Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  • current Fineract release process
    • we're shipping one release per quarter
    • takes weeks from heads-up email to ship/announce
  • proposed Fineract release goals from last Fineract community meeting
    • stable, reliable, frequent, well-documented
    • avoid vendor lock-in, leverage open source, release from any platform
    • reproducible? non-goal, for now
  • recent release process improvement thread
    • Adam M. clarified current voting process (especially artifact verification)
      • verify release candidate checksum/signature, build source, run binary
    • Adam M. shared vision on what an improved process might look like
      • "one-click release"
  • ideas
    • make it easy (and just as robust) for the next release manager
    • make it easy (and just as robust) to be a confident release voter
  • Oct 20, 2025 press release: Apache Trusted Releases platform begins second Alpha

ATR presentation from Sean

...

  • current Fineract release process: are we doing it right?
    • it seems heavyweight
    • Sean: yes, seems like the right steps (and ATR can help improve it)
  • fineract binary tarball is approaching 500MiB. Any issues with that?
    • Sean: shouldn't be a problem
    • others have bigger artifacts, up to 1GiB
    • can still get special dispensation beyond that
  • any issues while using ATR: contact Sean, use mailing lists, use github
  • if/when we have reproducible builds: Apache security teams will support auto-uploading elsewhere from github
    • get release key, revocation cert
    • could simplify artifact verification stage
  • JIRA hygiene
    • it can be complicated, but it shouldn't be!
    • James: looking for further improvement/simplification here
    • Adam: I think it's better/easier lately, Adam S. did the JIRA clean-up step quickly for 1.13.0
    • devs/PMs are keeping things up to date always, so there's not a huge pile of work right at release time
  • goal ideas:
    • no svn by February
    • build/upload rc directly from gh actions by March
  • artifact verification simplification
    • Terence verifies releases w/a virtual machine, all scripted, all terminal-based
    • some projects provide scripts to verify releases, e.g. log4net
  • being secure should be a reward
    • more secure, reward is easier too
  • we need to improve post-release packaging (Debian, Docker)
    • tabled for now

...