Re: [I] Make all client responses JSON by default (tooling-trusted-release)

2025-09-09 Thread via GitHub
sebbASF commented on issue #226: URL: https://github.com/apache/tooling-trusted-release/issues/226#issuecomment-3272378166 Maybe consider making the response type depend on the client Accept header: if it includes JSON, then return JSON. -- This is an automated message from the Apache Gi

Re: [I] Add an action for uploading distribution metadata after votes (tooling-trusted-release)

2025-09-09 Thread via GitHub
sbp closed issue #221: Add an action for uploading distribution metadata after votes URL: https://github.com/apache/tooling-trusted-release/issues/221 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to

[I] Make all client responses JSON by default (tooling-trusted-release)

2025-09-09 Thread via GitHub
sbp opened a new issue, #226: URL: https://github.com/apache/tooling-trusted-release/issues/226 Allow client responses to be JSON or human readable, as set in configuration, but use JSON by default. -- This is an automated message from the Apache Git Service. To respond to the message, pl

Re: [I] Adjustments for Alpha2 (tooling-trusted-release)

2025-09-09 Thread via GitHub
sbp commented on issue #224: URL: https://github.com/apache/tooling-trusted-release/issues/224#issuecomment-3271877781 Implemented parts 1 and 2 in 4555e568448a6905585d4111aba19f1f2d2832b4. All that remains is to modify the wording of the site warning message and link it to the new _About_

[I] Provide project lifecycle information as part of the release (tooling-trusted-release)

2025-09-07 Thread via GitHub
dave2wave opened a new issue, #222: URL: https://github.com/apache/tooling-trusted-release/issues/222 We should provide lifecycle information so that consumers have some idea of the lifecycle promises for a project and this major version. -- This is an automated message from the Apache Gi

[I] Speed up building the OCI container (tooling-trusted-release)

2025-09-06 Thread via GitHub
sbp opened a new issue, #225: URL: https://github.com/apache/tooling-trusted-release/issues/225 Building the OCI container is currently taking about 550 seconds on the Tooling VM, which makes it slow to test incremental changes. The container is not very complicated, and it hasn't always be

Re: [I] SBOMs and Attestations (tooling-trusted-release)

2025-09-06 Thread via GitHub
sbp commented on issue #87: URL: https://github.com/apache/tooling-trusted-release/issues/87#issuecomment-3259221382 1. Test license compliance to ASF standards in dependencies in binaries. 2. Missing metadata (a version of what has already been developed). 3. Do a vulnerability scan s

Re: [I] Speed up building the OCI container (tooling-trusted-release)

2025-09-05 Thread via GitHub
sbp commented on issue #225: URL: https://github.com/apache/tooling-trusted-release/issues/225#issuecomment-3259588105 Removing syft sped it up to 180 seconds. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL a

[I] Adjustments for Alpha2 (tooling-trusted-release)

2025-09-05 Thread via GitHub
dave2wave opened a new issue, #224: URL: https://github.com/apache/tooling-trusted-release/issues/224 There are adjustments for Alpha2: 1. Vote emails should go to the PMC's mailing lists. Announce emails continue to be redirected to the test mailing list. (Thinking about it) 2. Vo

[I] Backfill GitHub numeric IDs into LDAP (tooling-trusted-release)

2025-09-04 Thread via GitHub
sbp opened a new issue, #223: URL: https://github.com/apache/tooling-trusted-release/issues/223 Required for the Trusted Publishing implementation in the API. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL

Re: [I] Allow multiple release candidates for a release (tooling-trusted-release)

2025-09-03 Thread via GitHub
dave2wave commented on issue #171: URL: https://github.com/apache/tooling-trusted-release/issues/171#issuecomment-3243339270 @sbp Let's discuss this issue and see if we should make any UX changes, leave this as a continuing discussion, and/or ask as a question for Alpha 2 testers. -- Th

Re: [I] Add an action for uploading distribution metadata after votes (tooling-trusted-release)

2025-09-03 Thread via GitHub
sbp commented on issue #221: URL: https://github.com/apache/tooling-trusted-release/issues/221#issuecomment-3246163089 And we should add distribution recording to the draft candidate phase too. -- This is an automated message from the Apache Git Service. To respond to the message, please

Re: [I] Decide upon a platform name and hosts (tooling-trusted-release)

