+1 (non-binding) with minor nits shown below.

The GPL license in legal/LICENSE in the javadoc surprised me but its javadoc 
for a convenience binary so someone more familiar with Maven builds should make 
the call on that one. Claude check was verbose but included below in case it 
saves other's some time.

Cheers, Paul.

----


Claude with GroovyPolicyMCP checked:
================

Source distribution (src.tar.gz and src.zip):
- PGP signatures verify against key 530AA5F25C25011F
  (F4DD 59C9 0148 BDC5 2BEB  90A4 530A A5F2 5C25 011F), which is
  present in https://downloads.apache.org/commons/KEYS
- SHA-512 files match the archives and match the hashes in the VOTE mail
- LICENSE.txt (full AL2.0) and NOTICE.txt present at the root;
  NOTICE uses the required "developed at" wording, Copyright 2001-2026
- No compiled code (no .class/.jar/.so/.dll). The 194 .obj files are
  Java-serialised test fixtures for the serialisation compatibility tests
- src.tar.gz and src.zip are content-identical (922 files)
- Contents match git tag commons-collections-4.6.0-RC1
  (4107624de41aeed37985d2a069fad41992fd71a2) exactly - no file content
  differences; only dev-infra files are excluded from the assembly
  (.github, .gitignore, .asf.yaml, CODE_OF_CONDUCT.md, SECURITY.md,
  download_collections.cgi)
- Builds and tests clean: 3707 tests, 0 failures, 0 errors, 7 skipped

Binary distribution:
- Signatures and SHA-512s verify as above
- LICENSE.txt and NOTICE.txt present at the root
- bin.tar.gz and bin.zip are content-identical
- Bundled jars are byte-identical to the Nexus staging jars, and the
  src-dist pom.xml is byte-identical to the staged .pom

Nexus staging (orgapachecommons-1956):
- All 9 artifacts carry good signatures from the same key
- All match the SHA-512s given in the VOTE mail

Reports:
- RAT: 0 unapproved licences, 725 files AL2.0
- JApiCmp: no binary-incompatible changes; suggested semver bump 0.1.0,
  consistent with 4.5.0 -> 4.6.0. The four REMOVED entries are the
  intentional @Deprecated removals on Factory/Predicate/Transformer/Closure

Reproducible build:
- mvn clean verify artifact:compare against the staging repo reproduces
  all artifacts bit-for-bit (spdx.json ignored as per your instructions)

Environment
===========

Build and test:
openjdk version "17.0.20" 2026-07-21 LTS
OpenJDK Runtime Environment Zulu17.68+17-CA (build 17.0.20+8-LTS)
OpenJDK 64-Bit Server VM Zulu17.68+17-CA (build 17.0.20+8-LTS, mixed mode, 
sharing)

Reproducibility check: OpenJDK 21.0.10 Zulu21.48+15-CA

Apache Maven 3.9.16 (2bdd9fddda4b155ebf8000e807eb73fd829a51d5)

macOS 15.7.3 (24G419)
Darwin 24.6.0 arm64

Minor observations, none blocking
=================================

1. The reproducibility check only matches under TZ=UTC. The moditect
   add-module-info step writes zip entry timestamps in local time rather
   than normalising via project.build.outputTimestamp, so the main jar
   appears to differ by the reviewer's UTC offset. Everything else matches
   regardless of timezone. Might be worth adding TZ=UTC to step 4b of the
   validation instructions to save reviewers outside UTC some head
   scratching.

2. commons-collections4-4.6.0-javadoc.jar has no META-INF/LICENSE.txt or
   NOTICE.txt, unlike the other jars. It carries the JDK's legal/ directory
   instead, where legal/LICENSE is the GPLv2 text (with Classpath Exception
   via ASSEMBLY_EXCEPTION). Relatedly, the binary distribution bundles
   jQuery 3.7.1 and jQuery UI (MIT) under apidocs/script-dir/, which the
   root LICENSE.txt does not mention, though apidocs/legal/jquery.md and
   jqueryUI.md are present. This is inherited from stock javadoc and is
   common across ASF Java projects; the source release is unaffected.

3. The hash list in the VOTE mail uses the local build's file names rather
   than the deployed artifact names, which briefly had me looking for
   missing SBOMs. To save others the same detour: nothing is missing, the
   SBOMs are all present.

   commons-parent sets the CycloneDX outputName to
   ${project.artifactId}-${project.version}-bom, so the file on disk is
   commons-collections4-4.6.0-bom.json, but the plugin attaches it with
   classifier "cyclonedx" and it deploys as
   commons-collections4-4.6.0-cyclonedx.json. Likewise the SPDX file is
   written as org.apache.commons_commons-collections4-4.6.0.spdx.json but
   deploys as commons-collections4-4.6.0.spdx.json.

