Hi Simon, > Yes I am happy if you can sign artifacts and make the upload.
Thanks! > Are they reproducible? Not as things stand. The jar and javadoc tooling both embed timestamps. Fixable, but I'd rather leave it out of scope for now and get 1.44 out. What I built: the Java code from the 1.44 tarball, unmodified, recompiled with Java 8 for compatibility. > Do you have any pending source-code changes to merge into git? None to the Java sources, as my current drive is to get an existing, already published artifact become available. Worth noting on the pom: it isn't used by the make build at all. configure just does a version substitution on it, and automake compiles via javac directly. However, Central requires a pom in the upload, so it has to go up regardless. I've removed some redundant declarations from it, and will point <scm> at https://codeberg.org/libidn/libidn instead of Savannah. > I suspect Java people aren't using *.JAR's from GNU tarballs, but get > things through Maven or other sites, though. That's exactly right, and the current situation isn't very good: Central has only 1.15 (2009) and 0.6.5 (2006): https://mvnrepository.com/artifact/org.gnu.inet/libidn People can route around it with private repositories (e.g. https://igniterealtime.org/archiva/repository/maven/org/gnu/inet/libidn/), which is unsigned and unofficial and not a real fix - and likely outdated too. Not having it in Central will effectively make it unavailable to most developers. Getting 1.44 onto Central should sort it. Regards, Guus On Sun, Jul 12, 2026 at 3:48 PM Simon Josefsson <[email protected]> wrote: > Guus der Kinderen <[email protected]> writes: > > > Hi Simon, > > > > I know it has only been ten years, but perhaps we should do another Maven > > release? :) > > Hi Guus! Sounds good! > > > I've finally sorted out the build problem that defeated me in 2016, and I > > now have a complete, signed set of artifacts for 1.44 ready to publish. I > > also still seem to have access to the org.gnu.inet namespace on Maven > > Central, and 1.44 isn't taken yet. > > > > One thing I'd like your OK on before I push the button: you signed the > > artifacts yourself last time round, and I'd be signing these with my own > > GPG key. You did offer to make me "Maven maintainer" back in 2016, so I > > suspect that's fine, but it's a permanent public statement of who > published > > it, so I'd rather ask than assume. > > Yes I am happy if you can sign artifacts and make the upload. Are they > reproducible? > > Do you have any pending source-code changes to merge into git? Feel > free to open pull requests on https://codeberg.org/libidn/libidn for > that. > > Btw, In 2022, I stopped including the pre-built *.JAR file in the Libidn > release archive because I wanted the *.tar.gz to be reproducible without > a heavy Java toolchain. I suspect Java people aren't using *.JAR's from > GNU tarballs, but get things through Maven or other sites, though. > > /Simon > > > Regards, > > > > Guus > > > > On Fri, Jul 22, 2016 at 11:53 AM Simon Josefsson <[email