Guus der Kinderen <[email protected]> writes: > Hi Simon, > > I know it has only been ten years, but perhaps we should do another Maven > release? :)
Hi Guus! Sounds good! > I've finally sorted out the build problem that defeated me in 2016, and I > now have a complete, signed set of artifacts for 1.44 ready to publish. I > also still seem to have access to the org.gnu.inet namespace on Maven > Central, and 1.44 isn't taken yet. > > One thing I'd like your OK on before I push the button: you signed the > artifacts yourself last time round, and I'd be signing these with my own > GPG key. You did offer to make me "Maven maintainer" back in 2016, so I > suspect that's fine, but it's a permanent public statement of who published > it, so I'd rather ask than assume. Yes I am happy if you can sign artifacts and make the upload. Are they reproducible? Do you have any pending source-code changes to merge into git? Feel free to open pull requests on https://codeberg.org/libidn/libidn for that. Btw, In 2022, I stopped including the pre-built *.JAR file in the Libidn release archive because I wanted the *.tar.gz to be reproducible without a heavy Java toolchain. I suspect Java people aren't using *.JAR's from GNU tarballs, but get things through Maven or other sites, though. /Simon > Regards, > > Guus > > On Fri, Jul 22, 2016 at 11:53 AM Simon Josefsson <[email protected]> > wrote: > >> > Hi, >> > >> > Found it, and was able to use them. Sadly, my earlier comment on >> > being able to get away with not meeting requirements and only >> > supplying the bare minimum of having a signed pom file, and a signed >> > jar file does not hold true. We need more (and what we do have needs >> > additional information). >> >> Bummer! >> >> > I'll try to restructure the Java project a little to meet to above >> > needs (as well as address other issues I mentioned earlier). >> >> Great. You could pull out the Java Libidn source code into a separate >> git repository with its own release schedule etc if this makes things >> easier. If that works well, we could remove the current Java code and >> have the other project supersede that part of the libidn-*.tar.gz >> archive. This would probably make things easier anyway. >> >> > I just tried to subscribe to you over XMPP - that might be a better >> > venue for discussion about some of the details than this mailinglist. >> > If you would be so kind to accept my subscription request... :) >> >> I'm online now at [email protected] but didn't see any request. Try >> again :-) >> >> /Simon >> >> > >> > - Guus >> > >> > On 22 July 2016 at 11:24, Simon Josefsson <[email protected]> wrote: >> > >> > > Hi Guus, >> > > >> > > Sorry, I thought they were uploaded for all releases. I now >> > > uploaded signed JAR+POM for 1.33 manually. Check again! >> > > >> > > /Simon >> > > >> > > > Hi Simon, >> > > > >> > > > Where exactly on the FTP server are the signed JAR files? In >> > > > http://ftp.gnu.org/gnu/libidn/ there are lots of signed archives, >> > > > but no JAR files specifically (with the exception of version >> > > > 1.28). The archives themselves do appear to contain the JAR file, >> > > > but no JAR file signature. >> > > > >> > > > Regards, >> > > > >> > > > Guus >> > > > >> > > > >> > > > On 20 July 2016 at 19:18, Simon Josefsson <[email protected]> >> > > > wrote: >> > > > >> > > > > Guus der Kinderen <[email protected]> writes: >> > > > > >> > > > > > Hi Simon, >> > > > > > >> > > > > > What we appear to need are PGP-signed artifacts. I noticed >> > > > > > that you >> > > > > already >> > > > > > published a key, so it's probably best to re-use