2025-09-03 Thread via GitHub
dave2wave commented on issue #220: URL: https://github.com/apache/tooling-trusted-release/issues/220#issuecomment-3243345985 Alpha2 continues on the current host and we can continue with `release-test.apache.org` or rename as `releases-test.apache.org` Beta1 will be built on a new ho

Re: [I] What is the best project metadata format (tooling-trusted-release)

2025-09-02 Thread via GitHub
dave2wave closed issue #140: What is the best project metadata format URL: https://github.com/apache/tooling-trusted-release/issues/140 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific co

Re: [I] Add an action for uploading distribution metadata after votes (tooling-trusted-release)

2025-09-02 Thread via GitHub
sbp commented on issue #221: URL: https://github.com/apache/tooling-trusted-release/issues/221#issuecomment-3246159249 We can do resolving, distribution recording, and announcements, each optionally. -- This is an automated message from the Apache Git Service. To respond to the message,

Re: [I] Add an action for uploading distribution metadata after votes (tooling-trusted-release)

2025-09-02 Thread via GitHub
sbp commented on issue #221: URL: https://github.com/apache/tooling-trusted-release/issues/221#issuecomment-3246154989 We can also implicitly resolve the vote if the vote can be resolved. -- This is an automated message from the Apache Git Service. To respond to the message, please log on

[I] Add an action for uploading distribution metadata after votes (tooling-trusted-release)

2025-09-02 Thread via GitHub
sbp opened a new issue, #221: URL: https://github.com/apache/tooling-trusted-release/issues/221 In the Tooling actions repository. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific com

Re: [I] Decide upon a platform name and hosts (tooling-trusted-release)

2025-08-22 Thread via GitHub
dave2wave commented on issue #220: URL: https://github.com/apache/tooling-trusted-release/issues/220#issuecomment-3214966497 I think the name we were thinking was final is **Apache Trusted Releases** which mean the repository should be `tooling-trusted-releases` -- This is an automated m

Re: [I] Automation via GitHub Actions (tooling-trusted-release)

2025-08-22 Thread via GitHub
sbp commented on issue #86: URL: https://github.com/apache/tooling-trusted-release/issues/86#issuecomment-3214715735 We decided to avoid adding core upload functionality to the ATR client at present, because the existing action manages to cover it in relatively few lines of shell. We will

Re: [I] Automation via GitHub Actions (tooling-trusted-release)

2025-08-22 Thread via GitHub
sbp commented on issue #86: URL: https://github.com/apache/tooling-trusted-release/issues/86#issuecomment-3214708196 We now have a separate repository of GitHub Actions, which includes an upload to ATR action: https://github.com/apache/tooling-actions I've also requested from

Re: [I] Obtain more information about permitting projects to upload from GitHub (tooling-trusted-release)

2025-08-22 Thread via GitHub
sbp commented on issue #217: URL: https://github.com/apache/tooling-trusted-release/issues/217#issuecomment-3214702251 Requested the definitive list from Infra: https://issues.apache.org/jira/browse/INFRA-27164 -- This is an automated message from the Apache Git Service. To respond

[I] Decide upon a platform name and hosts (tooling-trusted-release)

2025-08-22 Thread via GitHub
sbp opened a new issue, #220: URL: https://github.com/apache/tooling-trusted-release/issues/220 The platform is currently called **Apache Trusted Release**, but we have discussed calling it **Apache Trusted Releasing** to make it clear that we are adding trust to the process. We shou

Re: [I] Create a GitHub Action to make it easier to upload to the ATR (tooling-trusted-release)

2025-08-22 Thread via GitHub
sbp closed issue #218: Create a GitHub Action to make it easier to upload to the ATR URL: https://github.com/apache/tooling-trusted-release/issues/218 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to

Re: [I] Create a GitHub Action to make it easier to upload to the ATR (tooling-trusted-release)

2025-08-22 Thread via GitHub
sbp commented on issue #218: URL: https://github.com/apache/tooling-trusted-release/issues/218#issuecomment-3214669011 [Implemented](https://github.com/apache/tooling-actions/commit/bbbae990619d9296492e3c236a04616569e21761) in a new repository for GitHub Actions created by ASF Tooling:

[I] Create a GitHub Action to make it easier to upload to the ATR (tooling-trusted-release)

