sbp commented on issue #388:
URL: 
https://github.com/apache/tooling-trusted-releases/issues/388#issuecomment-3607583378

   Note that Airflow have an interesting approach to this: as I understand it, 
they build RC and non-RC tagged versions simultaneously, distribute the RC 
tagged versions to their participants for voting, but consider the vote to be 
held on the non-RC tagged versions which are then released. If there were a 
[diffoscope](https://diffoscope.org/) style proof of minimal (tag only) 
differences between the artifacts, we could include this in the attestations 
that ATR makes. This should be reflected in the official ASF release policy, 
because at present this practice, if I understood it, is outside of that policy.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to