You are viewing a plain text version of this content. The canonical link for it is here.
Posted to users@subversion.apache.org by Daniel Shahaf <da...@apache.org> on 2017/07/06 10:39:10 UTC

[ANNOUNCE] Apache Subversion 1.9.6 released

I'm happy to announce the release of Apache Subversion 1.9.6.
Please choose the mirror closest to you by visiting:

    http://subversion.apache.org/download.cgi#recommended-release

This release fixes a bug where a repository would fail to store two files
having identical SHA-1 checksums [1].  Further information is available
in the 1.9.x series release notes [2] and in a new FAQ entry [3].

[1] http://shattered.io/
[2] https://subversion.apache.org/docs/release-notes/1.9#shattered-sha1
[3] https://subversion.apache.org/faq#shattered-sha1

The SHA1 checksums are:

    3375e697805fcdf6dc8c9b52f4e6626f70cabcd6 subversion-1.9.6.tar.bz2
    89e1b3f9d79422c094ccb95769360d5fe7df2bb1 subversion-1.9.6.tar.gz
    ba1a683297f176ef1a306dfeb894ede0236ef3b8 subversion-1.9.6.zip

SHA-512 checksums are available at:

    https://www.apache.org/dist/subversion/subversion-1.9.6.tar.bz2.sha512
    https://www.apache.org/dist/subversion/subversion-1.9.6.tar.gz.sha512
    https://www.apache.org/dist/subversion/subversion-1.9.6.zip.sha512

PGP Signatures are available at:

    http://www.apache.org/dist/subversion/subversion-1.9.6.tar.bz2.asc
    http://www.apache.org/dist/subversion/subversion-1.9.6.tar.gz.asc
    http://www.apache.org/dist/subversion/subversion-1.9.6.zip.asc

For this release, the following people have provided PGP signatures:

   Julian Foad [4096R/1FB064B84EECC493] with fingerprint:
    6011 63CF 9D49 9FD7 18CF  582D 1FB0 64B8 4EEC C493
   Philip Martin [2048R/76D788E1ED1A599C] with fingerprint:
    A844 790F B574 3606 EE95  9207 76D7 88E1 ED1A 599C
   Bert Huijben [4096R/C4A6C625CCC8E1DF] with fingerprint:
    3D1D C66D 6D2E 0B90 3952  8138 C4A6 C625 CCC8 E1DF
   Stefan Sperling [2048R/4F7DBAA99A59B973] with fingerprint:
    8BC4 DAE0 C5A4 D65F 4044  0107 4F7D BAA9 9A59 B973
   Stefan Fuhrmann [4096R/99EC741B57921ACC] with fingerprint:
    056F 8016 D9B8 7B1B DE41  7467 99EC 741B 5792 1ACC
   Stefan Hett (CODE SIGNING KEY) [4096R/376A3CFD110B1C95] with fingerprint:
    7B8C A7F6 451A D89C 8ADC  077B 376A 3CFD 110B 1C95
   Branko Čibej [4096R/1BCA6586A347943F] with fingerprint:
    BA3C 15B1 337C F0FB 222B  D41A 1BCA 6586 A347 943F
   Daniel Shahaf [3072R/A5FEEE3AC7937444] with fingerprint:
    E966 46BE 08C0 AF0A A0F9  0788 A5FE EE3A C793 7444
   Johan Corveleyn [4096R/B59CE6D6010C8AAD] with fingerprint:
    8AA2 C10E EAAD 44F9 6972  7AEA B59C E6D6 010C 8AAD

Release notes for the 1.9.x release series may be found at:

    http://subversion.apache.org/docs/release-notes/1.9.html

You can find the list of changes between 1.9.6 and earlier versions at:

    http://svn.apache.org/repos/asf/subversion/tags/1.9.6/CHANGES

Questions, comments, and bug reports to users@subversion.apache.org.

Thanks,
- The Subversion Team

Re: [ANNOUNCE] Apache Subversion 1.9.6 released

Posted by Daniel Shahaf <d....@daniel.shahaf.name>.
Daniel Shahaf wrote on Sat, 15 Jul 2017 21:16 +0000:
> Makes sense.  The attached patch updates the wording, however, requires
> a .py update that I haven't written yet.  dev@ folks, feel free to beat
> me to finishing the .py part.

Done in r1802130 and r1802132.

