.org/repos/dist/release/maven/maven-3/3.8.0/binaries/apache-maven-3.8.0-bin.zip
> > >
> > >
> >
> >
> https://dist.apache.org/repos/dist/release/maven/maven-3/3.8.0/source/apache-maven-3.8.0-src.zip
> > >
> > >
> > > Source release checksum(s):
> > >
> > > apache-maven-3.8.0-bin.zip sha512:
> >
> >
> b56da9a0efa45e084e4882b795787fc7b61970d19835635b2db099b91a9854f14e3776a01d569e3f7af9db946a05af91abbfad41cdc5ac09e90df25077dec01e
> >
> > >
> > > apache-maven-3.8.0-src.zip sha512:
> >
> >
> 51a1570894e8fb1ef52cb19ce472866745ccae2720e45304edd3cabc212cdf105937c76502558fe87995aea81c41402d7f581cc8e9393af234b64696e9a45893
> >
> > >
> > >
> > > Staging site:
> > > https://maven.apache.org/ref/3-LATEST/
> > >
> > > Guide to testing staged releases:
> > >
> https://maven.apache.org/guides/development/guide-testing-releases.html
> > >
> > > Vote open for at least 72 hours.
> > >
> > > [ ] +1
> > > [ ] +0
> > > [ ] -1
> > >
> >
>
Reply | Threaded
Open this post in threaded view
|

Re: [VOTE] Release Apache Maven version 3.8.0

Olivier Lamy
Yes you're right that shouldn't be there as this has been mirrored in all
Apache mirrors as a real release...

The procedure
http://maven.apache.org/developers/release/maven-core-release.html says:
"

For non-alpha/beta releases, release candidates are produced before the
actual release.

Checkout https://dist.apache.org/repos/dist/dev/maven/maven-3 then create
the necessary directory tree.

"

@Robert I moved the binaries. As the vote is not finished they shouldn;t be
in the official Apache release download area

svn mv https://dist.apache.org/repos/dist/release/maven/maven-3/3.8.0
https://dist.apache.org/repos/dist/dev/maven/maven-3/

Committing transaction...

Committed revision 46741.

On Fri, 26 Mar 2021 at 13:18, Mark Derricutt <[hidden email]> wrote:

> I notice in the vote email we have mentioned:
>
>
> dist.apache.org/repos/dist/release/maven/maven–3/3.8.0/binaries/apache-maven–3.8.0-bin.zip
> <http://dist.apache.org/repos/dist/release/maven/maven%E2%80%933/3.8.0/binaries/apache-maven%E2%80%933.8.0-bin.zip>
> <
> http://dist.apache.org/repos/dist/release/maven/maven%E2%80%933/3.8.0/binaries/apache-maven%E2%80%933.8.0-bin.zip
> >
>
> which doesn’t really highlight anywhere that this is a staging/unreleased
> version.
>
> Tho changing that probably won’t change too much here.
>
> *ponders*
>
>
>
>
> From: Gary Gregory <[hidden email]> <[hidden email]>
> Reply: Maven Developers List <[hidden email]> <[hidden email]>
> Date: 26 March 2021 at 2:13:05 PM
> To: Maven Developers List <[hidden email]> <[hidden email]>
> Subject:  Re: [VOTE] Release Apache Maven version 3.8.0
>
> It's pretty clear to me that the Maven release process is broken when
> people are getting new versions they think are real and valid when in fact
> it is a release candidate vote in in progress. Gary
>


--
Olivier Lamy
http://twitter.com/olamy | http://linkedin.com/in/olamy
Reply | Threaded
Open this post in threaded view
|

Re: [VOTE] Release Apache Maven version 3.8.0

Enrico Olivelli
The problem is that Robert uploaded the binaries to the "dist/release" directory

this is to be done only after the vote completes

IIRC we have dist/dev for staging releasing

Enrico

Il giorno ven 26 mar 2021 alle ore 08:17 Maxim Solodovnik
<[hidden email]> ha scritto:

