[
https://issues.apache.org/jira/browse/THRIFT-5972?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18078245#comment-18078245
]
Dmytro Shteflyuk commented on THRIFT-5972:
------------------------------------------
Would it make sense to automate with something like
https://github.com/marketplace/actions/maven-publish-action ? It is not
currently in the approved list, but probably should not be too hard to do
that...
The risk is that it would require a GPG key added to GitHub release
environment, which was not done for Thrift releases before afaik.
> publish 0.23.0 to public Maven
> ------------------------------
>
> Key: THRIFT-5972
> URL: https://issues.apache.org/jira/browse/THRIFT-5972
> Project: Thrift
> Issue Type: Improvement
> Components: Java - Library
> Affects Versions: 0.23.0
> Reporter: Shh
> Priority: Major
>
> HI.
>
> 0.23.0 addresses a critical vulnerability.
> and is available as a download here:
>
> [Release Version 0.23.0 · apache/thrift ·
> GitHub|https://github.com/apache/thrift/releases/tag/v0.23.0]
>
> My company's build systems are tied to public maven central.
>
> and 0.23.0 is not avaiable here.
>
> [Maven Repository: org.apache.thrift »
> libthrift|https://mvnrepository.com/artifact/org.apache.thrift/libthrift]
> (currently only 0.22.0 and lower is available).
>
>
> I am kindly requesting that the library be "published" to maven-central.
>
> Note, the time gap on 0.22.0 seems to have been about one month.
>
> I appreciated the consideration.
>
> thank you.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)