   The hashes confirm these are the same bytes either way - I verified the
   VOTE mail's -bom.json/-bom.xml hashes against both my own rebuild's
   target/ output and the -cyclonedx.json/-cyclonedx.xml files downloaded
   from staging. Might be worth having the release plugin emit the deployed
   names in the hash list.

4. RELEASE-NOTES.txt lists "Add a Maven benchmark profile for JMH" twice.


On 2026/08/06 10:18:34 Gary Gregory wrote:
> We have fixed a few bugs and added enhancements since the release of
> Apache Commons Collections 4.5.0, so I would like to release Apache
> Commons Collections 4.6.0.
> 
> Apache Commons Collections 4.6.0 RC1 is available for review here:
>     https://dist.apache.org/repos/dist/dev/commons/collections/4.6.0-RC1
> (svn revision 86577)
> 
> The Git tag commons-collections-4.6.0-RC1 commit for this RC is
> 4107624de41aeed37985d2a069fad41992fd71a2, which you can browse here:
>     
> https://gitbox.apache.org/repos/asf?p=commons-collections.git;a=commit;h=4107624de41aeed37985d2a069fad41992fd71a2
> You may checkout this tag using:
>     git clone https://gitbox.apache.org/repos/asf/commons-collections.git
> --branch commons-collections-4.6.0-RC1 commons-collections-4.6.0-RC1
> 
> Maven artifacts are here:
>     
> https://repository.apache.org/content/repositories/orgapachecommons-1956/org/apache/commons/commons-collections4/4.6.0/
> 
> These are the artifacts and their hashes:
> 
> #Release SHA-512s
> #Thu Aug 06 10:04:34 UTC 2026
> commons-collections4-4.6.0-bin.tar.gz=b54c61737ff2ec7eaf6e1caf4d2adae42534dd28a9383c3fae1d5f299bce97b00ca15aee2c81ba4a4b50e64db69103cc3629a43af39b52f90990cdee944d3aa5
> commons-collections4-4.6.0-bin.zip=7dd17310d9cde4148efca1c077040b4fc390056ac6ed93891037e012db89e5e5fac7cf6b7031c053f66fb36f7a246dab3c9b11a09c8974a8ad2a4b29c4ce7c01
> commons-collections4-4.6.0-bom.json=af24476bfeebbec0ba5d2cea15671b3f6d7df0b43db5f1b007749e41b6807386e00f04259804099c6e0b30d42cf68691607ae9de69c325765a169ca55c34c190
> commons-collections4-4.6.0-bom.xml=3afc64e7fe828d3fbd176e378fe3a87187331c22c3270f97bc53e51a3a0f648afdf3249b8b10ee2e8903779bb3ac6cf6cbe99696c719c69668d802ebe4770bd8
> commons-collections4-4.6.0-javadoc.jar=e41380ffeeef2cea4b1d3b573fa797785a892a69dcf67d12f3ea6933eca0deed9a274c088a030094e8813010cc3568866d9997141262e886876cf7de05ab998b
> commons-collections4-4.6.0-sources.jar=11f08ac33ed6b8736599884d1b39ddf5dbb176b7b65873bcc6f2afc7112c1549c4b86ee74f68bbe7fad693ff4839af384480bcde516c04dfda8b37852c711a40
> commons-collections4-4.6.0-src.tar.gz=445a1771c01ca87dd37e5ed16304858add36b4f7b8a0032ef2ba6aae8c4e59fa31e45ebcc67c1c71c64f34784c4382b2378ddc212819000a1f04ec25e77513d5
> commons-collections4-4.6.0-src.zip=6c58b8fd8eee2bc2b081e26c18685a0f13074ba92ef4ca5bd413ffaad71f3df04c977aa56f0eac9472cc8ddee5cb86bfc9525e60816e5e71c78f762566c0c9d2
> commons-collections4-4.6.0-test-sources.jar=e1c1e2f2906c867728317db4851082ea6ffa81c4b1ec6a59ba676761347c959b0b32a0731deea06cca4ce99ada8ac9499a4272c2fbe3e23f75ed7ffe2a79ad3b
> commons-collections4-4.6.0-tests.jar=9f06898680a41b32d3bb16324d58a20a8ec1cbc36bd5cb2cb369ed51b762d83ff45c018ffefea47ef0a526d3278512ca337dcf4e43f15a67d0b4d725be00a5aa
> org.apache.commons_commons-collections4-4.6.0.spdx.json=7459288c9504a8be96d5d5b55ada620be9c15b30d64dc7f0e2892985e1bb62e6888163e755487c56ada472dab8e00387c6be020329f5f776f275c8f60c7b66f9
> 
> 
> I have tested this with 'mvn' and 'mvn clean install site' using:
> 
> openjdk version "21.0.12" 2026-07-21
> OpenJDK Runtime Environment Homebrew (build 21.0.12)
> OpenJDK 64-Bit Server VM Homebrew (build 21.0.12, mixed mode, sharing)
> 
> Apache Maven 3.9.16 (2bdd9fddda4b155ebf8000e807eb73fd829a51d5)
> Maven home: /opt/homebrew/Cellar/maven/3.9.16/libexec
> Java version: 21.0.12, vendor: Homebrew, runtime:
> /opt/homebrew/Cellar/openjdk@21/21.0.12/libexec/openjdk.jdk/Contents/Home
