Hi,

Separately, asyncband 0.7.0 was just published to crates.io. That's a serious 
policy violation, and it needs to be fixed urgently.

Podlings can make non-ASF releases, so that's not the problem. The Incubator 
guidance says a non-ASF release is distributed via non-ASF infrastructure and 
is either not linked from the podling website or is clearly marked as a non-ASF 
release, and that the ASF takes on no legal liability for them [1][2]. This was 
none of that. It was published by trusted publishing from the apache/asyncband 
repository, through the release environment configured in .asf.yaml, under the 
Apache Asyncband name, with nothing on the crates.io page marking it as 
anything other than an Apache release. The release policy says projects shall 
not publish unreleased materials outside the development community [3], and 
this was the version the IPMC was voting on, with a binding -1 against it.

Please yank 0.7.0. That stops new dependencies from resolving to it and leaves 
existing builds working. If you want a non-ASF release to unblock downstream 
users in the meantime, it needs to be clearly marked as a non-ASF release.

Kind regards,
Justin

1. https://incubator.apache.org/policy/incubation.html (see Releases)
2. https://incubator.apache.org/guides/releasemanagement.html (see Requesting 
feedback on interim non-ASF releases)
3. https://www.apache.org/legal/release-policy.html#publication
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to