Cheers,

Daniel

Re: [ANNOUNCE] Apache Subversion 1.9.6 released

Posted by Daniel Shahaf <d....@daniel.shahaf.name>.
sebb wrote on Sat, 15 Jul 2017 21:44 +0100:
> On 6 July 2017 at 11:39, Daniel Shahaf <da...@apache.org> wrote:
> > I'm happy to announce the release of Apache Subversion 1.9.6.
> 
> What is the project about? Why should I be interested in it?
> [rhetorical questions]
> 
> Please can you add that information to future announce mails?

Makes sense.  The attached patch updates the wording, however, requires
a .py update that I haven't written yet.  dev@ folks, feel free to beat
me to finishing the .py part.

Cheers,

Daniel

[[[
release.py: Add details to email announcements.

* tools/dist/templates/rc-announce-ann.ezt,
* tools/dist/templates/stable-announce-ann.ezt:
    Say "This is a feature/security/bugfix release"
    and "Subversion is an open-source version control system" [quoted
    from our homepage] to make the announcements self-contained for
    readers of announce@apache.org and other aggregators.

* tools/dist/release.py
  (...): Pass two new parameters, 'security' and 'dot-zero', to the ezt
    templates.  ***NOT YET WRITTEN***

Suggested by: sebb
]]]

[[[
Index: tools/dist/templates/rc-release-ann.ezt
===================================================================
--- tools/dist/templates/rc-release-ann.ezt	(revision 1802030)
+++ tools/dist/templates/rc-release-ann.ezt	(working copy)
@@ -26,9 +26,10 @@ PGP Signatures are available at:
 For this release, the following people have provided PGP signatures:
 
 [siginfo]
-This is a pre-release for what will eventually become Apache Subversion
-[major-minor-patch].  It may contain known issues, a complete list of
-[major-minor-patch]-blocking issues can be found here:
+This is a pre-release for what will eventually become version [major-minor-patch] of the
+Apache Subversion open source version control system.  It may contain known
+issues, a complete list of [major-minor-patch]-blocking issues can be found
+here:
 
     http://subversion.tigris.org/issues/buglist.cgi?component=subversion&issue_status=NEW&issue_status=STARTED&issue_status=REOPENED&target_milestone=[major-minor-patch]
 
Index: tools/dist/templates/stable-release-ann.ezt
===================================================================
--- tools/dist/templates/stable-release-ann.ezt	(revision 1802030)
+++ tools/dist/templates/stable-release-ann.ezt	(working copy)
@@ -1,16 +1,28 @@
 From: ...@apache.org
 To: announce@subversion.apache.org, users@subversion.apache.org, dev@subversion.apache.org, announce@apache.org
-Subject: [[]ANNOUNCE] Apache Subversion [version] released
+[if-any security]Cc: security@apache.org
+[end][if-any security]Subject: [[]SECURITY][[]ANNOUNCE] Apache Subversion [version] released
+[else]Subject: [[]ANNOUNCE] Apache Subversion [version] released
+[end]
 
-From: ...@apache.org
-To: announce@subversion.apache.org, users@subversion.apache.org, dev@subversion.apache.org, announce@apache.org
-Cc: security@apache.org
-Subject: [[]SECURITY][[]ANNOUNCE] Apache Subversion [version] released
-
 I'm happy to announce the release of Apache Subversion [version].
 Please choose the mirror closest to you by visiting:
 
     http://subversion.apache.org/download.cgi#[anchor]
+[if-any dot-zero]
+
+This is a stable, feature release of the Apache Subversion open source
+version control system.
+[else]
+[if-any security]
+
+This is a stable bugfix and security release of the Apache Subversion
+open source version control system.
+[else]
+
+This is a stable bugfix release of the Apache Subversion open source
+version control system.
+[end]
 
 The SHA1 checksums are:
 
]]]

Re: [ANNOUNCE] Apache Subversion 1.9.6 released

Posted by sebb <se...@gmail.com>.
On 6 July 2017 at 11:39, Daniel Shahaf <da...@apache.org> wrote:
> I'm happy to announce the release of Apache Subversion 1.9.6.

What is the project about? Why should I be interested in it?
[rhetorical questions]

The Announce emails are sent to people not on the developer or user lists.
Most will have no idea what the project is about.

So the e-mails should contain at least brief details of what the
product does, and some info on why the new release might be of
interest to them.

Readers should not have to click the link to find out the basic information
(although of course it is useful to have such links for further detail).

Please can you add that information to future announce mails?

Thanks.


