This vote passes with the following binding +1 votes:

- Piotr P. Karwasz (pkarwasz)
- Rob Tompkins (chtompki)
- Gary Gregory (ggregory)

Thank you all,
Gary

On Sun, Sep 6, 2026 at 8:14 AM Gary Gregory <[email protected]> wrote:
>
> My +1
>
> Gary
>
> On Thu, Sep 3, 2026 at 10:46 PM Rob Tompkins <[email protected]> wrote:
> >
> > +1 (I missed the missing binary zip file on my last ok, admittedly I regret 
> > that. i did compiler verification, signature verification and site 
> > verification….whoops….I’m human). Checked the distribution files this time, 
> > they all look good and have proper signatures. Maybe my 
> > signature-validator.sh should verify that those files are 
> > present….thoughts????
> >
> > Otherwise from what I can tell this release looks good, as it’s well tested 
> > 91%, and the rat lines up along with it having a good RELEASE-NOTES.txt
> >
> > I know it’s a first release and that’s a bit risky, but RERO. GO!
> >
> > Cheers,
> > -Rob
> >
> > > On Sep 2, 2026, at 6:21 PM, Gary Gregory <[email protected]> wrote:
> > >
> > > I would like to release Apache Commons Secure XML 1.0.0. This is the
> > > first release, second release candidate.
> > >
> > > Apache Commons Secure XML 1.0.0 RC2 is available for review here:
> > >    https://dist.apache.org/repos/dist/dev/commons/secure-xml/1.0.0-RC2
> > > (svn revision 87149)
> > >
> > > The Git tag commons-secure-xml-1.0.0-RC2 commit for this RC is
> > > f240d75a9e69b9e89a7791ab6f226cf4a85161e4, which you can browse here:
> > >    
> > > https://gitbox.apache.org/repos/asf?p=commons-secure-xml.git;a=commit;h=f240d75a9e69b9e89a7791ab6f226cf4a85161e4
> > > You may checkout this tag using:
> > >    git clone https://gitbox.apache.org/repos/asf/commons-secure-xml.git
> > > --branch commons-secure-xml-1.0.0-RC2 commons-secure-xml-1.0.0-RC2
> > >
> > > Maven artifacts are here:
> > >    
> > > https://repository.apache.org/content/repositories/orgapachecommons-1962/org/apache/commons/commons-secure-xml/1.0.0/
> > >
> > > These are the artifacts and their hashes:
> > >
> > > #Release SHA-512s
> > > #Wed Sep 02 22:13:01 UTC 2026
> > > commons-secure-xml-1.0.0-bin.tar.gz=aceca3c825554fb396f254684080f01c772fd22f4b014fcbedb89cdc4b85bd53bfdd3c7f889170ea8c93e9ddb7d291b70abbe780aca0284f86e292761fe24031
> > > commons-secure-xml-1.0.0-bin.zip=3a84df97a21f610ef485cc393fed601ceff709f1f315ef68ebcf3ae822c20f70e186c5c9f900f9d9fc7e228718a1b3dca0164dd8365178f506f17ea653ed5e18
> > > commons-secure-xml-1.0.0-bom.json=8d847f4dc0a2875dac35513f5b4636bd5dafa6038d1acd8fcaaa6d9e15ef6ee2f2756b90377e0acf4129ffd18e6898d9d3a95ce932137815f0d3606648a9506c
> > > commons-secure-xml-1.0.0-bom.xml=a1ac8cd4bfd88a103acc2218cf49350aa7aebf1ec95e9366792e784b6f7c771e501bfefe5672eee25ebf18fdc1ea5b10fce695d5988295bc589b50ff5cf0a69b
> > > commons-secure-xml-1.0.0-javadoc.jar=781277f0a173e4533a5db0de3798b5c4284d809c1ec3629ca8dba62f9ef5c2ee13c1f986093b4cd6c4e8293352bc5b376d45b14ea384a43fde07b808e5da0fa7
> > > commons-secure-xml-1.0.0-sources.jar=9d74f98fd8032203956eb2c9e7b737f2d6184e2697761642066f4e1243c7dc12136d6abee5d857752e6bbd17e68712126de53bb3eb193485ace9a93b19442c7e
> > > commons-secure-xml-1.0.0-src.tar.gz=544c31c4c276287fd312eef07829ed7cf0ce88c7e296e4ee2a1b3b2ee185a711ee8be7479bd060b095c8cab9b4a23a7a2bbca0a040e30715154dc2788eb958e2
> > > commons-secure-xml-1.0.0-src.zip=c41883f7cbb76983726f8d1e86aa00365a3e8151ed7bd20e9d6e7dae3af2f483118fd58ae2363939225f2d47ebe53c02e90f20dbda6b266c67632d110cb03afc
> > > commons-secure-xml-1.0.0-test-sources.jar=0f6c95a8e764cecf064bf9613405036d6dd1dc3ef6ef478167b74a52c723d622c5eae5e742f65fefe53bf58c1a7679dd6b1b59ed1a002929bc8820d6c5c19528
> > > org.apache.commons_commons-secure-xml-1.0.0.spdx.json=ab49a0c8b3dc5ed2481ea85ea02cd2f387774bab8036b370113791726bdf4cd20b7c71c9b1e6379cadb8cdddf4e7766980e5befdd777e7333a947da08f99f3a6
> > >
> > >
> > > I have tested this with 'mvn' and 'mvn clean install site' using:
> > >
> > > openjdk version "21.0.12.1" 2026-08-18
> > > OpenJDK Runtime Environment Homebrew (build 21.0.12.1)
> > > OpenJDK 64-Bit Server VM Homebrew (build 21.0.12.1, mixed mode, sharing)
> > >
> > > Apache Maven 3.9.16 (2bdd9fddda4b155ebf8000e807eb73fd829a51d5)
> > > Maven home: /opt/homebrew/Cellar/maven/3.9.16/libexec
> > > Java version: 21.0.12.1, vendor: Homebrew, runtime:
> > > /opt/homebrew/Cellar/openjdk@21/21.0.12.1/libexec/openjdk.jdk/Contents/Home
> > > Default locale: en_US, platform encoding: UTF-8
