Re: [ALL] Reproducible builds

2025-01-11 Thread Piotr P. Karwasz
Hi Gary, On 11.01.2025 15:59, Gary Gregory wrote: In a vote thread, Herve wrote: " install should seriously be avoided when voting, but verify or package And with mvn clean verify site -s "$HOME/.m2/commons-settings.xml" artifact:compare -Dreference.repo=https://repository.apache.org/content/r

[ALL] Reproducible builds

2025-01-11 Thread Gary Gregory
In a vote thread, Herve wrote: " install should seriously be avoided when voting, but verify or package And with mvn clean verify site -s "$HOME/.m2/commons-settings.xml" artifact:compare -Dreference.repo=https://repository.apache.org/content/repositories/staging/ any voter can get his own check

[ANNOUNCE] Apache Commons Release Plugin 1.9.0

2025-01-11 Thread Gary Gregory
The Apache Commons team is pleased to announce Apache Commons Release Plugin Version 1.9.0. Historical list of changes: https://commons.apache.org/proper/commons-release-plugin//changes-report.html For complete information on the Apache Commons Release Plugin, including instructions on how to sub

[ANNOUNCE] Apache Commons Build Plugin Maven Mojo 1.15.0.

2025-01-11 Thread Gary Gregory
The Apache Commons team is pleased to announce Apache Commons Build Plugin Maven Mojo 1.15.0. Apache Maven Mojo for Apache Commons Build tasks. For example: mvn commons-build:download-page [-Dcommons.release.version=1.2.3] To use a SNAPSHOT version (for testing etc) mvn org.apache.commons:commo

[RESULT][VOTE] Release Apache Commons CSV 1.13.0 based on RC1

2025-01-11 Thread Gary Gregory
This vote thread passes with the following votes: +1 Gary Gregory (ggregory, binding) +1 Henri Biestro (henrib, binding) - 0 Herve Boutemy (hboutemy, non-binding) - 0 Piotr P. Karwasz (ppkarwasz, binding) + 1 Arnout Engelen (engelen, binding) A todo is to improve reproducible builds. TY, Gary O

Re: [VOTE] Release Apache Commons CSV 1.13.0 based on RC1

2025-01-11 Thread Gary Gregory
On Thu, Jan 9, 2025 at 6:57 PM sebb wrote: > > On Thu, 9 Jan 2025 at 23:04, Herve Boutemy wrote: > > > > -0 > > > > as I feared, same issue as Commons Release Plugin 1.9.0 RC1: wrong > > component hash in SBOM (in this case, it's one dependency: commons-codec) > > > > When I read > > > Built usi

[RESULT][VOTE][LAZY] Release Apache Commons Build Plugin Maven Mojo 1.15.0 based on RC1

2025-01-11 Thread Gary Gregory
This lazy vote passes with the following votes: +1 Gary Gregory (ggregory, binding) +1 Herve Boutemy (hboutemy, non-binding) A to-do is to improve the instructions and/or the release process for reproducible builds. TY, Gary On Wed, Jan 8, 2025 at 6:30 PM Herve Boutemy wrote: > > +1 > no issue

[RESUT][LAZY][VOTE] Release Apache Commons Release Plugin 1.9.0 based on RC1

2025-01-11 Thread Gary Gregory
This lazy vote passes with the following votes: +1 Gary Gregory (ggregory, binding) -0 Herve Boutemy (hboutemy, non-binding) A to-do is to improve the instructions and/or the release process for reproducible builds. TY, Gary On Wed, Jan 8, 2025 at 6:04 PM Herve Boutemy wrote: > > notice: when

Re: [VOTE] Release Apache Commons CSV 1.13.0 based on RC1

2025-01-11 Thread Gary Gregory
On Fri, Jan 10, 2025 at 6:36 PM Herve Boutemy wrote: > > > > On 2025/01/10 01:32:55 Gary Gregory wrote: > > On Thu, Jan 9, 2025 at 6:05 PM Herve Boutemy wrote: > > > > > > -0 > > > > > > as I feared, same issue as Commons Release Plugin 1.9.0 RC1: wrong > > > component hash in SBOM (in this case