that. >> > > > > > >> > > > > > I tried, but failed, to reproduce the Java build (I've just >> > > > > > started a different thread on this mailing list on the >> > > > > > subject). As libidn does not use Maven to do the actual >> > > > > > building, getting the artifacts in the exact right format is >> > > > > > a bit tricky. >> > > > > >> > > > > Hi Guus. Thanks for your work here. >> > > > > >> > > > > > Although more artifacts (javadocs, sources) are desired, I >> > > > > > found an >> > > > > obscure >> > > > > > reference that hinted that we could get away with the bare >> > > > > > minimum of having a signed pom file, and a signed jar file. >> > > > > > Simon, could you sign >> > > > > both >> > > > > > files (from the .32 release) and make those available to me >> > > > > > please? I'll see if I can make things work with just those. >> > > > > >> > > > > The signed JAR files are available via ftp.gnu.org. I'm >> > > > > attaching a 1.32 *.pom file and its signature. Can you make >> > > > > something work with this? >> > > > > >> > > > > Getting the build process up to speed would be good too... >> > > > > >> > > > > /Simon >> > > > > >> > > > > -----BEGIN PGP MESSAGE----- >> > > > > Version: GnuPG v1 >> > > > > >> > > > > owG1V31sFEUU75XPO4tFDBDlI5NLBFLbnesHiM12iSkfkrZA5EsiQuZ2565D9nY3 >> > > > > M7s9WjFqAiqaUBI/EiBA/AMTDUQxxkQMIWhVEJXwlwED0URFrf+IhhgM6Ozs7DHX >> > > > > 3mHQSAK5efPem9/7ze+9WXZPGlMzMfHsHU990PLHXfsTZ4azNesH31mnL9pasEEf >> > > > > poy4Tke6WcukAXZM1yJOviO9ds3SpoXpRUZK96i7BZs+4N4O60j3+r7XDmEB9WFH >> > > > > Qx4ye7Hm0jxctbIHtmkZniUF4j8ipH0rI6WwYrGoFVtFQEsm0wwf7elezTMUUBNx >> > > > > mI8cE6vhjLQzsdvtmsgXMP/xeFDNQxia+to2ZzZntK3MShv8JL3gWtheF5FgiAQ6 >> > > > > LLOFTnnqBt5yy+BptLwTaMTBvg5ja+iBqE9yyPT50iZZYjk6VEyhh4MK2Fi2Yi1Y >> > > > > vngF6CZZimi/DoU13Jb3YDRrrS06jFepcMvCzKTE8yUaAMIs3eIUQBhAIBfYdj+w >> > > > > XDMoYMfHFiAFz8bhb0EacHPA78VgtU/51XoUe40izarA6efXjQFyrBDVQ4B52CQ5 >> > > > > EnHNNHnIXAa8gHouw+FxvhupBIscYaiFRRbCj6aOCEU2GeAwLLeAiAPCGpkWVgLL >> > > > > SgktXFwe5kRhFpUWq03LBsS2NOYG1MRLpCoNIUod3tInShPdvukWPGJjKn04ufN1 >> > > > > WHmrYpiPaB77FcPkVuXTet3iekQdDocZPg3w6ENVj6o5FmN+WdFlVE+jOgmOVUpD >> > > > > Q0BtQ+m+UL9hOzA35xcRxTDSK9Rh6CgiCG9DcUcbMKIG71OuyHKbcLOJiR1Wujm5 >> > > > > NGT/3hR8N2YMU7AMO5gim8suy125toR7PIBAK29dlwIbcRXd7AuRqUoF8fmlH1qv >> > > > > X7BlHTLUIoyrPhsIerjyXa5B1RRBhwr20kLSx8yC9DJdx+GyC8O4sT1PfPEXQv6v >> > > > > xlAfchzUq6ALadX4ng6VyNTIiioGc2MRZ+Eir0NNIwvTocAU/uK+yCEDSEkd065y >> > > > > WI1BJWV5pmjseNixeK+XmlM19scmYY5HIVemlnfdvI21cCZoOeJY2SDPyoZlKUqZ >> > > > > kLx8N5pWbOTkLLnHQ7GFT+lmZUYqLszk2jd4B/QRC1shUeE6Bg9V9JUqSiqlbAkc >> > > > > og75ZDlgua1CTSoY27RmFWKyhM3HzP9PuBSK8wHXTXWIcns0xJ/kU9M2gsj/B6XJ >> > > > > XwMv7OlqOEsO1cjMaPObqPnvkSqG0lQUb0f85thBnn9+lOKj9U1hlb3/8osimsQy >> > > > > soK81QKjL494ajdFQZVlXqq5tYLE+WyXyEYiTd4ezJNz45BRKFlAcY5QXBFlckQf >> > > > > cgXdCqW6YtGYkbTLpz/H+VBojwzR7RJFF0TqQQYny4rn8cmkSkW8fZulxWF8VudI >> > > > > PqByEiZFcv762YGFmVwLR2kzGhpgZ4S0QdsiOi7ekcFQjY45GnWMSlyynEkWlQ8V >> > > > > zcqHPuJLWYTqLn0gGamdiZljaxITa8aPqw0/+WtSycnx/wP66yfcmHPy5V8/7un7 >> > > > > rKfr6Qfs3demHqzbXnd3YdbPv5+euf3qL3T7/IZrueM986ZmrTE7zRsvdB/+qvHL >> > > > > dW3s2OWL13flTn8/uWvwApl06gCobdw159zVcfV7ph06d/RDcG3Vyuz1L+7dqE1L >> > > > > 7339/OwLJzbUTziauLP+240vvUaH2ve8+f7Yufd9Ojz87uPvzXumvuXs2fQM94cX >> > > > > 17xV13wxv7Lx8F/onunHhwa++fzBJ47Nfv7S+NpZ5t6uoVfe3vDw+qHfDvy4bWni >> > > > > /s4pHw08Nua506/uGIRfP7lpxZSBT1K5BUsu1564YpN9+pFtwaELb8zYNHiq7vyf >> > > > > tDNx5cSCg50HwKUZq79beGT6zEf2o32p4R3nz/wN >> > > > > =BG7g >> > > > > -----END PGP MESSAGE----- >> > > > > >> > > > > >> > > >> > > >> >>
signature.asc
Description: PGP signature
