My +1

Gary

On Fri, Oct 2, 2026 at 10:31 PM Gary Gregory <[email protected]> wrote:
>
> We have fixed a few bugs and added enhancements since the release of
> Apache Commons Secure XML 1.0.0, so I would like to release Apache
> Commons Secure XML 1.1.0.
>
> Apache Commons Secure XML 1.1.0 RC1 is available for review here:
>     https://dist.apache.org/repos/dist/dev/commons/secure-xml/1.1.0-RC1
> (svn revision 88170)
>
> The Git tag commons-secure-xml-1.1.0-RC1 commit for this RC is
> 22936183b876d473d7de20de669eab19dbbf137c, which you can browse here:
>     
> https://gitbox.apache.org/repos/asf?p=commons-secure-xml.git;a=commit;h=22936183b876d473d7de20de669eab19dbbf137c
> You may checkout this tag using:
>     git clone https://gitbox.apache.org/repos/asf/commons-secure-xml.git
> --branch commons-secure-xml-1.1.0-RC1 commons-secure-xml-1.1.0-RC1
>
> Maven artifacts are here:
>     
> https://repository.apache.org/content/repositories/orgapachecommons-1967/org/apache/commons/commons-secure-xml/1.1.0/
>
> These are the artifacts and their hashes:
>
> #Release SHA-512s
> #Sat Oct 03 02:23:05 UTC 2026
> commons-secure-xml-1.1.0-bin.tar.gz=3c5337624100592624a589317c1bcac13a699f8a0735b7c378739c18394dd94eb8900753176f9f8d352ca153345d6510b24c12849a6fdcff2ec993ef6bdbb97f
> commons-secure-xml-1.1.0-bin.zip=9b20b8a2cf27ccf392792914353802edbbe5b139a1333cd6bb50c7c482a45b0a20731fc62b67d29410f59f1ff02fe299c93f56e3cdfeee0dec16f0a83a14d881
> commons-secure-xml-1.1.0-bom.json=df107b7b2678ab071d602b6be4bbfd48338ff74ee8604833ba9f76bdcff576b5854a4873fb56cf5c755a2a64e08b682a80cba5270bebdd2359f5ad01d6f311f4
> commons-secure-xml-1.1.0-bom.xml=890dc3647b85a073e59ed2fa6ad27644fbbb28453880b94e4bdc27b79f6f6959b1d475826ebc6a6902961a275275909fc583a331aec0c6daea9a79c0c0d52bf5
> commons-secure-xml-1.1.0-javadoc.jar=2fa465ec66ed70bbf04105567e12eb832da9f8e38c4aef1caac00131cdb6bccbc7861a0687419a489fd3688841f0ed6e880a06402c5a2da4d3b07bbe17315714
> commons-secure-xml-1.1.0-sources.jar=0e650164b80744597971b0028d7c247cc00418ea1f87a34179c75115583a2879141cead273ab0141c66a0652ec9af61c735b2bb961fbf1a704c5e619d3f84bee
> commons-secure-xml-1.1.0-src.tar.gz=cfe99526c45f9964bd5d89f9a10e50054072aba64b1f693d8901e6674010fcd4fe4abd2da24e8e1e8d9a822fdcd49b4fb64b4b960c6a6e7d453d6dbd6b000ebc
> commons-secure-xml-1.1.0-src.zip=0960817254e138d060baa9f574cdebaa88a3d5672d7a302ea7387922021eea11d106360fbe3cabffa27ea00846619dd35c2f864da9e0029ab518981dd6e33eb1
> commons-secure-xml-1.1.0-test-sources.jar=f2b71ea10675948cb5f7919d0d6d0ec1c0edc6fd2e1af037048530d4bb604b569ca48160f0428da71b11259e3c5fbe14c065244a91bee90e844f82590f19ccc2
> org.apache.commons_commons-secure-xml-1.1.0.spdx.json=25e2ee5a5dba83e6396e20ff0bf1918c7c259194e545454a33e1299778e9327b62baae4c2477d67d618634ce433f6529ce582fb58db469497505148d094a3f68
>
>
> I have tested this with 'mvn' and 'mvn clean install site' using:
>
> openjdk version "25.0.4.1" 2026-08-18
> OpenJDK Runtime Environment Homebrew (build 25.0.4.1)
> OpenJDK 64-Bit Server VM Homebrew (build 25.0.4.1, mixed mode, sharing)
>
> Apache Maven 3.10.0 (c43a36b8d67be7e0805a411bc0898af1a51f5472)
> Maven home: /opt/homebrew/Cellar/maven/3.10.0/libexec
> Java version: 25.0.4.1, vendor: Homebrew, runtime:
> /opt/homebrew/Cellar/openjdk@25/25.0.4.1/libexec/openjdk.jdk/Contents/Home
> Default locale: en_US, platform encoding: UTF-8, time zone: UTC
> OS name: "mac os x", version: "26.7.1", arch: "aarch64", family: "mac"
>
> Darwin Garys-MacBook-Pro.local 25.6.0 Darwin Kernel Version 25.6.0:
> Tue Aug 18 17:48:46 PDT 2026;
