You are viewing a plain text version of this content. The canonical link for it is here.
Posted to general@incubator.apache.org by Jun Liu <li...@apache.org> on 2018/05/29 08:47:55 UTC

[VOTE]: Release Apache Dubbo (Incubating) 2.6.2 [RC2]

Hello All,

This is a call for vote to release Apache Dubbo (Incubating) version 2.6.2.

The Apache Dubbo community has voted on and approved a proposal to release Apache Dubbo (Incubating) version 2.6.2.

We now kindly request the Incubator PMC members review and vote on this incubator release.

Apache Dubbo™ (incubating) is a high-performance, java based, open source RPC framework. Dubbo offers three key functionalities, which include interface based remote call, fault tolerance & load balancing, and automatic service registration & discovery. 

Dubbo vote thread:
https://lists.apache.org/thread.html/38560cb159a5c32d0cf98485c9fe791505fbc52d18d86a37713582f0@%3Cdev.dubbo.apache.org%3E <https://lists.apache.org/thread.html/38560cb159a5c32d0cf98485c9fe791505fbc52d18d86a37713582f0@%3Cdev.dubbo.apache.org%3E>

Dubbo vote result thread:
https://lists.apache.org/thread.html/0b1e022a32e136ff0a9b42e7ef7da5ccc7d256d175394c2d5858f1cf@%3Cdev.dubbo.apache.org%3E <https://lists.apache.org/thread.html/0b1e022a32e136ff0a9b42e7ef7da5ccc7d256d175394c2d5858f1cf@%3Cdev.dubbo.apache.org%3E>

The release candidates:
https://dist.apache.org/repos/dist/dev/incubator/dubbo/2.6.2 <https://dist.apache.org/repos/dist/dev/incubator/dubbo/2.6.2>

Git tag for the release:
https://github.com/apache/incubator-dubbo/tree/dubbo-2.6.2 <https://github.com/apache/incubator-dubbo/tree/dubbo-2.6.2> 

Hash for the release tag:
5eeb240337ccfbc820d4bde023d8cf643f33d735

Release Notes:
https://github.com/apache/incubator-dubbo/blob/2.6.2-release/CHANGES.md <https://github.com/apache/incubator-dubbo/blob/2.6.2-release/CHANGES.md>

The artifacts have been signed with Key : 28681CB1, which can be found in the keys file:
https://dist.apache.org/repos/dist/dev/incubator/dubbo/KEYS <https://dist.apache.org/repos/dist/dev/incubator/dubbo/KEYS>

The vote will be open for at least 72 hours or until necessary number of votes are reached.

Please vote accordingly:
[ ] +1 approve 
[ ] +0 no opinion 
[ ] -1 disapprove with the reason

Thanks.
Jun Liu,
on behalf of The Apache Dubbo (Incubating) Team

Re: [VOTE]: Release Apache Dubbo (Incubating) 2.6.2 [RC2]

Posted by Justin Mclean <ju...@classsoftware.com>.
Hi,

> The license of guava is just boiler plate Apache License v2, I think
> there is no need to keep a local copy of it.
> Meanwhile, since the link points to a specific tag version, as long as
> guava does not re-tag it or Github is not down, it should remain
> unchanged. :)

Which I agree with and  that what I was trying to say, sorry for tech confusion.

Thanks,
Justin

Re: [VOTE]: Release Apache Dubbo (Incubating) 2.6.2 [RC2]

Posted by Huxing Zhang <hu...@apache.org>.
Hi,

On Sat, Jun 2, 2018 at 8:09 AM, Willem Jiang <wi...@gmail.com> wrote:
> Hi,
> Here are my +1(binding) for this vote.
>
> I checked the sign and signature they are OK.
> The License and Notice file are OK.
> The release kit has the incubating work
> I can build the binary from the source kit.
>
> Here are some minor issues that I found:
> 1. The release kit's name should start with Apache.
> 2. The License of guava is just link, it's better to keep local copy of it
> as the link could be broken or the License content could be changed.

The license of guava is just boiler plate Apache License v2, I think
there is no need to keep a local copy of it.
Meanwhile, since the link points to a specific tag version, as long as
guava does not re-tag it or Github is not down, it should remain
unchanged. :)

