Maybe I'm missing something but it looks to me like there is some
inconsistency with the NOTICE and LICENSE going on - namely,

the NOTICE in the source release states that it:

 "includes software developed by the The Open Web Application Security
Project (https://www.owasp.org/)"

(but the source release doesn't actually include any) while the NOTICE of
the resulting binary (i.e., the jar file) _does not_ say that (but the
binary does actually include it).

Likewise, the LICENSE of the source release lists the relevant licenses and
copyrights which are actually included in the binary but the
META-INF/LICENSE of the binary doesn't.

It seems to me that at a minimum the NOTICE and LICENSE of the source
release should be used for the binary as well, no?

regards,

Karl

On Fri, Aug 12, 2016 at 10:23 AM, Bertrand Delacretaz <
[email protected]> wrote:
>
> Hi,
>
> The vote is still ongoing for V1.0.10 of the same module, but we
> should have waited for another small fix that's included in this
> release. No big deal.
>
> We solved 1 issue in this release:
> https://issues.apache.org/jira/browse/SLING/fixforversion/12338062
>
> Staging repository:
> https://repository.apache.org/content/repositories/orgapachesling-1500/
>
> You can use this UNIX script to download the release and verify the
signatures:
> http://svn.apache.org/repos/asf/sling/trunk/check_staged_release.sh
>
> Usage:
> sh check_staged_release.sh 1500 /tmp/sling-staging
>
> Please vote to approve this release:
>
>   [ ] +1 Approve the release
>   [ ]  0 Don't care
>   [ ] -1 Don't release, because ...
>
> This majority vote is open for at least 72 hours.
>
> Here's my +1.
>
> -Bertrand




--
Karl Pauls
[email protected]

Reply via email to