2025-08-21 Thread via GitHub
sbp opened a new issue, #218: URL: https://github.com/apache/tooling-trusted-release/issues/218 Uploading to the ATR requires [several steps](https://github.com/apache/tooling-trusted-release/issues/86#issuecomment-3211040275) in a GHA workflow. To make this easier on users, we could create

Re: [I] Potentially allow upload from GHAs during the finish phase (tooling-trusted-release)

2025-08-21 Thread via GitHub
sbp commented on issue #219: URL: https://github.com/apache/tooling-trusted-release/issues/219#issuecomment-3211915697 This can be potentially for attestations. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL

Re: [I] Potentially allow upload from GHAs during the finish phase (tooling-trusted-release)

2025-08-21 Thread via GitHub
sbp commented on issue #219: URL: https://github.com/apache/tooling-trusted-release/issues/219#issuecomment-3211921185 And a list of distribution channels. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL a

Re: [I] Obtain more information about permitting projects to upload from GitHub (tooling-trusted-release)

2025-08-21 Thread via GitHub
sbp commented on issue #217: URL: https://github.com/apache/tooling-trusted-release/issues/217#issuecomment-3211765398 Thank you very much. Using this information I was able to create a list of projects which are currently allowed to perform automated builds on GitHub. That list was added

Re: [I] Obtain more information about permitting projects to upload from GitHub (tooling-trusted-release)

2025-08-21 Thread via GitHub
sbp closed issue #217: Obtain more information about permitting projects to upload from GitHub URL: https://github.com/apache/tooling-trusted-release/issues/217 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL abov

Re: [I] Automation via GitHub Actions (tooling-trusted-release)

2025-08-21 Thread via GitHub
sbp commented on issue #86: URL: https://github.com/apache/tooling-trusted-release/issues/86#issuecomment-3211778363 Thanks to the information in #217 I was able to compile a list of projects which are allowed to perform automated builds on GitHub. I added that as a simple committee check,

Re: [I] Automation via GitHub Actions (tooling-trusted-release)

2025-08-21 Thread via GitHub
sbp commented on issue #86: URL: https://github.com/apache/tooling-trusted-release/issues/86#issuecomment-3211773761 > These steps must be delivered as an action. Will do. That's being tracked as #218 and work on the action is already proceeding. -- This is an automated messag

Re: [I] Potentially allow upload from GHAs during the finish phase (tooling-trusted-release)

2025-08-21 Thread via GitHub
dave2wave commented on issue #219: URL: https://github.com/apache/tooling-trusted-release/issues/219#issuecomment-3211566486 What would be uploaded during the finish stage? -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and

Re: [I] Automation via GitHub Actions (tooling-trusted-release)

2025-08-21 Thread via GitHub
dave2wave commented on issue #86: URL: https://github.com/apache/tooling-trusted-release/issues/86#issuecomment-3211555070 > These steps are a few dozen lines in the workflow, which isn't too bad, but writing our own GitHub Action might make it even more user friendly. These steps mu

Re: [I] Obtain more information about permitting projects to upload from GitHub (tooling-trusted-release)

2025-08-21 Thread via GitHub
raboof commented on issue #217: URL: https://github.com/apache/tooling-trusted-release/issues/217#issuecomment-3211351994 > Who set the criterion? Was it a Board decision, or a Security decision? It is a long-standing requirement in the ASF Release Policy (https://www.apache.org/lega

[I] Obtain more information about permitting projects to upload from GitHub (tooling-trusted-release)

2025-08-21 Thread via GitHub
sbp opened a new issue, #217: URL: https://github.com/apache/tooling-trusted-release/issues/217 ASF projects are only allowed to upload from GitHub when Security allows this. Security's criterion is that the project perform reproducible builds. Questions to answer: * Who set the crit

[I] Potentially allow upload from GHAs during the finish phase (tooling-trusted-release)

2025-08-21 Thread via GitHub
sbp opened a new issue, #219: URL: https://github.com/apache/tooling-trusted-release/issues/219 It's not at all clear what the policies surrounding this should be, but we should consider and discuss this. -- This is an automated message from the Apache Git Service. To respond to the messa

Re: [I] Automation via GitHub Actions (tooling-trusted-release)

