Re: Signing releases using automated release infra

2023-07-19 Thread Daniel Gruno
On 2023-07-19 11:45, tison wrote: Hi Daniel, Automating this process *requires* a reproducible build process that has been approved by the ASF security team It sseems the security team has limited bandwidth to process such a review request. I make the request to secur...@apache.org for

Re: Signing releases using automated release infra

2023-07-19 Thread tison
Hi Daniel, > Automating this process *requires* a > reproducible build process that has been approved by the ASF security > team It sseems the security team has limited bandwidth to process such a review request. I make the request to secur...@apache.org for OpenDAL (incubating) and the team

Re: Signing releases using automated release infra

2023-07-19 Thread Daniel Gruno
On 2023-07-19 11:21, Francis Chuang wrote: Is infra happy to explore the case where release artifacts are automatically uploaded via CI? The exploration is already ongoing. This would go a long way towards automating our release process as asking RMs to download the release artifacts from

Re: Signing releases using automated release infra

2023-07-19 Thread Francis Chuang
Is infra happy to explore the case where release artifacts are automatically uploaded via CI? This would go a long way towards automating our release process as asking RMs to download the release artifacts from GitHub and uploading them manually is a bit clunky. On 2023/07/18 19:55:00 Volkan

Signing releases using automated release infra

2023-07-18 Thread Volkan Yazıcı
Abstract: Signing release artifacts using an automated release infrastructure has been officially approved by LEGAL. This enables projects to sign artifacts using, say, GitHub Actions. I have been trying to overhaul the Log4j release process and make it as frictionless as possible since last