> > > OS name: "mac os x", version: "26.6.2", arch: "aarch64", family: "mac"
> > >
> > > Darwin ****.local 25.6.0 Darwin Kernel Version 25.6.0: Fri Jul 31
> > > 19:17:26 PDT 2026; root:xnu-12377.161.14~5/RELEASE_ARM64_T6041 arm64
> > >
> > > Docker version 29.7.2, build a7dcaa6
> > >
> > >
> > > Details of changes since 103 are in the release notes:
> > >    
> > > https://dist.apache.org/repos/dist/dev/commons/secure-xml/1.0.0-RC2/RELEASE-NOTES.txt
> > >    
> > > https://dist.apache.org/repos/dist/dev/commons/secure-xml/1.0.0-RC2/site/changes.html
> > >
> > > Site:
> > >    
> > > https://dist.apache.org/repos/dist/dev/commons/secure-xml/1.0.0-RC2/site/index.html
> > >    (Note some *relative* links are broken and the 1.0.0 directories
> > > are not yet created - these will be OK once the site is deployed.)
> > >
> > > JApiCmp Report: None, this is the first release.
> > >
> > >
> > > RAT Report:
> > >    
> > > https://dist.apache.org/repos/dist/dev/commons/secure-xml/1.0.0-RC2/site/rat-report.html
> > >
> > > KEYS:
> > >  https://downloads.apache.org/commons/KEYS
> > >
> > > Please review the release candidate and vote.
> > > This vote will close no sooner than 72 hours from now.
> > >
> > >  [ ] +1 Release these artifacts
> > >  [ ] +0 OK, but...
> > >  [ ] -0 OK, but really should fix...
> > >  [ ] -1 I oppose this release because...
> > >
> > > Thank you,
> > >
> > > Gary Gregory,
> > > Release Manager (using key 530AA5F25C25011F)
> > >
> > > The following is intended as a helper and refresher for reviewers.
> > >
> > > Validating a release candidate
> > > ==============================
> > >
> > > These guidelines are NOT complete.
> > >
> > > Requirements: Git, Java, and Maven.
> > >
> > > You can validate a release from a release candidate (RC) tag as follows.
> > >
> > > 1a) Download and decompress the source archive from:
> > >
> > > https://dist.apache.org/repos/dist/dev/commons/secure-xml/1.0.0-RC2/source
> > >
> > > 1b) Check out the RC tag from git (optional)
> > >
> > > This is optional,  as a reviewer must at least check source distributions.
> > >
> > > git clone https://gitbox.apache.org/repos/asf/commons-secure-xml.git
> > > --branch commons-secure-xml-1.0.0-RC2 commons-secure-xml-1.0.0-RC2
> > > cd commons-secure-xml-1.0.0-RC2
> > >
> > > 2) Checking the build
> > >
> > > All components should include a default Maven goal, such that you can
> > > run 'mvn' from the command line by itself.
> > >
> > > 2) Check Apache licenses
> > >
> > > This step is not required if the site includes a RAT report page,
> > > which you then must check.
> > > This check should be included in the default Maven build, but you can
> > > check it with:
> > >
> > > mvn apache-rat:check
> > >
> > > 3) Check binary compatibility
> > >
> > > This step is not required if the site includes a JApiCmp report page,
> > > which you then must check.
> > > This check should be included in the default Maven build, but you can
> > > check it with:
> > >
> > > mvn verify -DskipTests -P japicmp japicmp:cmp
> > >
> > > 4) Build the package
> > >
> > > This check should be included in the default Maven build, but you can
> > > check it with:
> > >
> > > mvn -V clean package
> > >
> > > You can record the Maven and Java version produced by -V in your VOTE 
> > > reply.
> > > To gather OS information from a command line:
> > > Windows: ver
> > > Linux: uname -a
> > >
> > > 4b) Check reproducibility
> > >
> > > To check that a build is reproducible, run:
> > >
> > > mvn clean verify artifact:compare -DskipTests
> > > -Dreference.repo=https://repository.apache.org/content/repositories/staging/
> > > '-Dbuildinfo.ignore=*/*.spdx.json'
> > >
> > > Note that this excludes SPDX files from the check.
> > >
> > > 5) Build the site for a single module project
> > >
> > > Note: Some plugins require the components to be installed instead of 
> > > packaged.
> > >
> > > mvn site
> > > Check the site reports in:
> > > - Windows: target\site\index.html
> > > - Linux: target/site/index.html
> > >
> > > -the end-
> > >
> > > ---------------------------------------------------------------------
> > > To unsubscribe, e-mail: [email protected]
> > > For additional commands, e-mail: [email protected]
> > >
> >
> >
> > ---------------------------------------------------------------------
> > To unsubscribe, e-mail: [email protected]
> > For additional commands, e-mail: [email protected]
> >

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to