>
> Hello,
>
> Moving might not do what is expected
> the binaries are already in http://archive.apache.org/dist/maven/maven-3/3.8.0/
>
> On Fri, 26 Mar 2021 at 11:25, Olivier Lamy <[hidden email]> wrote:
> >
> > Yes you're right that shouldn't be there as this has been mirrored in all
> > Apache mirrors as a real release...
> >
> > The procedure
> > http://maven.apache.org/developers/release/maven-core-release.html says:
> > "
> >
> > For non-alpha/beta releases, release candidates are produced before the
> > actual release.
> >
> > Checkout https://dist.apache.org/repos/dist/dev/maven/maven-3 then create
> > the necessary directory tree.
> >
> > "
> >
> > @Robert I moved the binaries. As the vote is not finished they shouldn;t be
> > in the official Apache release download area
> >
> > svn mv https://dist.apache.org/repos/dist/release/maven/maven-3/3.8.0
> > https://dist.apache.org/repos/dist/dev/maven/maven-3/
> >
> > Committing transaction...
> >
> > Committed revision 46741.
> >
> > On Fri, 26 Mar 2021 at 13:18, Mark Derricutt <[hidden email]> wrote:
> >
> > > I notice in the vote email we have mentioned:
> > >
> > >
> > > dist.apache.org/repos/dist/release/maven/maven–3/3.8.0/binaries/apache-maven–3.8.0-bin.zip
> > > <http://dist.apache.org/repos/dist/release/maven/maven%E2%80%933/3.8.0/binaries/apache-maven%E2%80%933.8.0-bin.zip>
> > > <
> > > http://dist.apache.org/repos/dist/release/maven/maven%E2%80%933/3.8.0/binaries/apache-maven%E2%80%933.8.0-bin.zip
> > > >
> > >
> > > which doesn’t really highlight anywhere that this is a staging/unreleased
> > > version.
> > >
> > > Tho changing that probably won’t change too much here.
> > >
> > > *ponders*
> > >
> > >
> > >
> > >
> > > From: Gary Gregory <[hidden email]> <[hidden email]>
> > > Reply: Maven Developers List <[hidden email]> <[hidden email]>
> > > Date: 26 March 2021 at 2:13:05 PM
> > > To: Maven Developers List <[hidden email]> <[hidden email]>
> > > Subject:  Re: [VOTE] Release Apache Maven version 3.8.0
> > >
> > > It's pretty clear to me that the Maven release process is broken when
> > > people are getting new versions they think are real and valid when in fact
> > > it is a release candidate vote in in progress. Gary
> > >
> >
> >
> > --
> > Olivier Lamy
> > http://twitter.com/olamy | http://linkedin.com/in/olamy
>
>
>
> --
> Best regards,
> Maxim
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [hidden email]
> For additional commands, e-mail: [hidden email]
>

---------------------------------------------------------------------
To unsubscribe, e-mail: [hidden email]
For additional commands, e-mail: [hidden email]

Reply | Threaded
Open this post in threaded view
|

Re: [VOTE] Release Apache Maven version 3.8.0

Guillaume Nodet
In reply to this post by Olivier Lamy
And that's expected as archive.apache.org keeps all releases that are not
current, i.e. those that have been removed from dist.apache.org.
The release process should really be fixed and the commit to dist.apache.org
should really happen after the vote.
I suggest sending an email to infra to see if the binaries can be removed
from archive.apache.org.

In any case, I'm -0 on this release.  I'm also concerned about the leap in
the release numbering.  You need to balance how many people will wonder why
3.7.0 can not be found vs the number of people who were expecting a feature
in 3.7.0 (which they would expect to be in 3.8.0 anyway).  A failed attempt
should not lead to a missing release number either, as the failure stays in
the dev community, so I don't think the larger user audience cares about
those...