protected]> > > wrote: > > > >> > Hi, > >> > > >> > Found it, and was able to use them. Sadly, my earlier comment on > >> > being able to get away with not meeting requirements and only > >> > supplying the bare minimum of having a signed pom file, and a signed > >> > jar file does not hold true. We need more (and what we do have needs > >> > additional information). > >> > >> Bummer! > >> > >> > I'll try to restructure the Java project a little to meet to above > >> > needs (as well as address other issues I mentioned earlier). > >> > >> Great. You could pull out the Java Libidn source code into a separate > >> git repository with its own release schedule etc if this makes things > >> easier. If that works well, we could remove the current Java code and > >> have the other project supersede that part of the libidn-*.tar.gz > >> archive. This would probably make things easier anyway. > >> > >> > I just tried to subscribe to you over XMPP - that might be a better > >> > venue for discussion about some of the details than this mailinglist. > >> > If you would be so kind to accept my subscription request... :) > >> > >> I'm online now at [email protected] but didn't see any request. Try > >> again :-) > >> > >> /Simon > >> > >> > > >> > - Guus > >> > > >> > On 22 July 2016 at 11:24, Simon Josefsson <[email protected]> > wrote: > >> > > >> > > Hi Guus, > >> > > > >> > > Sorry, I thought they were uploaded for all releases. I now > >> > > uploaded signed JAR+POM for 1.33 manually. Check again! > >> > > > >> > > /Simon > >> > > > >> > > > Hi Simon, > >> > > > > >> > > > Where exactly on the FTP server are the signed JAR files? In > >> > > > http://ftp.gnu.org/gnu/libidn/ there are lots of signed archives, > >> > > > but no JAR files specifically (with the exception of version > >> > > > 1.28). The archives themselves do appear to contain the JAR file, > >> > > > but no JAR file signature. > >> > > > > >> > > > Regards, > >> > > > > >> > > > Guus > >> > > > > >> > > > > >> > > > On 20 July 2016 at 19:18, Simon Josefsson <[email protected]> > >> > > > wrote: > >> > > > > >> > > > > Guus der Kinderen <[email protected]> writes: > >> > > > > > >> > > > > > Hi Simon, > >> > > > > > > >> > > > > > What we appear to need are PGP-signed artifacts. I noticed > >> > > > > > that you > >> > > > > already > >> > > > > > published a key, so it's probably best to re-use that. > >> > > > > > > >> > > > > > I tried, but failed, to reproduce the Java build (I've just > >> > > > > > started a different thread on this mailing list on the > >> > > > > > subject). As libidn does not use Maven to do the actual > >> > > > > > building, getting the artifacts in the exact right format is > >> > > > > > a bit tricky. > >> > > > > > >> > > > > Hi Guus. Thanks for your work here. > >> > > > > > >> > > > > > Although more artifacts (javadocs, sources) are desired, I > >> > > > > > found an > >> > > > > obscure > >> > > > > > reference that hinted that we could get away with the bare > >> > > > > > minimum of having a signed pom file, and a