2025-08-21 Thread via GitHub
sbp commented on issue #86: URL: https://github.com/apache/tooling-trusted-release/issues/86#issuecomment-3211040275 The way that this works currently in a GHA workflow is to: * Request an OIDC JWT from `ACTIONS_ID_TOKEN_REQUEST_URL` * Generate an SSH key pair * Send the GitHub

[I] Implement RAO / Maven connectivity (tooling-trusted-release)

2025-08-11 Thread via GitHub
dave2wave opened a new issue, #216: URL: https://github.com/apache/tooling-trusted-release/issues/216 (no comment) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubs

Re: [I] Automation via GitHub Actions (tooling-trusted-release)

2025-08-11 Thread via GitHub
dave2wave commented on issue #86: URL: https://github.com/apache/tooling-trusted-release/issues/86#issuecomment-3177119101 finish and compose actions can include distributions. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub

Re: [I] Add manual recording of packages released through external distribution channels (tooling-trusted-release)

2025-08-11 Thread via GitHub
sbp closed issue #215: Add manual recording of packages released through external distribution channels URL: https://github.com/apache/tooling-trusted-release/issues/215 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the

Re: [I] Add manual recording of packages released through external distribution channels (tooling-trusted-release)

2025-08-11 Thread via GitHub
sbp commented on issue #215: URL: https://github.com/apache/tooling-trusted-release/issues/215#issuecomment-3174875819 Resolved by 57346e0d582da2d6d6f9987b7d40426f5ed55f48, 3cd149d469e223e52ece70dde865f23761d96c71, 1a338e258f33f8371363e0d872f1577d485d0c86, 41525a3ed930d30298141fbc237ea304

[I] Add manual recording of packages released through external distribution channels (tooling-trusted-release)

2025-08-11 Thread via GitHub
sbp opened a new issue, #215: URL: https://github.com/apache/tooling-trusted-release/issues/215 As the first component of #88. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment

Re: [I] Bug use of PAT and JWT is not registered on the manage tokens page (tooling-trusted-release)

2025-08-05 Thread via GitHub
sbp closed issue #213: Bug use of PAT and JWT is not registered on the manage tokens page URL: https://github.com/apache/tooling-trusted-release/issues/213 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to

Re: [I] Bug use of PAT and JWT is not registered on the manage tokens page (tooling-trusted-release)

2025-08-05 Thread via GitHub
sbp commented on issue #213: URL: https://github.com/apache/tooling-trusted-release/issues/213#issuecomment-3156087598 Resolved by 9f1641a8cae8cf0205506334bcabba12987e00c5 ("_Track last time of use for PATs_"), and 661d81bb171129d19576036ca5ea2f020a8ce707 ("_Display the most recent JWT iss

[I] Add log sealing (tooling-trusted-release)

2025-08-05 Thread via GitHub
sbp opened a new issue, #214: URL: https://github.com/apache/tooling-trusted-release/issues/214 Ensure that audit logs are tamper resistant. Port QuickLog2 to user space, and record merkle tree roots in Rekor. -- This is an automated message from the Apache Git Service. To respond to the

[I] Bug use of PAT and JWT is not registered on the manage tokens page (tooling-trusted-release)

2025-08-01 Thread via GitHub
dave2wave opened a new issue, #213: URL: https://github.com/apache/tooling-trusted-release/issues/213 I created a PAT and saved it into the ATR client config. I then refreshed the JWT and created a draft release candidate. I went to the Manage Tokens page and do see any JWT tokens and

Re: [I] Use an external data source for committees without releases (tooling-trusted-release)

2025-08-01 Thread via GitHub
dave2wave commented on issue #148: URL: https://github.com/apache/tooling-trusted-release/issues/148#issuecomment-3145663610 We could move the STANDING_COMMITTEE list to https://github.com/apache/tooling-trusted-release/blob/main/atr/config.py#L39 and have it optionally be filled by a json

Re: [I] Hide upload keys on standing committee pages (tooling-trusted-release)

2025-08-01 Thread via GitHub
dave2wave closed issue #212: Hide upload keys on standing committee pages URL: https://github.com/apache/tooling-trusted-release/issues/212 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specifi

Re: [I] Hide upload keys on standing committee pages (tooling-trusted-release)