> root:xnu-12377.161.15.700.19~2/RELEASE_ARM64_T6041 arm64
>
> Docker version 29.8.1, build 4a63305
>
>
> Details of changes since 1.0.0 are in the release notes:
>     
> https://dist.apache.org/repos/dist/dev/commons/secure-xml/1.1.0-RC1/RELEASE-NOTES.txt
>     
> https://dist.apache.org/repos/dist/dev/commons/secure-xml/1.1.0-RC1/site/changes.html
>
> Site:
>     
> https://dist.apache.org/repos/dist/dev/commons/secure-xml/1.1.0-RC1/site/index.html
>     (Note some *relative* links are broken and the 1.1.0 directories
> are not yet created - these will be OK once the site is deployed.)
>
> JApiCmp Report (compared to 1.0.0):
>     
> https://dist.apache.org/repos/dist/dev/commons/secure-xml/1.1.0-RC1/site/japicmp.html
>
> RAT Report:
>     
> https://dist.apache.org/repos/dist/dev/commons/secure-xml/1.1.0-RC1/site/rat-report.html
>
> KEYS:
>   https://downloads.apache.org/commons/KEYS
>
> Please review the release candidate and vote.
> This vote will close no sooner than 72 hours from now.
>
>   [ ] +1 Release these artifacts
>   [ ] +0 OK, but...
>   [ ] -0 OK, but really should fix...
>   [ ] -1 I oppose this release because...
>
> Thank you,
>
> Gary Gregory,
> Release Manager (using key 530AA5F25C25011F)
>
> The following is intended as a helper and refresher for reviewers.
>
> Validating a release candidate
> ==============================
>
> These guidelines are NOT complete.
>
> Requirements: Git, Java, and Maven.
>
> You can validate a release from a release candidate (RC) tag as follows.
>
> 1a) Download and decompress the source archive from:
>
> https://dist.apache.org/repos/dist/dev/commons/secure-xml/1.1.0-RC1/source
>
> 1b) Check out the RC tag from git (optional)
>
> This is optional,  as a reviewer must at least check source distributions.
>
> git clone https://gitbox.apache.org/repos/asf/commons-secure-xml.git
> --branch commons-secure-xml-1.1.0-RC1 commons-secure-xml-1.1.0-RC1
> cd commons-secure-xml-1.1.0-RC1
>
> 2) Checking the build
>
> All components should include a default Maven goal, such that you can
> run 'mvn' from the command line by itself.
>
> 2) Check Apache licenses
>
> This step is not required if the site includes a RAT report page,
> which you then must check.
> This check should be included in the default Maven build, but you can
> check it with:
>
> mvn apache-rat:check
>
> 3) Check binary compatibility
>
> This step is not required if the site includes a JApiCmp report page,
> which you then must check.
> This check should be included in the default Maven build, but you can
> check it with:
>
> mvn verify -DskipTests -P japicmp japicmp:cmp
>
> 4) Build the package
>
> This check should be included in the default Maven build, but you can
> check it with:
>
> mvn -V clean package
>
> You can record the Maven and Java version produced by -V in your VOTE reply.
> To gather OS information from a command line:
> Windows: ver
> Linux: uname -a
>
> 4b) Check reproducibility
>
> To check that a build is reproducible, run:
>
> mvn clean verify artifact:compare -DskipTests
> -Dreference.repo=https://repository.apache.org/content/repositories/staging/
> '-Dbuildinfo.ignore=*/*.spdx.json'
>
> Note that this excludes SPDX files from the check.
>
> 5) Build the site for a single module project
>
> Note: Some plugins require the components to be installed instead of packaged.
>
> mvn site
> Check the site reports in:
> - Windows: target\site\index.html
> - Linux: target/site/index.html
>
> -the end-

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to