Re: [VOTE] Release Apache ShardingSphere (Incubating) 4.0.0 round 2

2020-01-05 Thread zhangli...@apache.org
Thank you for all participants, the vote had finished successfully, I will send a new email to statistics the vote result. -- Liang Zhang (John) Apache ShardingSphere & Dubbo Willem Jiang 于2020年1月6日周一 上午8:56写道: > +1 (binding) > > I checked > Download links are valid, git tag

Re: [VOTE] Release Apache ShardingSphere (Incubating) 4.0.0 round 2

2020-01-05 Thread Willem Jiang
+1 (binding) I checked Download links are valid, git tag is OK. The kits have incubating in the name. Checksums and PGP signatures are valid. DISCLAIMER is included. LICENSE and NOTICE files are good. No binary file in the source kit. I can build the kits from source kit. Willem Jiang Twitter:

Re: [VOTE] Release Apache ShardingSphere (Incubating) 4.0.0 round 2

2020-01-04 Thread guangyuan wang
Hi +1 approve. I have checked the following items: [+] Download links are valid. [+] Checksums and PGP signatures are valid. [+] DISCLAIMER is included. [+] Source code artifacts have correct names matching the current release. [+] LICENSE and NOTICE files are correct for each

Re: [VOTE] Release Apache ShardingSphere (Incubating) 4.0.0 round 2

2020-01-02 Thread Craig Russell
Hi, +1 (IPMC) can be carried over to general incubator release vote I checked: [x] incubating in names. [x] Download links are valid. [x] Checksums and PGP signatures are valid (I checked src) [x] DISCLAIMER is included. [x] Source code artifacts have correct names matching the current

Re: [VOTE] Release Apache ShardingSphere (Incubating) 4.0.0 round 2

2020-01-02 Thread Zhang Yonglun
+1 Checked: Download links are valid. PGP checked. DISCLAIMER is included. LICENSE and NOTICE files are correct for each ShardingSphere repo. All files have license headers if necessary. mvn install succeed. -- Zhang Yonglun Apache ShardingSphere Juan Pan 于2020年1月2日周四 下午6:44写道: > +1, it is

Re: [VOTE] Release Apache ShardingSphere (Incubating) 4.0.0 round 2

2020-01-02 Thread Juan Pan
+1, it is ok for me My check list, Download links are valid. Checksums and PGP signatures are valid. DISCLAIMER is included. LICENSE and NOTICE files are correct for each ShardingSphere repo. All files have license headers if necessary. Install source files successfully. Juan Pan (Trista)

Re: [VOTE] Release Apache ShardingSphere (Incubating) 4.0.0 round 2

2020-01-01 Thread Sheng Wu
Got it. +1 binding Checked 1. Incubating in names 2. Compiling pass. 3. GPG checked 4. sha512 exist 5. LICENSE and NOTICE exist. Good luck and glad to see the stable release will be available soon Sheng Wu 吴晟 Twitter, wusheng1108 zhangli...@apache.org 于2020年1月2日周四 下午12:38写道: > Sorry, I can

Re: [VOTE] Release Apache ShardingSphere (Incubating) 4.0.0 round 2

2020-01-01 Thread zhangli...@apache.org
Sorry, I can not find the old secret key, so we can not reuse the old public key for now. The only way is use the current key to check the gpg signature. Please reimport the `KEYS` file to validate the signature for now. It is unnecessary to re-release version. How about continue to vote on this

Re: [VOTE] Release Apache ShardingSphere (Incubating) 4.0.0 round 2

2020-01-01 Thread Juan Pan
Thanks for your explanation, Willem. Let me make it clear, my concern is that a public key ever signed for one release, and now this key is compromised, and although this key is in KEYS file, it could not work well. Therefore we could not use it for verify the integrity of old release in [1]

Re: [VOTE] Release Apache ShardingSphere (Incubating) 4.0.0 round 2

2020-01-01 Thread Willem Jiang
No, I don't think using the KEYS file can keep good track of the public key, it doesn't support the revoke operation. It's better to use the public Key server to host the public key and we can know if the key is revoked or not. Willem Jiang Twitter: willemjiang Weibo: 姜宁willem On Thu, Jan 2,

Re: [VOTE] Release Apache ShardingSphere (Incubating) 4.0.0 round 2

2020-01-01 Thread Juan Pan
That means once one key was used for one release, it could not be deleted from KEYS files anymore no matter it is great on or not, right? Juan Pan (Trista) Senior DBA & PPMC of Apache ShardingSphere(Incubating) E-mail: panj...@apache.org On 01/2/2020 12:00,Willem

Re: [VOTE] Release Apache ShardingSphere (Incubating) 4.0.0 round 2

2020-01-01 Thread zhangli...@apache.org
Sure, 2 same usernames will make the checker confuse. I prefer to re-release again for round 3 and just make sure one release manager only have a single gpg signature. -- Liang Zhang (John) Apache ShardingSphere & Dubbo Juan Pan 于2020年1月2日周四 上午11:12写道: > Very appreciated