2025-08-01 Thread via GitHub
sbp commented on issue #212: URL: https://github.com/apache/tooling-trusted-release/issues/212#issuecomment-3145538974 Resolved by 7a7ff1c36eabd8001e1563056eb4d310ec9de97f. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and

Re: [I] Bug error when navigating to projects page (tooling-trusted-release)

2025-08-01 Thread via GitHub
sbp closed issue #211: Bug error when navigating to projects page URL: https://github.com/apache/tooling-trusted-release/issues/211 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific commen

Re: [I] Bug error when navigating to projects page (tooling-trusted-release)

2025-08-01 Thread via GitHub
sbp commented on issue #211: URL: https://github.com/apache/tooling-trusted-release/issues/211#issuecomment-3145532586 Resolved by 19dbfc797a0bd34cf21cf8ae5f853d5c545e4063. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and

Re: [I] Bug projects are duplicated on committee page (tooling-trusted-release)

2025-08-01 Thread via GitHub
sbp closed issue #210: Bug projects are duplicated on committee page URL: https://github.com/apache/tooling-trusted-release/issues/210 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific com

Re: [I] Bug projects are duplicated on committee page (tooling-trusted-release)

2025-08-01 Thread via GitHub
sbp commented on issue #210: URL: https://github.com/apache/tooling-trusted-release/issues/210#issuecomment-3145464151 Resolved by dc31310d43121701f90ffa44add96074e09205f5. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub

[I] Hide upload keys on standing committee pages (tooling-trusted-release)

2025-08-01 Thread via GitHub
dave2wave opened a new issue, #212: URL: https://github.com/apache/tooling-trusted-release/issues/212 I looked at the Logo Dev standing committee page and I am allowed to upload a KEYS file. Standing Committees do not have KEYS and this association should not even be seen. https://gi

[I] Bug error when navigating to projects page (tooling-trusted-release)

2025-08-01 Thread via GitHub
dave2wave opened a new issue, #211: URL: https://github.com/apache/tooling-trusted-release/issues/211 I navigate to one of my Pulsar projects and get the following error: ``` can only join an iterable An error occurred while processing your request. This has been logged and

[I] Bug projects are duplicated on committee page (tooling-trusted-release)

2025-08-01 Thread via GitHub
dave2wave opened a new issue, #210: URL: https://github.com/apache/tooling-trusted-release/issues/210 I'm looking at the OpenOffice page and I see the project twice: https://github.com/user-attachments/assets/3277e25e-96df-4874-8ab1-432f0f7f6a91"; /> -- This is an automated message

[I] Add tests suited to the alpha2 phase (tooling-trusted-release)

2025-08-01 Thread via GitHub
sbp opened a new issue, #209: URL: https://github.com/apache/tooling-trusted-release/issues/209 We have a range of basic e2e and API client tests, but we should ensure that some of the workflow procedures which will be most used in beta are exercised more exhaustively by some new tests.

[I] Add developer documentation (tooling-trusted-release)

2025-08-01 Thread via GitHub
sbp opened a new issue, #208: URL: https://github.com/apache/tooling-trusted-release/issues/208 We need some of the major, most commonly used, interfaces to be documented, for ourselves and for contributors. -- This is an automated message from the Apache Git Service. To respond to th

Re: [I] Policy page under Documentation (tooling-trusted-release)

2025-08-01 Thread via GitHub
sbp closed issue #206: Policy page under Documentation URL: https://github.com/apache/tooling-trusted-release/issues/206 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsu

Re: [I] Policy page under Documentation (tooling-trusted-release)

2025-08-01 Thread via GitHub
sbp commented on issue #206: URL: https://github.com/apache/tooling-trusted-release/issues/206#issuecomment-3145118615 Resolved by 9cd7780470cd8657801f5af3ccf1bc2d59705226. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and

Re: [I] Bug - error viewing a committees page (tooling-trusted-release)

2025-08-01 Thread via GitHub
sbp closed issue #205: Bug - error viewing a committees page URL: https://github.com/apache/tooling-trusted-release/issues/205 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. T

Re: [I] Bug - error viewing a committees page (tooling-trusted-release)

2025-08-01 Thread via GitHub
sbp commented on issue #205: URL: https://github.com/apache/tooling-trusted-release/issues/205#issuecomment-3145089122 Resolved by 01507f8152404a4af035044dc2f7545fccff075c. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and