> Please choose the mirror closest to you by visiting:
>
>     http://subversion.apache.org/download.cgi#recommended-release
>
> This release fixes a bug where a repository would fail to store two files
> having identical SHA-1 checksums [1].  Further information is available
> in the 1.9.x series release notes [2] and in a new FAQ entry [3].
>
> [1] http://shattered.io/
> [2] https://subversion.apache.org/docs/release-notes/1.9#shattered-sha1
> [3] https://subversion.apache.org/faq#shattered-sha1
>
> The SHA1 checksums are:
>
>     3375e697805fcdf6dc8c9b52f4e6626f70cabcd6 subversion-1.9.6.tar.bz2
>     89e1b3f9d79422c094ccb95769360d5fe7df2bb1 subversion-1.9.6.tar.gz
>     ba1a683297f176ef1a306dfeb894ede0236ef3b8 subversion-1.9.6.zip
>
> SHA-512 checksums are available at:
>
>     https://www.apache.org/dist/subversion/subversion-1.9.6.tar.bz2.sha512
>     https://www.apache.org/dist/subversion/subversion-1.9.6.tar.gz.sha512
>     https://www.apache.org/dist/subversion/subversion-1.9.6.zip.sha512
>
> PGP Signatures are available at:
>
>     http://www.apache.org/dist/subversion/subversion-1.9.6.tar.bz2.asc
>     http://www.apache.org/dist/subversion/subversion-1.9.6.tar.gz.asc
>     http://www.apache.org/dist/subversion/subversion-1.9.6.zip.asc
>
> For this release, the following people have provided PGP signatures:
>
>    Julian Foad [4096R/1FB064B84EECC493] with fingerprint:
>     6011 63CF 9D49 9FD7 18CF  582D 1FB0 64B8 4EEC C493
>    Philip Martin [2048R/76D788E1ED1A599C] with fingerprint:
>     A844 790F B574 3606 EE95  9207 76D7 88E1 ED1A 599C
>    Bert Huijben [4096R/C4A6C625CCC8E1DF] with fingerprint:
>     3D1D C66D 6D2E 0B90 3952  8138 C4A6 C625 CCC8 E1DF
>    Stefan Sperling [2048R/4F7DBAA99A59B973] with fingerprint:
>     8BC4 DAE0 C5A4 D65F 4044  0107 4F7D BAA9 9A59 B973
>    Stefan Fuhrmann [4096R/99EC741B57921ACC] with fingerprint:
>     056F 8016 D9B8 7B1B DE41  7467 99EC 741B 5792 1ACC
>    Stefan Hett (CODE SIGNING KEY) [4096R/376A3CFD110B1C95] with fingerprint:
>     7B8C A7F6 451A D89C 8ADC  077B 376A 3CFD 110B 1C95
>    Branko Čibej [4096R/1BCA6586A347943F] with fingerprint:
>     BA3C 15B1 337C F0FB 222B  D41A 1BCA 6586 A347 943F
>    Daniel Shahaf [3072R/A5FEEE3AC7937444] with fingerprint:
>     E966 46BE 08C0 AF0A A0F9  0788 A5FE EE3A C793 7444
>    Johan Corveleyn [4096R/B59CE6D6010C8AAD] with fingerprint:
>     8AA2 C10E EAAD 44F9 6972  7AEA B59C E6D6 010C 8AAD
>
> Release notes for the 1.9.x release series may be found at:
>
>     http://subversion.apache.org/docs/release-notes/1.9.html
>
> You can find the list of changes between 1.9.6 and earlier versions at:
>
>     http://svn.apache.org/repos/asf/subversion/tags/1.9.6/CHANGES
>
> Questions, comments, and bug reports to users@subversion.apache.org.
>
> Thanks,
> - The Subversion Team

Re: [ANNOUNCE] Apache Subversion 1.9.6 released

Posted by Paul Hammant <pa...@hammant.org>.
Great work, all round :)

Re: [ANNOUNCE] Apache Subversion 1.9.6 released

Posted by Branko Čibej <br...@apache.org>.
On 06.07.2017 12:45, Paul Hammant wrote:
> Someone owns the consequential updates to Homebrew - right ?
>
> Ref: https://github.com/Homebrew/homebrew-core/blob/master/Formula/subversion.rb
>  - Pull-Requests are the usual model, but there's easily room for
> duplicated effort, here.

I usually prepared the Homebrew updates in advance and created the pull
request when the release was announced. This time I don't have anything
prepared, but can do this in a day or so.

-- Brane

Re: [ANNOUNCE] Apache Subversion 1.9.6 released

Posted by Paul Hammant <pa...@hammant.org>.
Someone owns the consequential updates to Homebrew - right ?

Ref:
https://github.com/Homebrew/homebrew-core/blob/master/Formula/subversion.rb
 - Pull-Requests are the usual model, but there's easily room for
duplicated effort, here.

- Paul