+1 (binding)

On Sun, Sep 20, 2026 at 1:50 PM Søren Berg Glasius <[email protected]>
wrote:

> +1 (binding)
>
>
> Den lør. 19. sep. 2026 kl. 21.38 skrev Matt M <
> [email protected]>:
>
>> +1 (binding)
>>
>>
>> ------ Original Message ------
>> From "Paul King" <[email protected]>
>> To "Groovy_Developers" <[email protected]>
>> Date 9/18/2026 9:52:15 PM
>> Subject [VOTE] Release Apache Groovy 6.0.0
>>
>> >
>> >
>> >Dear development community,
>> >
>> >
>> >
>> >I am happy to start the VOTE thread for a Groovy 6.0.0 release!
>> >
>> >
>> >
>> >This release includes 10 bug fixes/improvements as outlined in the
>> changelog:
>> >
>> >
>> https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12318123&version=12357525
>> >
>> >
>> >
>> >Tag: https://github.com/apache/groovy/tree/GROOVY_6_0_0/
>> >
>> >Tag commit id: bc6b3cfd9f8f3397129f8ebbdf85a189d16d7360
>> >
>> >
>> >
>> >The artifacts to be voted on are located as follows (r87671).
>> >
>> >Source release:
>> https://dist.apache.org/repos/dist/dev/groovy/6.0.0/sources
>> >
>> >Convenience binaries:
>> >
>> >https://dist.apache.org/repos/dist/dev/groovy/6.0.0/distribution
>> >
>> >Temporary artifacts:
>> >
>> >https://repository.apache.org/content/repositories/orgapachegroovy-1125
>> >
>> >
>> >
>> >Release artifacts are signed with a key from the following file:
>> >
>> >https://dist.apache.org/repos/dist/release/groovy/KEYS
>> >
>> >
>> >
>> >Please vote on releasing this package as Apache Groovy 6.0.0.
>> >
>> >
>> >
>> >Reminder on ASF release approval requirements for PMC members:
>> >
>> >http://www.apache.org/legal/release-policy.html#release-approval
>> >
>> >Hints on validating checksums/signatures (but replace md5sum with
>> sha256sum):
>> >
>> >https://www.apache.org/info/verification.html
>> >
>> >
>> >
>> >The vote is open for the next 72 hours and passes if a majority of at
>> >
>> >least three +1 PMC votes are cast.
>> >
>> >
>> >
>> >[ ] +1 Release Apache Groovy 6.0.0
>> >
>> >[ ]  0 I don't have a strong opinion about this, but I assume it's ok
>> >
>> >[ ] -1 Do not release Apache Groovy 6.0.0 because...
>> >
>> >
>> >
>> >Here is my vote:
>> >
>> >
>> >
>> >+1 (binding)
>> >
>> >
>> >
>> >----
>> >
>> >
>> >
>> >My local verify.sh:
>> >
>> >
>> >
>> >✅ KEYS Downloaded
>> >
>> >✅ Source Distribution Verified
>> >
>> >✅ Binary Distribution Verified
>> >
>> >✅ Docs Distribution Verified
>> >
>> >✅ SDK Distribution Verified
>> >
>> >✅ Gradle Bootstrapped
>> >
>> >✅ RAT passed
>> >
>> >✅✅✅ Automatic verification finished.
>> >
>> >
>> >
>> >GroovyPolicyMCP:
>> >
>> >
>> >
>> >**Verdict: Apache Groovy 6.0.0 is clean. I would vote +1.** Every
>> >
>> >check on the release checklist passed, and my worktree for the RAT run
>> >
>> >was removed without touching your GROOVY_6_0_X checkout.
>> >
>> >
>> >
>> >**Tag and source**
>> >
>> >
>> >
>> >- The annotated tag on gitbox and GitHub resolves to commit
>> >
>> >bc6b3cfd9f8f3397129f8ebbdf85a189d16d7360, matching the vote email. Its
>> >
>> >parent is on origin/GROOVY_6_0_X, and it carries 12 commits after
>> >
>> >RC-3, all dependency bumps and the listed fixes.
>> >
>> >- The source zip is identical to `git archive` at the tag. The only
>> >
>> >absent files are the usual deliberate omissions: benchmark, perf
>> >
>> >dashboard, wrapper, governance docs, CI configs, ABI surface.
>> >
>> >- No compiled code or archives in the source zip. The full project RAT
>> >
>> >check passes at the tag. The version is 6.0.0 with no SNAPSHOT or RC
>> >
>> >remnants in the properties, jar manifests, or poms.
>> >
>> >- The JIRA changelog lists 10 unique issues, as the email says.
>> >
>> >
>> >
>> >**Signatures and checksums**
>> >
>> >
>> >
>> >| Location                           | Artifacts | Signed by
>> >
>> >6A65176A0FB1CD0B | Checksums                           |
>> >
>> >| ---------------------------------- | --------- |
>> >
>> >-------------------------- | ----------------------------------- |
>> >
>> >| dist.apache.org zips               | 4         | 4 good
>> >
>> >        | SHA-256 match                       |
>> >
>> >| Nexus staging orgapachegroovy-1125 | 297       | 297 good
>> >
>> >        | md5, sha1, sha256, sha512 all match |
>> >
>> >
>> >
>> >The key is in the published KEYS file at dist/release/groovy.
>> >
>> >
>> >
>> >**LICENSE and NOTICE**
>> >
>> >
>> >
>> >- All four zips' LICENSE and NOTICE files are byte-identical to
>> >
>> >RC-3's. Pointers resolve 18 of 18 in binary and SDK, 6 of 6 in source,
>> >
>> >4 of 4 in docs, with no unreferenced texts. NOTICE carries the 13
>> >
>> >upstream credits.
>> >
>> >- The lib set changed only in versions since RC-3: JLine and jansi to
>> >
>> >4.4.5, jcl-over-slf4j to 2.0.19, and the maven-resolver family to
>> >
>> >2.0.23. JLine 4.4.5's pom still declares BSD-3-Clause, and the other
>> >
>> >two keep their MIT and Apache licences, so the existing LICENSE text
>> >
>> >covers them.
>> >
>> >- All 167 staged jars carry META-INF LICENSE and NOTICE with every
>> >
>> >pointer resolving. Raw, shaded, grooid, sources and groovy-all-sources
>> >
>> >declarations match their content. Sources, javadoc and groovydoc jars
>> >
>> >contain no classes.
>> >
>> >- The core, grooid and groovy-test-grooid jars in the binary zip are
>> >
>> >byte-identical to the staged ones, as are all 39 module jars in lib/,
>> >
>> >and the staged groovy-binary zip is byte-identical to the dist binary
>> >
>> >zip.
>> >
>> >- All 43 poms declare the licence with no SNAPSHOT or RC dependencies.
>> >
>> >SBOMs show 729 of 729 components licensed.
>>
>>
>
> --
>
> Med venlig hilsen,
> Søren Berg Glasius
>
> Hedevej 1, Gl. Rye, 8680 Ry
> Mobile: +45 40 44 91 88 <+45%2040%2044%2091%2088>
> --- Press ESC once to quit - twice to save the changes.
>

Reply via email to