>
> @Jun
> As the most IPMC has a daily job, so we cannot always stand by for
> reviewing the kit.
> You may take advantage of sending the vote before the weekend and provide
> sophisticated verification in the internal vote thread to speed up the
> review process.
>
> BTW,There are some side projects of Apache Dubbo. Can I know if there are
> any release plan for these projects?
>
>
> Willem Jiang
>
> Twitter: willemjiang
> Weibo: 姜宁willem
>
> On Fri, Jun 1, 2018 at 10:41 AM, Jun Liu <li...@apache.org> wrote:
>
>> Hello,
>>
>> This vote has opened for nearly 72 hours, i am asking again for help to
>> check and vote on this release candidate.
>>
>> Best regards,
>> Jun
>>
>> > On 29 May 2018, at 4:47 PM, Jun Liu <li...@apache.org> wrote:
>> >
>> > Hello All,
>> >
>> > This is a call for vote to release Apache Dubbo (Incubating) version
>> 2.6.2.
>> >
>> > The Apache Dubbo community has voted on and approved a proposal to
>> release Apache Dubbo (Incubating) version 2.6.2.
>> >
>> > We now kindly request the Incubator PMC members review and vote on this
>> incubator release.
>> >
>> > Apache Dubbo™ (incubating) is a high-performance, java based, open
>> source RPC framework. Dubbo offers three key functionalities, which include
>> interface based remote call, fault tolerance & load balancing, and
>> automatic service registration & discovery.
>> >
>> > Dubbo vote thread:
>> > https://lists.apache.org/thread.html/38560cb159a5c32d0cf98485c9fe79
>> 1505fbc52d18d86a37713582f0@%3Cdev.dubbo.apache.org%3E <
>> https://lists.apache.org/thread.html/38560cb159a5c32d0cf98485c9fe79
>> 1505fbc52d18d86a37713582f0@%3Cdev.dubbo.apache.org%3E>
>> >
>> > Dubbo vote result thread:
>> > https://lists.apache.org/thread.html/0b1e022a32e136ff0a9b42e7ef7da5
>> ccc7d256d175394c2d5858f1cf@%3Cdev.dubbo.apache.org%3E <
>> https://lists.apache.org/thread.html/0b1e022a32e136ff0a9b42e7ef7da5
>> ccc7d256d175394c2d5858f1cf@%3Cdev.dubbo.apache.org%3E>
>> >
>> > The release candidates:
>> > https://dist.apache.org/repos/dist/dev/incubator/dubbo/2.6.2 <
>> https://dist.apache.org/repos/dist/dev/incubator/dubbo/2.6.2>
>> >
>> > Git tag for the release:
>> > https://github.com/apache/incubator-dubbo/tree/dubbo-2.6.2 <
>> https://github.com/apache/incubator-dubbo/tree/dubbo-2.6.2>
>> >
>> > Hash for the release tag:
>> > 5eeb240337ccfbc820d4bde023d8cf643f33d735
>> >
>> > Release Notes:
>> > https://github.com/apache/incubator-dubbo/blob/2.6.2-release/CHANGES.md
>> <https://github.com/apache/incubator-dubbo/blob/2.6.2-release/CHANGES.md>
>> >
>> > The artifacts have been signed with Key : 28681CB1, which can be found
>> in the keys file:
>> > https://dist.apache.org/repos/dist/dev/incubator/dubbo/KEYS <
>> https://dist.apache.org/repos/dist/dev/incubator/dubbo/KEYS>
>> >
>> > The vote will be open for at least 72 hours or until necessary number of
>> votes are reached.
>> >
>> > Please vote accordingly:
>> > [ ] +1 approve
>> > [ ] +0 no opinion
>> > [ ] -1 disapprove with the reason
>> >
>> > Thanks.
>> > Jun Liu,
>> > on behalf of The Apache Dubbo (Incubating) Team
>>
>>



-- 
Best Regards!
Huxing

---------------------------------------------------------------------
To unsubscribe, e-mail: general-unsubscribe@incubator.apache.org
For additional commands, e-mail: general-help@incubator.apache.org


Re: [VOTE]: Release Apache Dubbo (Incubating) 2.6.2 [RC2]

Posted by Huxing Zhang <hu...@apache.org>.
Hi,

On Sun, Jun 3, 2018 at 2:08 PM, Justin Mclean <ju...@classsoftware.com> wrote:
> Hi,
>
> +1 (binding). There is an security software export issue that needs looking into and probably acted on.
>
> I checked:
> - incubating in name
> - signatures and hashed all good
> - DISCLAIMER exists
> - LICENSE and NOTICE correct
> - No unexpected binary files
> - Source files have ASF headers (with a couple of exceptions)
> - Can compile from source
>
> Re including the full text of the guava license as it is boiler plate ALv2 there's no need to duplicate that in LICENSE. You may want to include as a text file but there’s no real need IMO.

The included text in LICENSE is not boiler plate ALv2 for guava(there
is just a link to the license), it is a modified version of Apache
license v1.1 for hessian-lite.