> Default locale: en_US, platform encoding: UTF-8
> OS name: "mac os x", version: "26.6", arch: "aarch64", family: "mac"
> 
> Darwin Garys-MacBook-Pro.local 25.6.0 Darwin Kernel Version 25.6.0:
> Sat Jul 11 15:27:27 PDT 2026;
> root:xnu-12377.161.13~4/RELEASE_ARM64_T6041 arm64
> 
> Docker version 29.6.2, build dfc4efb
> 
> 
> Details of changes since 4.5.0 are in the release notes:
>     
> https://dist.apache.org/repos/dist/dev/commons/collections/4.6.0-RC1/RELEASE-NOTES.txt
>     
> https://dist.apache.org/repos/dist/dev/commons/collections/4.6.0-RC1/site/changes.html
> 
> Site:
>     
> https://dist.apache.org/repos/dist/dev/commons/collections/4.6.0-RC1/site/index.html
>     (Note some *relative* links are broken and the 4.6.0 directories
> are not yet created - these will be OK once the site is deployed.)
> 
> JApiCmp Report (compared to 4.5.0):
>     
> https://dist.apache.org/repos/dist/dev/commons/collections/4.6.0-RC1/site/japicmp.html
> 
> RAT Report:
>     
> https://dist.apache.org/repos/dist/dev/commons/collections/4.6.0-RC1/site/rat-report.html
> 
> KEYS:
>   https://downloads.apache.org/commons/KEYS
> 
> Please review the release candidate and vote.
> This vote will close no sooner than 72 hours from now.
> 
>   [ ] +1 Release these artifacts
>   [ ] +0 OK, but...
>   [ ] -0 OK, but really should fix...
>   [ ] -1 I oppose this release because...
> 
> Thank you,
> 
> Gary Gregory,
> Release Manager (using key 530AA5F25C25011F)
> 
> The following is intended as a helper and refresher for reviewers.
> 
> Validating a release candidate
> ==============================
> 
> These guidelines are NOT complete.
> 
> Requirements: Git, Java, and Maven.
> 
> You can validate a release from a release candidate (RC) tag as follows.
> 
> 1a) Download and decompress the source archive from:
> 
> https://dist.apache.org/repos/dist/dev/commons/collections/4.6.0-RC1/source
> 
> 1b) Check out the RC tag from git (optional)
> 
> This is optional,  as a reviewer must at least check source distributions.
> 
> git clone https://gitbox.apache.org/repos/asf/commons-collections.git
> --branch commons-collections-4.6.0-RC1 commons-collections-4.6.0-RC1
> cd commons-collections-4.6.0-RC1
> 
> 2) Checking the build
> 
> All components should include a default Maven goal, such that you can
> run 'mvn' from the command line by itself.
> 
> 2) Check Apache licenses
> 
> This step is not required if the site includes a RAT report page,
> which you then must check.
> This check should be included in the default Maven build, but you can
> check it with:
> 
> mvn apache-rat:check
> 
> 3) Check binary compatibility
> 
> This step is not required if the site includes a JApiCmp report page,
> which you then must check.
> This check should be included in the default Maven build, but you can
> check it with:
> 
> mvn verify -DskipTests -P japicmp japicmp:cmp
> 
> 4) Build the package
> 
> This check should be included in the default Maven build, but you can
> check it with:
> 
> mvn -V clean package
> 
> You can record the Maven and Java version produced by -V in your VOTE reply.
> To gather OS information from a command line:
> Windows: ver
> Linux: uname -a
> 
> 4b) Check reproducibility
> 
> To check that a build is reproducible, run:
> 
> mvn clean verify artifact:compare -DskipTests
> -Dreference.repo=https://repository.apache.org/content/repositories/staging/
> '-Dbuildinfo.ignore=*/*.spdx.json'
> 
> Note that this excludes SPDX files from the check.
> 
> 5) Build the site for a single module project
> 
> Note: Some plugins require the components to be installed instead of packaged.
> 
> mvn site
> Check the site reports in:
> - Windows: target\site\index.html
> - Linux: target/site/index.html
> 
> -the end-
> 
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
> 
> 

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to