On 2019-01-10 11:11, [email protected] wrote:
Yes, but they may not be the people the board has tasked with ensuring that all 
released source code has been +1'd by at least three PMC members.

A working solution could be that during a release, a release-vote branch is maintained and everyone that +1s a release adds and pushes his signature to the release binaries to that branch. As soon as there are enough +1s to pass the vote, the release-vote branch can then be merged to master. When jenkins runs the pipeline on a master branch, the Jenkinsfile can then be written such that it builds and uploads the binaries to dist, publishes the website etc. In this scenario, write operations to the repository are always done by a human. The bot just does whatever the human tells him to do.

Reply via email to