Hey Ismael,

We've actually already been doing this since May! I started a thread for
this here https://lists.apache.org/thread/mw9dbbdjtkqlvs0mmrh452z3jsf68sct and
its in an Actions workflow here -
https://github.com/apache/beam/blob/0c6ef7dd4788d13b3785d4e06d4552907c7200e3/.github/workflows/build_release_candidate.yml#L67

Thanks for calling this out though, it's definitely nice that ASF has
published some more formal documentation/process around this. Previously I
had to ask the VP of Security for special permission to do this 🙃

Thanks,
Danny

On Thu, Aug 24, 2023 at 10:48 AM Ismaël Mejía <ieme...@gmail.com> wrote:

> Hi,
>
> I just saw an interesting change on the ASF side that could be of interest
> for Beam releases.
>
> The ASF now allows to do signing of releases by automated infrastructure.
> https://issues.apache.org/jira/browse/LEGAL-647
>
> This is a good step for automation that I remember we discussed at the
> beginning of the project so maybe someone can have some cycles to do the
> work and avoid errors/manual work in the future.
>
> Regards,
> Ismaël
>
>

Reply via email to