...
Release files must be signed with an OpenPGP compatible key. Follow If you do not already have a key for signing Apache releases, follow the developer instructions in the KEYS file in the Daffodil repository to generate a key and add it to the KEYS file. Follow the contributor workflow and create a review branch and pull request to commit your changes to the KEYS file. Once merged, the KEY file should also be copied to the release/inucbator/daffodil/KEYS
file in the apache-dist repo (see below). Your key fingerprint should also be added to https://id.apache.org.
For more information on creating a signing key, visit How to OpenPGP and Signing Releases.
SBT PGP
The sbt-pgp plugin is required to publish signed releases. Add the following to the file ~/.sbt/1.0/pgp.sbt
to enable usage of the plugin:
...
Staged files are created in the dev
directory and are moved to the release
directory once approved by the Incubator Project Management Committee.
Creating a Release Candidate
- Prior to creating the release candidate, the
version
setting inbuild.sbt
should contain the-SNAPSHOT
keyword. Create and merge a pull request to remove this keyword in preparation for a non-snapshot release. - Download the release-candidate.sh script, this script automates many of the tasks need needed to create a release candidate, including creating the release files, creating a git tag, and publishing to staging repositories.
- From within the root of the Daffodil directory, execute the release candidate script, providing the release candidate label (e.g. rc1), the path to the root of apache-dist directory created above, and your Apache login credentials. The credentials are used to publish the jars to a the Apache staging repo. You will also be asked to enter the password for your private gpg key created above to sign the published jars and the zip/tars . This script will perform the following actions:
- Create a zip of the source
- Create a tgz, zip, and rpm rpm
- Calculate sha1, sha256, sha512 checksums of the above files
- Create ASCII armored detached signatures of the above files
Updates the KEYS - Stages jars/poms to https://repository.apache.org
- Create a git tag
- Create a zip of the source
- Once the script completes, you should verify all the files. This includes verifying the checksums and signatures created in the Apache dist directories, verifying the stagged staged jars/poms at https://repository.apache.org/, and verify the git tag is correct.
- If anything does not look correct, delete the files in Apache dist, "drop" the published jars/poms, and delete the git tag.
- If anything does not look correct, delete the files in Apache dist, "drop" the published jars/poms, and delete the git tag.
- After verifying all is correct, commit the changes:
Commit the files in Apache dist, for example:
Code Block language bash svn add dev/incubator/daffodil/* svn ci -m "Stage Apache Daffodil (incubating) 2.0.0-rc1"
- Close the published Nexus files by visiting https://repository.apache.org, log in, find the release in "Staging Repositories" and select "Close".
Push the git tag
Code Block language bash git push --tag asf 2.0.0-rc1
...
Code Block |
---|
released: false
artifact-root: "https://dist.apache.org/repos/dist/dev/incubator/daffodil/2.0.0-rc1/"
checksum-root: "https://dist.apache.org/repos/dist/dev/incubator/daffodil/2.0.0-rc1/"
key-file: "https://dist.apache.org/repos/dist/dev/incubator/daffodil/KEYS" |
Follow the steps in the README in that repository to publish the new release page.
...
With the release files published for staging and a website createcreated, you may now start a vote on these files. To do so, send an email to dev@daffodil.apache.org with base on the following example, making sure to update all links and version numbers:
...
In the Apache dist directory, move the release candidate files to the release directory
Code Block language bash svn mv dev/incubator/daffodil/2.0.0-rc1/ release/incubator/daffodil/2.0.0/ svm ci -m "Release Apache Daffodil (incubating) 2.0.0"
In the Daffodil git repository, create a signed git tag based on the release candidate tag
Code Block language bash git tag -as -m "Release v2.0.0" rel/v2.0.0 v2.0.0-rc1 git push --tag asf rel/v2.0.0
- Release the published Nexus files by visiting https://repository.apache.org, log in, find the release in "Staging Repositories" and selecting "Release".
Modify the website release page to have the following parameters:
Code Block released: true artifact-root: "http://www.apache.org/dyn/closer.lua/incubator/daffodil/2.0.0/" checksum-root: "http://www.apache.org/dist/incubator/daffodil/2.0.0/" key-file: "http://www.apache.org/dist/incubator/daffodil/KEYS"
Give approximately 24 hours for the release files to sync to mirrors and maven central.
Send an announcement email to announce@apache.org, dev@daffodil.apache.org, and users@daffodil.apache.org, (note: send three separate emails instead of one email with multiple TO/CC's), with the following template:
Code Block language text Subject: [ANNOUNCE] Apache Daffodil (incubating) 2.0.0 The Apache Daffodil (incubating) community is pleased to announce the release of version 2.0.0. Release notes and downloads are available at: https://daffodil.apache.org/releases/2.0.0/ Daffodil is an open source implementation of the DFDL (Data Format Description Language) specification that uses DFDL schemas to parse fixed format data into an infoset, which is most commonly represented as either XML or JSON. This allows the use of well-established XML or JSON technologies and libraries to consume, inspect, and manipulate fixed format data in existing solutions. Daffodil is also capable of the reverse by serializing or "unparsing" an XML or JSON infoset back to the original data format. For more information about Daffodil visit: https://daffodil.apache.org/ Regards, The Apache Daffodil Team
...