Re: [I] Allow extra RAT excludes to be specified in the ATR interface (tooling-trusted-release)

2025-08-01 Thread via GitHub
sbp commented on issue #187: URL: https://github.com/apache/tooling-trusted-release/issues/187#issuecomment-3145073458 The new check result ignores introduced to resolve #199 ostensibly cover this feature request. In practice, however, they did not, because RAT member results are bundled i

Re: [I] Allow extra RAT excludes to be specified in the ATR interface (tooling-trusted-release)

2025-08-01 Thread via GitHub
sbp closed issue #187: Allow extra RAT excludes to be specified in the ATR interface URL: https://github.com/apache/tooling-trusted-release/issues/187 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to

Re: [I] Second round vote email fails to send (tooling-trusted-release)

2025-08-01 Thread via GitHub
sbp commented on issue #198: URL: https://github.com/apache/tooling-trusted-release/issues/198#issuecomment-3144796686 Resolved by c27820681313dfce75ab4193726477d12a1122d0. This was a simple typo: an instance of `user-tests` was misspelled as `user-test`. The commit ensures that all instan

Re: [I] Second round vote email fails to send (tooling-trusted-release)

2025-08-01 Thread via GitHub
sbp closed issue #198: Second round vote email fails to send URL: https://github.com/apache/tooling-trusted-release/issues/198 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. T

Re: [I] Add/activate openapi endpoints (tooling-trusted-release)

2025-08-01 Thread via GitHub
sbp commented on issue #207: URL: https://github.com/apache/tooling-trusted-release/issues/207#issuecomment-3144530744 These are provided, automatically, under the `api/` tree: https://release-test.apache.org/api/docs https://release-test.apache.org/api/openapi.json Commit 4

Re: [I] Add/activate openapi endpoints (tooling-trusted-release)

2025-08-01 Thread via GitHub
sbp closed issue #207: Add/activate openapi endpoints URL: https://github.com/apache/tooling-trusted-release/issues/207 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsub

[I] Add/activate openapi endpoints (tooling-trusted-release)

2025-07-31 Thread via GitHub
dave2wave opened a new issue, #207: URL: https://github.com/apache/tooling-trusted-release/issues/207 It would be helpful if standard openapi endpoints were available to help in discovery and testing. Quart should support the following two ... 1. /docs which will display the api test

[I] Policy page under Documentation (tooling-trusted-release)

2025-07-31 Thread via GitHub
dave2wave opened a new issue, #206: URL: https://github.com/apache/tooling-trusted-release/issues/206 We should provide curated links to ASF Release Policies. 1. Create a `policies.md` page. 2. Add a link to it in the left navigation under **Documentation** as "Policies" The

[I] Bug - error viewing a committees page (tooling-trusted-release)

2025-07-31 Thread via GitHub
dave2wave opened a new issue, #205: URL: https://github.com/apache/tooling-trusted-release/issues/205 When I click on the name of a committee on the committees page I get an error on rendering the page: ``` Parent instance is not bound to a Session; lazy load operation of attribu

Re: [I] Vote form should distinguish between binding votes and non-binding according to the user (tooling-trusted-release)

2025-07-31 Thread via GitHub
sbp closed issue #197: Vote form should distinguish between binding votes and non-binding according to the user URL: https://github.com/apache/tooling-trusted-release/issues/197 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and

Re: [I] Vote form should distinguish between binding votes and non-binding according to the user (tooling-trusted-release)

2025-07-31 Thread via GitHub
sbp commented on issue #197: URL: https://github.com/apache/tooling-trusted-release/issues/197#issuecomment-3141152406 Resolved by d4520430593473032b971215e71aa9551627ba3a. Attempts to work even in the case of PPMC members, by checking for IPMC membership instead in those cases:

Re: [I] License header exceptions allowed in checks (tooling-trusted-release)

2025-07-31 Thread via GitHub
sbp closed issue #199: License header exceptions allowed in checks URL: https://github.com/apache/tooling-trusted-release/issues/199 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comme

Re: [I] License header exceptions allowed in checks (tooling-trusted-release)

2025-07-31 Thread via GitHub
sbp commented on issue #199: URL: https://github.com/apache/tooling-trusted-release/issues/199#issuecomment-3141106308 We discussed having a general check result ignore mechanism. Such a mechanism would allow users to be able to ignore license header exceptions too, and would remove the ne

