Checked:
- git commit and tag seem correct
- could download from
https://dist.apache.org/repos/dist/dev/pekko/1.1.0-M1-RC1/
- tgz is a proper subset of git
- tgz matches sha512
882ffe5350d48b7517ee0b188dddfc5b34b4f859d2e21ec1549150ea862100c21f09b5658f6b22a62712e12fb5e05cc408363a12b218d5e0a865a0d40a027627
- checked tgz signature from 6BA4DA8B1C88A49428A29C3D0C69C1EF41181E13
-
https://github.com/apache/incubator-pekko/blob/main/README.md#verifying-the-binary-build
is not the right link, this should be
https://github.com/apache/pekko-site/wiki/Pekko-Release-Process#verifying-the-binary-build.
The 2.12 and 2.13 artifacts reproduce, the 3.3 artifacts have two
nondeterminisms (in pekko-cluster-sharding and pekko-persistence) - will
try to narrow them down and report them upstream.
- tested a small Pekko HTTP application still works fine

This is my +1

On Wed, May 8, 2024 at 2:05 PM PJ Fanning <fannin...@apache.org> wrote:

> https://github.com/apache/incubator-pekko/tree/v1.1.0-M1-RC1
> Git commit ID: b34d529f344f50801b4dd9f4df966b03d3464c2f
>
> Please download, verify, and test.
>
> We have also staged jars in the Apache Nexus Repository. These were built
> with the same code as appears in this Source Release Candidate.
> We would appreciate if users could test with these too.
> If anyone finds any serious problems with these jars, please also notify us
> on this thread.
>
> https://repository.apache.org/content/groups/staging/org/apache/pekko/
>
> For sbt 1.9.4 or greater you can add this resolver
>
> resolvers += Resolver.ApacheMavenStagingRepo
>
> Otherwise for older versions of sbt
>
> resolvers += "Apache Pekko Staging" at "
> https://repository.apache.org/content/groups/staging";
>
>
> The VOTE will pass if we have more positive votes than negative votes
> and there must be a minimum of 3 approvals from Pekko PMC members.
> Anyone voting in favour of the release, could you please provide a list of
> the checks you have done?
> The vote will be left open for at least 72hrs.
>
> [ ] +1 approve
> [ ] +0 no opinion
> [ ] -1 disapprove with the reason
>
> To learn more about Apache Pekko, please see https://pekko.apache.org/
>
> Checklist for reference:
>
> [ ] Download links are valid.
> [ ] Checksums and signatures.
> [ ] LICENSE/NOTICE files exist
> [ ] No unexpected binary files
> [ ] All source files have ASF headers
> [ ] Can compile from source
> [ ] Can verify the binary build
>
> To compile from the source, please refer to:
>
>
> https://github.com/apache/incubator-pekko/blob/main/README.md#building-from-source
>
> To verify the binary build, please refer to:
>
>
> https://github.com/apache/incubator-pekko/blob/main/README.md#verifying-the-binary-build
>
> Some notes about verifying downloads can be found at:
>
> https://pekko.apache.org/download.html#verifying-downloads
>
> Here is my +1 (binding).
>
> Thanks,
> PJ Fanning (Apache Pekko PMC member)
>


-- 
Arnout Engelen
ASF Security Response
Apache Pekko PMC member, ASF Member
NixOS Committer
Independent Open Source consultant

Reply via email to