+1

sigs ok, content ok, smoketest worked.


notes for next release:

the one-time key could be also printed directly to System.out so that it
lands in the console logger and could be easily read from container logs
and/or console while testing.

notice file would need a date bump at some point ;)

-mbien

On 9/18/26 01:28, Dave wrote:
> Right o, here we go...
>
> Please review and vote on Apache Roller 6.1.6, candidate RC4.
>
> Source and convenience binary artifacts:
> https://dist.apache.org/repos/dist/dev/roller/roller-6.1/v6.1.6
>
> Source tag: roller-6.1.6-rc4
> https://github.com/apache/roller/tree/roller-6.1.6-rc4
>
> commit 47c5cf0bbfa00fe199bc743a7fb88df8e6b21d32
> KEYS: https://downloads.apache.org/roller/KEYS
>
> Signing fingerprint: 3687 8574 1958 DE96 98FF DF4E 8FEC 6F9C BA59 703C
>
> Release notes:
> https://github.com/apache/roller/blob/roller-6.1.6-rc4/CHANGES.md
>
> Changes since RC3:
> - Secure initial Roller setup with a one-time operator token (#189)
> - Normalize links in HTML subset formatting (#190)
> - Format LDAP comment form values consistently (#191)
> - Override bootstrap .table-striped row shading (#188)
> - Add roller-release and roller-security AI skills (#186)
>
> Reviewers may want to exercise the new initial-setup flow in particular:
> a first install now requires a one-time token printed to the server log,
> as does an upgrade that migrates the database schema.
>
> The vote will remain open until at least 2026-09-20 20:00 EDT,
> allowing at least 72 hours for review under the normal process.
>
> [ ] +1 Release this candidate
> [ ] +0 No opinion
> [ ] -1 Do not release, because [reason]
>
> Dave Johnson

Reply via email to