Le ven. 26 mars 2021 à 08:17, Maxim Solodovnik <[hidden email]> a
écrit :

> Hello,
>
> Moving might not do what is expected
> the binaries are already in
> http://archive.apache.org/dist/maven/maven-3/3.8.0/
>
> On Fri, 26 Mar 2021 at 11:25, Olivier Lamy <[hidden email]> wrote:
> >
> > Yes you're right that shouldn't be there as this has been mirrored in all
> > Apache mirrors as a real release...
> >
> > The procedure
> > http://maven.apache.org/developers/release/maven-core-release.html says:
> > "
> >
> > For non-alpha/beta releases, release candidates are produced before the
> > actual release.
> >
> > Checkout https://dist.apache.org/repos/dist/dev/maven/maven-3 then
> create
> > the necessary directory tree.
> >
> > "
> >
> > @Robert I moved the binaries. As the vote is not finished they shouldn;t
> be
> > in the official Apache release download area
> >
> > svn mv https://dist.apache.org/repos/dist/release/maven/maven-3/3.8.0
> > https://dist.apache.org/repos/dist/dev/maven/maven-3/
> >
> > Committing transaction...
> >
> > Committed revision 46741.
> >
> > On Fri, 26 Mar 2021 at 13:18, Mark Derricutt <[hidden email]> wrote:
> >
> > > I notice in the vote email we have mentioned:
> > >
> > >
> > >
> dist.apache.org/repos/dist/release/maven/maven–3/3.8.0/binaries/apache-maven–3.8.0-bin.zip
> <http://dist.apache.org/repos/dist/release/maven/maven%E2%80%933/3.8.0/binaries/apache-maven%E2%80%933.8.0-bin.zip>
> > > <
> http://dist.apache.org/repos/dist/release/maven/maven%E2%80%933/3.8.0/binaries/apache-maven%E2%80%933.8.0-bin.zip
> >
> > > <
> > >
> http://dist.apache.org/repos/dist/release/maven/maven%E2%80%933/3.8.0/binaries/apache-maven%E2%80%933.8.0-bin.zip
> > > >
> > >
> > > which doesn’t really highlight anywhere that this is a
> staging/unreleased
> > > version.
> > >
> > > Tho changing that probably won’t change too much here.
> > >
> > > *ponders*
> > >
> > >
> > >
> > >
> > > From: Gary Gregory <[hidden email]> <[hidden email]>
> > > Reply: Maven Developers List <[hidden email]> <
> [hidden email]>
> > > Date: 26 March 2021 at 2:13:05 PM
> > > To: Maven Developers List <[hidden email]> <[hidden email]
> >
> > > Subject:  Re: [VOTE] Release Apache Maven version 3.8.0
> > >
> > > It's pretty clear to me that the Maven release process is broken when
> > > people are getting new versions they think are real and valid when in
> fact
> > > it is a release candidate vote in in progress. Gary
> > >
> >
> >
> > --
> > Olivier Lamy
> > http://twitter.com/olamy | http://linkedin.com/in/olamy
>
>
>
> --
> Best regards,
> Maxim
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [hidden email]
> For additional commands, e-mail: [hidden email]
>
>

--
------------------------
Guillaume Nodet
Reply | Threaded
Open this post in threaded view
|

Re: [VOTE] Release Apache Maven version 3.8.0

Arnaud Héritier
In reply to this post by Elliotte Rusty Harold
+1

On Sat, Mar 27, 2021 at 4:03 AM Mark Derricutt <[hidden email]> wrote:

> Mostly reads good to me, only minor niggle to me is:
>
> Then once the vote passed, svn move to release
>
> which I think might be grammatically better:
>
> “Once the vote has passed, svn move to the release tree ”
>
> +1.5 non-binding :)
>
>
>
>
> From: Hervé BOUTEMY <[hidden email]> <[hidden email]>
> Reply: Maven Developers List <[hidden email]> <[hidden email]>
> Date: 27 March 2021 at 2:19:48 PM
> To: Maven Developers List <[hidden email]> <[hidden email]>
> Subject:  Re: [VOTE] Release Apache Maven version 3.8.0
>
> first pass of documentation improvement done in
>
> github.com/apache/maven-site/commit/ec73b445adc7012e1384cf1b89af3f0a6f5eee17
> please all review and see if anything you read may be mis-interpreted when
> reading fast
>


--
Arnaud Héritier
Twitter/Skype : aheritier