-1 (non-binding)
I verified the release candidate as follows:
- Downloaded openserverless-0.9.0-incubating-RC3-src.tar.gz from
https://dist.apache.org/repos/dist/dev/incubator/openserverless/0.9.0-incubating-RC3/-
Imported KEYS, verified the GPG signature: "Good signature from Michele
Sciabarra (Apache OpenServerless Release Key)"- Verified the SHA512 checksum:
OK- Confirmed LICENSE, NOTICE, README.md, CHANGES present at the root- Ran
build-and-test-ubuntu.sh on a clean environment: build completed, and all 13
applicable test scripts (deploy, ssl, sys-redis, sys-ferretdb, sys-postgres,
sys-seaweedfs, login, static, user-redis, user-ferretdb, user-postgres,
user-seaweedfs, runtime-testing) reported SUCCESS.
While checking for unexpected binary files in the source archive(per VERIFY.md
section 5), I found:
- oplugins-op/enterprise-util/kafka/jmx/jmx_prometheus_javaagent-0.18.0.jar
(544KB), a compiled third-party binary.
I checked both LICENSE and NOTICE at the root of the archive andfound no
mention of this file or of jmx_prometheus_javaagent /Prometheus JMX exporter.
I haven't reviewed every other .jar file in the archive in thesame depth (there
are also several small gradle-wrapper.jar andtest-fixture hello.jar files
elsewhere, which I have not assessed),so my vote is specifically about this one
undocumented binary, nota general claim about all binaries in the source tree.
I'd be happy to change my vote once this is addressed or clarified -apologies
if I'm missing something.
Il giorno giovedì 10 settembre 2026 alle ore 16:47:16 CEST, Michele
Sciabarra <[email protected]> ha scritto:
Hi all,
I propose the following RC to be released as the official
Apache OpenServerless 0.9.0-incubating release.
Apache OpenServerless is an effort undergoing incubation at The Apache
Software
Foundation (ASF), sponsored by the Apache Incubator. Incubation is required
of all newly accepted projects until a further review indicates that the
infrastructure, communications, and decision making process have stabilized
in a manner consistent with other successful ASF projects. While incubation
status is not necessarily a reflection of the completeness or stability of
the code, it does indicate that the project has yet to be fully endorsed by
the ASF.
The artifacts for this release candidate can be found at:
https://dist.apache.org/repos/dist/dev/incubator/openserverless/0.9.0-incubating-RC3
The Git tag to be voted upon is:
v0.9.0-incubating-RC3
https://github.com/apache/openserverless/releases/tag/v0.9.0-incubating-RC3
Release artifacts are signed with the GPG key of the release manager.
The KEYS file is available at:
https://dist.apache.org/repos/dist/dev/incubator/openserverless/KEYS
Please download, verify, and test the release candidate.
For detailed step-by-step instructions on how to verify this
release, please see the file VERIFY.md within the source
archive, or check:
https://github.com/apache/openserverless/blob/0.9.0/VERIFY.md
The vote will run for a minimum of 72 hours and close no earlier
than:
2026-09-13 16:30 UTC
Please vote:
[ ] +1 Release this package as Apache OpenServerless 0.9.0-incubating
[ ] +0
[ ] -1 Do not release this package because... (reason required)
Only PPMC members have binding votes, but community votes are
encouraged.
Checklist for reference:
[ ] Download links are valid
[ ] Checksums and signatures are valid
[ ] LICENSE/NOTICE files exist
[ ] No unexpected binary files in source
[ ] All source files have ASF headers
[ ] Can compile from source
On behalf of the Apache OpenServerless Podling PMC (PPMC),
--
Michele Sciabarrà - [email protected] - linkedin.com/in/msciab
Apache OpenServerless committer - reddit.com/r/openserverless
Apache OpenWhisk PMC member - Author Learning Apache OpenWhisk
<https://www.oreilly.com/library/view/learning-apache-openwhisk/9781492046158/>