signed jar file. > >> > > > > > Simon, could you sign > >> > > > > both > >> > > > > > files (from the .32 release) and make those available to me > >> > > > > > please? I'll see if I can make things work with just those. > >> > > > > > >> > > > > The signed JAR files are available via ftp.gnu.org. I'm > >> > > > > attaching a 1.32 *.pom file and its signature. Can you make > >> > > > > something work with this? > >> > > > > > >> > > > > Getting the build process up to speed would be good too... > >> > > > > > >> > > > > /Simon > >> > > > > > >> > > > > -----BEGIN PGP MESSAGE----- > >> > > > > Version: GnuPG v1 > >> > > > > > >> > > > > owG1V31sFEUU75XPO4tFDBDlI5NLBFLbnesHiM12iSkfkrZA5EsiQuZ2565D9nY3 > >> > > > > M7s9WjFqAiqaUBI/EiBA/AMTDUQxxkQMIWhVEJXwlwED0URFrf+IhhgM6Ozs7DHX > >> > > > > 3mHQSAK5efPem9/7ze+9WXZPGlMzMfHsHU990PLHXfsTZ4azNesH31mnL9pasEEf > >> > > > > poy4Tke6WcukAXZM1yJOviO9ds3SpoXpRUZK96i7BZs+4N4O60j3+r7XDmEB9WFH > >> > > > > Qx4ye7Hm0jxctbIHtmkZniUF4j8ipH0rI6WwYrGoFVtFQEsm0wwf7elezTMUUBNx > >> > > > > mI8cE6vhjLQzsdvtmsgXMP/xeFDNQxia+to2ZzZntK3MShv8JL3gWtheF5FgiAQ6 > >> > > > > LLOFTnnqBt5yy+BptLwTaMTBvg5ja+iBqE9yyPT50iZZYjk6VEyhh4MK2Fi2Yi1Y > >> > > > > vngF6CZZimi/DoU13Jb3YDRrrS06jFepcMvCzKTE8yUaAMIs3eIUQBhAIBfYdj+w > >> > > > > XDMoYMfHFiAFz8bhb0EacHPA78VgtU/51XoUe40izarA6efXjQFyrBDVQ4B52CQ5 > >> > > > > EnHNNHnIXAa8gHouw+FxvhupBIscYaiFRRbCj6aOCEU2GeAwLLeAiAPCGpkWVgLL > >> > > > > SgktXFwe5kRhFpUWq03LBsS2NOYG1MRLpCoNIUod3tInShPdvukWPGJjKn04ufN1 > >> > > > > WHmrYpiPaB77FcPkVuXTet3iekQdDocZPg3w6ENVj6o5FmN+WdFlVE+jOgmOVUpD > >> > > > > Q0BtQ+m+UL9hOzA35xcRxTDSK9Rh6CgiCG9DcUcbMKIG71OuyHKbcLOJiR1Wujm5 > >> > > > > NGT/3hR8N2YMU7AMO5gim8suy125toR7PIBAK29dlwIbcRXd7AuRqUoF8fmlH1qv > >> > > > > X7BlHTLUIoyrPhsIerjyXa5B1RRBhwr20kLSx8yC9DJdx+GyC8O4sT1PfPEXQv6v > >> > > > > xlAfchzUq6ALadX4ng6VyNTIiioGc2MRZ+Eir0NNIwvTocAU/uK+yCEDSEkd065y > >> > > > > WI1BJWV5pmjseNixeK+XmlM19scmYY5HIVemlnfdvI21cCZoOeJY2SDPyoZlKUqZ > >> > > > > kLx8N5pWbOTkLLnHQ7GFT+lmZUYqLszk2jd4B/QRC1shUeE6Bg9V9JUqSiqlbAkc > >> > > > > og75ZDlgua1CTSoY27RmFWKyhM3HzP9PuBSK8wHXTXWIcns0xJ/kU9M2gsj/B6XJ > >> > > > > XwMv7OlqOEsO1cjMaPObqPnvkSqG0lQUb0f85thBnn9+lOKj9U1hlb3/8osimsQy > >> > > > > soK81QKjL494ajdFQZVlXqq5tYLE+WyXyEYiTd4ezJNz45BRKFlAcY5QXBFlckQf > >> > > > > cgXdCqW6YtGYkbTLpz/H+VBojwzR7RJFF0TqQQYny4rn8cmkSkW8fZulxWF8VudI > >> > > > > PqByEiZFcv762YGFmVwLR2kzGhpgZ4S0QdsiOi7ekcFQjY45GnWMSlyynEkWlQ8V > >> > > > > zcqHPuJLWYTqLn0gGamdiZljaxITa8aPqw0/+WtSycnx/wP66yfcmHPy5V8/7un7 > >> > > > > rKfr6Qfs3demHqzbXnd3YdbPv5+euf3qL3T7/IZrueM986ZmrTE7zRsvdB/+qvHL > >> > > > > dW3s2OWL13flTn8/uWvwApl06gCobdw159zVcfV7ph06d/RDcG3Vyuz1L+7dqE1L > >> > > > > 7339/OwLJzbUTziauLP+240vvUaH2ve8+f7Yufd9Ojz87uPvzXumvuXs2fQM94cX > >> > > > > 17xV13wxv7Lx8F/onunHhwa++fzBJ47Nfv7S+NpZ5t6uoVfe3vDw+qHfDvy4bWni > >> > > > > /s4pHw08Nua506/uGIRfP7lpxZSBT1K5BUsu1564YpN9+pFtwaELb8zYNHiq7vyf > >> > > > > tDNx5cSCg50HwKUZq79beGT6zEf2o32p4R3nz/wN > >> > > > > =BG7g > >> > > > > -----END PGP MESSAGE----- > >> > > > > > >> > > > > > >> > > > >> > > > >> > >> >