Re: [VOTE] Release Apache ShardingSphere (Incubating) 4.0.0 round 2

2020-01-01 Thread Willem Jiang
If the private key is compromised[1] or if we cannot find the private key, we should revoke the public KEY[2]. Please keep your private key in a safe place. [1]https://www.thesslstore.com/blog/heres-what-happens-when-your-private-key-gets-compromised/

Re: [VOTE] Release Apache ShardingSphere (Incubating) 4.0.0 round 2

2020-01-01 Thread Juan Pan
Very appreciated Sheng, make sense. Juan Pan (Trista) Senior DBA & PPMC of Apache ShardingSphere(Incubating) E-mail: panj...@apache.org On 01/2/2020 11:09,Sheng Wu wrote: Yes, because the verification is introduced on the official website, download page, right? If

Re: [VOTE] Release Apache ShardingSphere (Incubating) 4.0.0 round 2

2020-01-01 Thread Sheng Wu
Yes, because the verification is introduced on the official website, download page, right? If we delete it, users will fail when we do the verification. Sheng Wu 吴晟 Twitter, wusheng1108 Juan Pan 于2020年1月2日周四 上午11:03写道: > Hi Sheng, > > > Thanks for your correction. > Just confirm, the key

Re: [VOTE] Release Apache ShardingSphere (Incubating) 4.0.0 round 2

2020-01-01 Thread Juan Pan
Hi Sheng, Thanks for your correction. Just confirm, the key point is that the old key for 4.0.0-RC1 release which passed the release vote but exists in our release list now could not be deleted, right? In other words, only one certain release exists, the key used for which must exist?

Re: [VOTE] Release Apache ShardingSphere (Incubating) 4.0.0 round 2

2020-01-01 Thread Sheng Wu
You can't simply delete the old one. Because ShardingSphere has existing release based on that KEY :) We could still continue in this way, but it should not be recommended if your old key is still available. Sheng Wu 吴晟 Twitter, wusheng1108 Juan Pan 于2020年1月2日周四 上午10:18写道: > Hi Liang, > > >

Re: [VOTE] Release Apache ShardingSphere (Incubating) 4.0.0 round 2

2020-01-01 Thread Juan Pan
Hi Liang, If you plan not to use the old one any more, deleting is is an alternative to avoid confusion. If so, it is necessary to delete it in KEYS file and public key servers, IMO. Juan Pan (Trista) Senior DBA & PPMC of Apache ShardingSphere(Incubating) E-mail:

Re: [VOTE] Release Apache ShardingSphere (Incubating) 4.0.0 round 2

2020-01-01 Thread zhangli...@apache.org
> A question, why you have two pgp keys in the KEYS file? I change a computer, the 1st one is for the 4.0.0-RC1, the 4th one is for this version. Do you think we could remove the 1st one? because I will never use that gpp key again, but do we need to keep it to make the 4.0.0-RC1 can be validate?

Re: [VOTE] Release Apache ShardingSphere (Incubating) 4.0.0 round 2

2020-01-01 Thread Sheng Wu
Hi Liang Zhang A question, why you have two pgp keys in the KEYS file? Sheng Wu 吴晟 Twitter, wusheng1108 zhangli...@apache.org 于2019年12月30日周一 下午9:44写道: > Hello ShardingSphere Community, > > This is a call for vote to release Apache ShardingSphere (Incubating) > version 4.0.0 > > Release

Re: [VOTE] Release Apache ShardingSphere (Incubating) 4.0.0 round 2

2019-12-31 Thread zhaojun
+1 I have checked: [OK] Download links are valid. [OK] Checksums and PGP signatures are valid. [OK] DISCLAIMER is included. [OK] Source code artifacts have correct names matching the current release. [OK] All files have license headers if necessary. [OK] No compiled archives bundled in source

Re:[VOTE] Release Apache ShardingSphere (Incubating) 4.0.0 round 2

2019-12-31 Thread Zonglei Dong
+1 The checklist: [ OK ] Download links are valid. [ OK ] Checksums and PGP signatures are valid. [ OK ] DISCLAIMER is included. [ OK ] Source code artifacts have correct names matching the current release. [ OK ] All files have license headers if necessary. [ OK ] No compiled archives bundled

Re:[VOTE] Release Apache ShardingSphere (Incubating) 4.0.0 round 2

2019-12-30 Thread sunbufu
+1 I have checked the following items. Checklist for reference: [v] Download links are valid. [v] Checksums and PGP signatures are valid. [v] DISCLAIMER is included. [v] Source code artifacts have correct names matching the current release. — Haisheng Sun (sunbufu) Apache

Re:[VOTE] Release Apache ShardingSphere (Incubating) 4.0.0 round 2

2019-12-30 Thread Sion Yang
+1 I checked the LICENSE, NOTICE, Checksums, PGP signatures and installing source code. No problem happened. -- Yi Yang(Sion) Apache ShardingSphere At 2019-12-30 21:43:37, "zhangli...@apache.org" wrote: >Hello ShardingSphere Community, > >This is a call for vote to release Apache