There will definitely be an RC2 so we can pull in this PR https://github.com/apache/roller/pull/180, but I'll hold off on that to see if there's any feedback on RC1.
Dave On Sun, Sep 6, 2026 at 7:43 AM Dave <[email protected]> wrote: > Dear Apache Roller Community, > > I am pleased to call for a vote on the release of Apache Roller 6.1.6-RC1. > This is a maintenance release that retires three obsolete features, hardens > media and enclosure handling, and fixes the source distribution so that it > builds. The release candidate files can be found at: > > https://dist.apache.org/repos/dist/dev/roller/roller-6.1/v6.1.6 > > * apache-roller-6.1.6-rc1-source.tar.gz > * apache-roller-6.1.6-rc1-source.zip > * apache-roller-6.1.6-rc1-binary.tar.gz > * apache-roller-6.1.6-rc1-binary.zip > > Each has a .asc signature and .sha512 and .sha256 checksums alongside it. > This release is signed with a new key, 8FEC6F9CBA59703C, so please > re-import > KEYS before verifying: https://downloads.apache.org/roller/KEYS > > Please review the release candidate and cast your vote: > > [ ] +1 Release this package as Apache Roller 6.1.6 > [ ] 0 No opinion > [ ] -1 Do not release this package because... > > The vote will be open for at least 72 hours. > > ## Key Changes in Apache Roller 6.1.6 > > ### Retired Features - Please Read Before Upgrading > * Incoming Trackback support removed; the endpoint is gone and unmapped > * Outbound Trackback removed from the entry editor > * WSSE AtomPub authentication retired; authentication.method now takes > basic or oauth, and an installation set to wsse will fail closed on > startup rather than falling back > > ### Media and Enclosures > * Media file content types derived from file content, not the upload > request > * Enclosure metadata stored as submitted, without fetching the remote URL > > ### Authoring and Rendering > * Authoring resource lookups scoped to the weblog being edited > * Weblog template resources resolved within the active theme > * Front page selection moved into the administrator setup workflow > * Authoring UI event handlers moved to data attributes > > ### Web Services > * XML-RPC handlers check weblog permission per method > * Vendor extension types disabled on the XML-RPC servlet > * OAuth authorization bound to the current session and made one-shot > > ### Build and Packaging > * Source distribution now includes db-utils, which was missing from earlier > source releases and prevented them from building > * Third-party jars no longer shipped in the source distribution > * CHANGES.md added, and sign-release.sh takes the version as an argument > > Thank you for your time and contributions to the Apache Roller project. > > Best regards, > Dave Johnson >
