On 15 August 2013 10:08, Chris Graham <chrisgw...@gmail.com> wrote:
> What sebb does not appear to have understood or accepted, as Stephen has
> endlessly pointed out, is that we vote on the source bundle, not a scm
> revision, and that, strictly speaking a SCM is not even required (however
> sensible it is to use one).
> He wants a tree and a revision so that we can compare between releases,
> where what he should be doing, strictly speaking, is comparing source tar
> balls, as that is what we really are voting on.

I agree that what is released (and voted on) are the source tarballs.
And any such tarballs should be identical (barring possibly different
EOL settings for text files).

However, that is only one of the checks that need to be made.

The PMC also needs to ensure that the files are being released under
the correct license.

I contend that the only practical way to check the licences is to
compare the source tarball(s) with the files in SCM.

[The files should only be added to SCM if the license is OK, so the
SCM tag acts as a database of validated source files.]

The SVN revision / Git hash are needed to ensure uniqueness.

To unsubscribe, e-mail: dev-unsubscr...@maven.apache.org
For additional commands, e-mail: dev-h...@maven.apache.org

Reply via email to