+1 (binding). Verified everything from the dev dist folder and reproduced the
artifacts from the wave tag.

Wave tag providers/2026-08-25 -> commit aab20fadfad6ad9c0f219f324af53de1c98d2c1d
("Prepare providers release 2026-08-25" #72069), which is on main. All three rc
tags (providers-amazon/9.35.1rc1, providers-fab/3.8.1rc2,
providers-microsoft-azure/15.0.1rc1) point at that same commit.

* Folder complete: 21 files = 3 providers x (whl + sdist + .asc + .sha512) plus
  the source trio. 7 .sha512 / 7 .asc, nothing spurious.
* SHA512: 7/7 OK.
* GPG: 7/7 good signatures, all your key
  BD78CB838D25B411C1241EAAC079C32311BB9FEB (ed25519), present in KEYS.
* Reproducible build: 7/7 byte-identical. Rebuilt the 6 provider distributions
  and the source tarball from a clean checkout at the wave tag; every artifact
  matches the published SHA512 exactly.
* Licences: apache-rat 0.18 over the source tarball -> 0 unapproved, 0 unknown
  (10014 standard files).
* No binaries in the source release beyond the four known pre-existing fixtures
  (the two registry web fonts, the google gcs tmp.tar.gz placeholder and the
  azure dummy.pdf test resource). LICENSE and NOTICE are in the tarball root.
* Versions consistent: pyproject version == top changelog section for all three
  providers, and all three rc pages resolve on PyPI with both wheel and sdist.
* fab 3.8.1 was excluded from the 2026-08-18 wave and never published, so
  keeping the same version and extending its changelog section (rc2 adds
  #72010 on top of the rc1 content) is the right call rather than superseding
  it. I confirmed the national-cloud endpoints from #72010 are actually in the
  shipped wheel, and Aaron Chen has confirmed on #72117 that #71920 - the
  regression that pulled fab from the last wave - is fixed.

Good job on your first release Niko !

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to