[ 
https://issues.apache.org/jira/browse/TOMEE-2975?focusedWorklogId=562343&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-562343
 ]

ASF GitHub Bot logged work on TOMEE-2975:
-----------------------------------------

                Author: ASF GitHub Bot
            Created on: 08/Mar/21 13:21
            Start Date: 08/Mar/21 13:21
    Worklog Time Spent: 10m 
      Work Description: rmannibucau commented on a change in pull request #21:
URL: 
https://github.com/apache/tomee-site-generator/pull/21#discussion_r589415574



##########
File path: src/main/jbake/content/download-ng.adoc
##########
@@ -7,12 +7,18 @@
 
 [.table.table-bordered,options="header"]
 
+== Release Integrity
+
+You **must** link:https://www.apache.org/info/verification.html[verify] the 
integrity of the downloaded files. We provide OpenPGP signatures  (*.asc files) 
for every release file. This signature should be matched against 
link:https://downloads.apache.org/tomee/KEYS[KEYS] file which contains the 
OpenPGP keys of TomEE's Release Managers. We also provide SHA-512 checksums for 
every release file. After you download the file, you should calculate a 
checksum for your download, and make sure it is the same as ours.
+
+== Download Links
+
 |===
 |Name|Version|Date|Size|Type|Links
-|TomEE plume|9.0.0-M3|25 Jan 2021|65 MB |ZIP| 
https://www.apache.org/dyn/closer.cgi/tomee/tomee-9.0.0-M3/apache-tomee-9.0.0-M3-plume.zip[icon:download[]
 ZIP] 
https://www.apache.org/dist/tomee/tomee-9.0.0-M3/apache-tomee-9.0.0-M3-plume.zip.sha256[icon:download[]
 SHA256] 
https://www.apache.org/dist/tomee/tomee-9.0.0-M3/apache-tomee-9.0.0-M3-plume.zip.sha512[icon:download[]
 SHA512]
-|TomEE plus|9.0.0-M3|25 Jan 2021|58 MB |ZIP| 
https://www.apache.org/dyn/closer.cgi/tomee/tomee-9.0.0-M3/apache-tomee-9.0.0-M3-plus.zip[icon:download[]
 ZIP] 
https://www.apache.org/dist/tomee/tomee-9.0.0-M3/apache-tomee-9.0.0-M3-plus.zip.sha256[icon:download[]
 SHA256] 
https://www.apache.org/dist/tomee/tomee-9.0.0-M3/apache-tomee-9.0.0-M3-plus.zip.sha512[icon:download[]
 SHA512]
-|TomEE webprofile|9.0.0-M3|25 Jan 2021|41 MB |ZIP| 
https://www.apache.org/dyn/closer.cgi/tomee/tomee-9.0.0-M3/apache-tomee-9.0.0-M3-webprofile.zip[icon:download[]
 ZIP] 
https://www.apache.org/dist/tomee/tomee-9.0.0-M3/apache-tomee-9.0.0-M3-webprofile.zip.sha256[icon:download[]
 SHA256] 
https://www.apache.org/dist/tomee/tomee-9.0.0-M3/apache-tomee-9.0.0-M3-webprofile.zip.sha512[icon:download[]
 SHA512]
-|TomEE microprofile|9.0.0-M3|25 Jan 2021|41 MB |ZIP| 
https://www.apache.org/dyn/closer.cgi/tomee/tomee-9.0.0-M3/apache-tomee-9.0.0-M3-microprofile.zip[icon:download[]
 ZIP] 
https://www.apache.org/dist/tomee/tomee-9.0.0-M3/apache-tomee-9.0.0-M3-microprofile.zip.sha256[icon:download[]
 SHA256] 
https://www.apache.org/dist/tomee/tomee-9.0.0-M3/apache-tomee-9.0.0-M3-microprofile.zip.sha512[icon:download[]
 SHA512]
+|TomEE plume|9.0.0-M3|25 Jan 2021|65 MB |ZIP| 
https://www.apache.org/dyn/closer.cgi/tomee/tomee-9.0.0-M3/apache-tomee-9.0.0-M3-plume.zip[icon:download[]
 ZIP] 
https://www.apache.org/dist/tomee/tomee-9.0.0-M3/apache-tomee-9.0.0-M3-plume.zip.sha256[icon:download[]
 SHA256] 
https://www.apache.org/dist/tomee/tomee-9.0.0-M3/apache-tomee-9.0.0-M3-plume.zip.sha512[icon:download[]
 SHA512] 
https://www.apache.org/dist/tomee/tomee-9.0.0-M3/apache-tomee-9.0.0-M3-plume.zip.asc[icon:download[]
 PGP]

Review comment:
       is it a manual fix? Should go into 
https://github.com/apache/tomee-site-generator/blob/master/src/main/java/org/apache/tomee/website/Downloads.java#L152
 probably




----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
[email protected]


Issue Time Tracking
-------------------

    Worklog Id:     (was: 562343)
    Time Spent: 20m  (was: 10m)

> Download page must provide sigs for all release artifacts
> ---------------------------------------------------------
>
>                 Key: TOMEE-2975
>                 URL: https://issues.apache.org/jira/browse/TOMEE-2975
>             Project: TomEE
>          Issue Type: Bug
>         Environment: http://tomee.apache.org/download-ng.html
>            Reporter: Sebb
>            Assignee: Richard Zowalla
>            Priority: Major
>          Time Spent: 20m
>  Remaining Estimate: 0h
>
> None of the releases on the download page have signature files (.asc).
> These are required:
> [https://infra.apache.org/release-distribution#sigs-and-sums]
> The asc files are present on the download site, they just need to be linked 
> from the page.
> Also there must be a link to the KEYS file, as well as download verification 
> instructions.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

Reply via email to