> On Sep 3, 2026, at 5:09 PM, Justin Mclean <[email protected]> wrote:
>
> Hi,
>
> ATR is useful but it won't change much here. It checks signatures, hashes,
> headers, and the presence of the DISCLAIMER, and those rarely get a -1. The
> analysis of ten years of general@ release votes [1] found the mechanical
> issues have mostly gone. Releases get voted down on general@ for things that
> need a person to look at: bundled third-party code with no license, LICENSE
> and NOTICE that don't match what's in the archive, category X dependencies,
> compiled code in the source release, etc. Tooling won't find those sorts of
> issues.
If there is an SBOM then we may find Category X dependencies. We do checks on
artifact integrity which can include checking that source artifacts include
nothing that is not in the repository. But that’s not pertinent to this
discussion.
ATR can handle counting votes on multiple email threads. It can allow ballots
to be cast in the system. It allows contributors to vote unless it’s an
expedited release.
Best,
Dave
>
> Concurrent votes don't reduce that review, they just mean the IPMC does it on
> RCs the podling hasn't checked yet. If IPMC members wait for the PPMC result
> before looking, as Tison suggests, then the general@ vote sits idle until it
> arrives.
>
> Thanks,
> Justin
>
> 1.
> https://cwiki.apache.org/confluence/spaces/INCUBATOR/pages/393677685/Release+Vote+Insights
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
>
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]