The ASF Tooling initiative has its Apache Trusted Releases (ATR) platform in beta. The project has two goals: to simplify the release manager's work and to enhance security so that projects and end-users alike can be confident that each release includes what it should and nothing more.
>From the user guide [1]: "The Apache Trusted Releases (*ATR*) provides a standard and easy way for a Project Management Committee (*PMC*) or incubating project (*PPMC*) to manage their releases in order to easily follow the Apache Way of governance." Apache Magpie has a runbook for ATR, which starts [2]: "The Apache Trusted Releases (ATR) backend for an Apache release: compose a signed release candidate in the ATR web platform, let ATR run the policy checks and drive the [VOTE], then *finish* the release so it is published to dist.apache.org and announced. The runbook has a chart labeled "The three ATR phases vs the 14-step lifecycle", summarizing how ATR automates steps 5-11 of the release process (the "mechanical middle"). No project is going to be forced to use the ATR platform, but I think it is worth looking at to see if it could help reduce the work and stress of our release efforts. If we suspect it could be useful, we could move to a formal vote to approve use of the ATR platform. 1: https://releases.apache.org/docs/user-guide 2: https://magpie.apache.org/docs/release-management/atr-release-runbook/ Andrew Wetmore Assistant VP, Marketing and Publicity, The ASF <https://apache.org> Editor-Writer, Infra team, The ASF