Re: [I] License header exceptions allowed in checks (tooling-trusted-release)

2025-07-29 Thread via GitHub
sbp commented on issue #199: URL: https://github.com/apache/tooling-trusted-release/issues/199#issuecomment-3133067669 For the RAT we have to extract the whole archive, and if the archive contains a `.ignore` file then we use it. For our own checks, we stream the archive. This means that w

Re: [I] License header exceptions allowed in checks (tooling-trusted-release)

2025-07-29 Thread via GitHub
sbp commented on issue #199: URL: https://github.com/apache/tooling-trusted-release/issues/199#issuecomment-3133028937 In 91060481163985aee42b13aefca3f80726324c85 we added a `.ignore` file for RAT checks, to resolve #153. We could use the same mechanism for our own license checks. We could

Re: [I] KEYS files don't apply to Attic, Comdev, Incubator etc (tooling-trusted-release)

2025-07-29 Thread via GitHub
sbp closed issue #134: KEYS files don't apply to Attic, Comdev, Incubator etc URL: https://github.com/apache/tooling-trusted-release/issues/134 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the spe

Re: [I] KEYS files don't apply to Attic, Comdev, Incubator etc (tooling-trusted-release)

2025-07-29 Thread via GitHub
sbp commented on issue #134: URL: https://github.com/apache/tooling-trusted-release/issues/134#issuecomment-3132975175 Resolved by a3c61c090cb2ca84f231b8449cb00c777f281ddd. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and

[I] Migrate remaining code to the storage interface (tooling-trusted-release)

2025-07-29 Thread via GitHub
sbp opened a new issue, #204: URL: https://github.com/apache/tooling-trusted-release/issues/204 Currently only keys code has been migrated to the storage interface. Migrate the remaining code for all database and filesystem writes. -- This is an automated message from the Apache Git S

Re: [I] API Documentation (tooling-trusted-release)

2025-07-29 Thread via GitHub
sbp commented on issue #143: URL: https://github.com/apache/tooling-trusted-release/issues/143#issuecomment-3132946126 Issue #203 tracks making the API stable. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL a

[I] Make the API stable, and document the fact (tooling-trusted-release)

2025-07-29 Thread via GitHub
sbp opened a new issue, #203: URL: https://github.com/apache/tooling-trusted-release/issues/203 Following up to #143. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To uns

Re: [I] Create an API for read-only data, and existing ATR workflows (tooling-trusted-release)

2025-07-29 Thread via GitHub
sbp closed issue #196: Create an API for read-only data, and existing ATR workflows URL: https://github.com/apache/tooling-trusted-release/issues/196 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to

Re: [I] Create an API for read-only data, and existing ATR workflows (tooling-trusted-release)

2025-07-29 Thread via GitHub
sbp commented on issue #196: URL: https://github.com/apache/tooling-trusted-release/issues/196#issuecomment-3132939501 Resolved by numerous commits, culminating in 386fe98b99fe1486acf41bd966b59ce1be3f3108. Compare also the resolutions to #145 and #143. -- This is an automated message fr

Re: [I] API Documentation (tooling-trusted-release)

2025-07-29 Thread via GitHub
sbp closed issue #143: API Documentation URL: https://github.com/apache/tooling-trusted-release/issues/143 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mai

Re: [I] API Documentation (tooling-trusted-release)

2025-07-29 Thread via GitHub
sbp commented on issue #143: URL: https://github.com/apache/tooling-trusted-release/issues/143#issuecomment-3132932950 As of 386fe98b99fe1486acf41bd966b59ce1be3f3108, we have [36 API endpoints, each with corresponding documentation](https://release-test.apache.org/api/docs). These API endp

Re: [I] Support a wide range of basic functionality in the API (tooling-trusted-release)

2025-07-29 Thread via GitHub
sbp closed issue #145: Support a wide range of basic functionality in the API URL: https://github.com/apache/tooling-trusted-release/issues/145 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the spe

Re: [I] Support a wide range of basic functionality in the API (tooling-trusted-release)

2025-07-29 Thread via GitHub
sbp commented on issue #145: URL: https://github.com/apache/tooling-trusted-release/issues/145#issuecomment-3132915694 This has been implemented across a large number of commits. As of 386fe98b99fe1486acf41bd966b59ce1be3f3108 we have the following endpoints, many of which are also used in

