-1 (non-binding)
I verified the release candidate as follows:
- Downloaded openserverless-0.9.0-incubating-RC3-src.tar.gz from  
https://dist.apache.org/repos/dist/dev/incubator/openserverless/0.9.0-incubating-RC3/-
 Imported KEYS, verified the GPG signature: "Good signature from  Michele 
Sciabarra (Apache OpenServerless Release Key)"- Verified the SHA512 checksum: 
OK- Confirmed LICENSE, NOTICE, README.md, CHANGES present at the root- Ran 
build-and-test-ubuntu.sh on a clean environment: build completed,  and all 13 
applicable test scripts (deploy, ssl, sys-redis,  sys-ferretdb, sys-postgres, 
sys-seaweedfs, login, static, user-redis,  user-ferretdb, user-postgres, 
user-seaweedfs, runtime-testing)  reported SUCCESS.
While checking for unexpected binary files in the source archive(per VERIFY.md 
section 5), I found:
- oplugins-op/enterprise-util/kafka/jmx/jmx_prometheus_javaagent-0.18.0.jar  
(544KB), a compiled third-party binary.
I checked both LICENSE and NOTICE at the root of the archive andfound no 
mention of this file or of jmx_prometheus_javaagent /Prometheus JMX exporter.
I haven't reviewed every other .jar file in the archive in thesame depth (there 
are also several small gradle-wrapper.jar andtest-fixture hello.jar files 
elsewhere, which I have not assessed),so my vote is specifically about this one 
undocumented binary, nota general claim about all binaries in the source tree.
I'd be happy to change my vote once this is addressed or clarified -apologies 
if I'm missing something.

    Il giorno giovedì 10 settembre 2026 alle ore 16:47:16 CEST, Michele 
Sciabarra <[email protected]> ha scritto:  
 
 Hi all,

I propose the following RC to be released as the official
Apache OpenServerless 0.9.0-incubating release.

Apache OpenServerless is an effort undergoing incubation at The Apache
Software
Foundation (ASF), sponsored by the Apache Incubator. Incubation is required
of all newly accepted projects until a further review indicates that the
infrastructure, communications, and decision making process have stabilized
in a manner consistent with other successful ASF projects. While incubation
status is not necessarily a reflection of the completeness or stability of
the code, it does indicate that the project has yet to be fully endorsed by
the ASF.

The artifacts for this release candidate can be found at:

https://dist.apache.org/repos/dist/dev/incubator/openserverless/0.9.0-incubating-RC3

The Git tag to be voted upon is:

v0.9.0-incubating-RC3

https://github.com/apache/openserverless/releases/tag/v0.9.0-incubating-RC3

Release artifacts are signed with the GPG key of the release manager.

The KEYS file is available at:

https://dist.apache.org/repos/dist/dev/incubator/openserverless/KEYS

Please download, verify, and test the release candidate.

For detailed step-by-step instructions on how to verify this
release, please see the file VERIFY.md within the source
archive, or check:

https://github.com/apache/openserverless/blob/0.9.0/VERIFY.md

The vote will run for a minimum of 72 hours and close no earlier
than:

2026-09-13 16:30 UTC

Please vote:

[ ] +1 Release this package as Apache OpenServerless 0.9.0-incubating
[ ] +0
[ ] -1 Do not release this package because... (reason required)

Only PPMC members have binding votes, but community votes are
encouraged.

Checklist for reference:
[ ] Download links are valid
[ ] Checksums and signatures are valid
[ ] LICENSE/NOTICE files exist
[ ] No unexpected binary files in source
[ ] All source files have ASF headers
[ ] Can compile from source

On behalf of the Apache OpenServerless Podling PMC (PPMC),
--
Michele Sciabarrà - [email protected] - linkedin.com/in/msciab
Apache OpenServerless committer - reddit.com/r/openserverless
Apache OpenWhisk PMC member  - Author Learning Apache OpenWhisk
<https://www.oreilly.com/library/view/learning-apache-openwhisk/9781492046158/>
  

Reply via email to