Re: [I] Missing `favicon.ico` warnings when running `pelican -l` (tooling-docs)

2025-07-28 Thread via GitHub
dave2wave commented on issue #44: URL: https://github.com/apache/tooling-docs/issues/44#issuecomment-3128423370 I moved the favicon.ico within the code. Browsers are not having trouble displaying it... -- This is an automated message from the Apache Git Service. To respond to the message,

Re: [I] Missing `favicon.ico` warnings when running `pelican -l` (tooling-docs)

2025-07-28 Thread via GitHub
dave2wave closed issue #44: Missing `favicon.ico` warnings when running `pelican -l` URL: https://github.com/apache/tooling-docs/issues/44 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specifi

Re: [I] KEYS files don't apply to Attic, Comdev, Incubator etc (tooling-trusted-release)

2025-07-28 Thread via GitHub
sbp commented on issue #134: URL: https://github.com/apache/tooling-trusted-release/issues/134#issuecomment-3127352717 This was partially resolved in a44adfcdb9c8d17cad48a7d0d5bf4adcebd39bec. The standing committee list still needs updating. -- This is an automated message from the Apach

Re: [PR] Expand the pre-commit config (tooling-trusted-release)

2025-07-28 Thread via GitHub
sbp commented on PR #202: URL: https://github.com/apache/tooling-trusted-release/pull/202#issuecomment-3127274516 Also, if you like, you can enable [**Allow edits by maintainers**](https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/working-with-forks/allowing-changes-

Re: [PR] Expand the pre-commit config (tooling-trusted-release)

2025-07-28 Thread via GitHub
sbp commented on PR #202: URL: https://github.com/apache/tooling-trusted-release/pull/202#issuecomment-3127264187 If you rebase onto f7e32bef208c6551341e759a926be54167910232, that might fix the check. -- This is an automated message from the Apache Git Service. To respond to the message,

Re: [PR] Clean up the Makefile and pre-commit config (tooling-docs)

2025-07-26 Thread via GitHub
dave2wave merged PR #45: URL: https://github.com/apache/tooling-docs/pull/45 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: dev-unsubscr...@tooling.apa

Re: [I] Missing `favicon.ico` warnings when running `pelican -l` (tooling-docs)

2025-07-26 Thread via GitHub
dave2wave commented on issue #44: URL: https://github.com/apache/tooling-docs/issues/44#issuecomment-3123056318 We should simply copy the favicon from Apache/www-site -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use th

[PR] Clean up the Makefile and pre-commit config (tooling-docs)

2025-07-26 Thread via GitHub
jbampton opened a new pull request, #45: URL: https://github.com/apache/tooling-docs/pull/45 (no comment) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-

[I] Missing `favicon.ico` warnings when running `pelican -l` (tooling-docs)

2025-07-26 Thread via GitHub
jbampton opened a new issue, #44: URL: https://github.com/apache/tooling-docs/issues/44 After running `pelican -l` I found some messages in my terminal. Screen shot below: https://github.com/user-attachments/assets/ac464aea-af5b-4bc0-9507-7cc5cf269405"; /> A quick googl

[PR] Expand the pre-commit config (tooling-trusted-release)

2025-07-26 Thread via GitHub
jbampton opened a new pull request, #202: URL: https://github.com/apache/tooling-trusted-release/pull/202 Creates a more complete config file -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the s

[I] We could add `zizmor` with `pre-commit`: static analysis for GitHub Actions (tooling-docs)

2025-07-26 Thread via GitHub
jbampton opened a new issue, #43: URL: https://github.com/apache/tooling-docs/issues/43 Good documentation and mainly in Rust zizmor seems great. refs #32 https://docs.zizmor.sh/ https://github.com/zizmorcore/zizmor https://github.com/zizmorcore/zizmor-pre-commit

Re: [I] How to Improve Package Verification (tooling-docs)

2025-07-25 Thread via GitHub
sbp commented on issue #5: URL: https://github.com/apache/tooling-docs/issues/5#issuecomment-3120132868 @dave2wave I've implemented a proof of concept of the envisaged command. An example of how the command works is attached below. Note the `--verbose` flag. Without it, the command o

  1   2   3   4   5   6   7   8   9   10   >