>
> On minor issue is that some of the pom files still have "Copyright 1999-2011 Alibaba Group.” in them this should be updated.
>
> I also just noticed that hessian lite (bundled in the source code) includes some encryption code. (See files X509Encryption.java and X509Signature.java.) It’s likely that the PPMC will need to go though this process [1] but I cannot say for sure as I don’t know US regulation on this well. What’s required is to register the software for export and add a warning that the code contains encryption software to the README. Note that instruction on that page may be out of date. Here’s the ASF export list for comparison. [2]
>
> I’m struct by a sense of irony that software that’s been mostly developed in China may need an US export license to be used in China when hosted for distribution at the ASF. :-)
>
> Thanks,
> Justin
>
> 1. http://www.apache.org/dev/crypto.html
> 2. http://www.apache.org/licenses/exports/
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: general-unsubscribe@incubator.apache.org
> For additional commands, e-mail: general-help@incubator.apache.org
>

-- 
Best Regards!
Huxing

---------------------------------------------------------------------
To unsubscribe, e-mail: general-unsubscribe@incubator.apache.org
For additional commands, e-mail: general-help@incubator.apache.org


Re: [VOTE]: Release Apache Dubbo (Incubating) 2.6.2 [RC2]

Posted by Justin Mclean <ju...@classsoftware.com>.
Hi,

> A preliminary investigation shows these two files is not used
> currently (a more careful check will be done later), it can be removed
> later. Moreover the overall hessian-lite module is supposed to be
> moved out of core repository as discussed on the mailing list.  

So looks like there nothing that needs to be done here.

Thanks,
Justin

Re: [VOTE]: Release Apache Dubbo (Incubating) 2.6.2 [RC2]

Posted by Huxing Zhang <hu...@apache.org>.
Hi,

On Sun, Jun 3, 2018 at 2:08 PM, Justin Mclean <ju...@classsoftware.com> wrote:
> Hi,
>
> +1 (binding). There is an security software export issue that needs looking into and probably acted on.
>
> I checked:
> - incubating in name
> - signatures and hashed all good
> - DISCLAIMER exists
> - LICENSE and NOTICE correct
> - No unexpected binary files
> - Source files have ASF headers (with a couple of exceptions)
> - Can compile from source
>
> Re including the full text of the guava license as it is boiler plate ALv2 there's no need to duplicate that in LICENSE. You may want to include as a text file but there’s no real need IMO.
>
> On minor issue is that some of the pom files still have "Copyright 1999-2011 Alibaba Group.” in them this should be updated.
>
> I also just noticed that hessian lite (bundled in the source code) includes some encryption code. (See files X509Encryption.java and X509Signature.java.) It’s likely that the PPMC will need to go though this process [1] but I cannot say for sure as I don’t know US regulation on this well. What’s required is to register the software for export and add a warning that the code contains encryption software to the README. Note that instruction on that page may be out of date. Here’s the ASF export list for comparison. [2]

A preliminary investigation shows these two files is not used
currently (a more careful check will be done later), it can be removed
later. Moreover the overall hessian-lite module is supposed to be
moved out of core repository as discussed on the mailing list.  [1]

>
> I’m struct by a sense of irony that software that’s been mostly developed in China may need an US export license to be used in China when hosted for distribution at the ASF. :-)
>
> Thanks,
> Justin
>
> 1. http://www.apache.org/dev/crypto.html
> 2. http://www.apache.org/licenses/exports/
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: general-unsubscribe@incubator.apache.org
> For additional commands, e-mail: general-help@incubator.apache.org
>

[1] https://lists.apache.org/thread.html/a5e5e1a09cb15b1d508cf22ce2bd674ddc915ffbfe16dda55dbc90ac@%3Cdev.dubbo.apache.org%3E

-- 
Best Regards!
Huxing

---------------------------------------------------------------------
To unsubscribe, e-mail: general-unsubscribe@incubator.apache.org
For additional commands, e-mail: general-help@incubator.apache.org


Re: [VOTE]: Release Apache Dubbo (Incubating) 2.6.2 [RC2]

Posted by Justin Mclean <ju...@classsoftware.com>.
Hi,

+1 (binding). There is an security software export issue that needs looking into and probably acted on.

I checked:
- incubating in name
- signatures and hashed all good
- DISCLAIMER exists
- LICENSE and NOTICE correct
- No unexpected binary files
- Source files have ASF headers (with a couple of exceptions)
- Can compile from source

Re including the full text of the guava license as it is boiler plate ALv2 there's no need to duplicate that in LICENSE. You may want to include as a text file but there’s no real need IMO.

On minor issue is that some of the pom files still have "Copyright 1999-2011 Alibaba Group.” in them this should be updated.

I also just noticed that hessian lite (bundled in the source code) includes some encryption code. (See files X509Encryption.java and X509Signature.java.) It’s likely that the PPMC will need to go though this process [1] but I cannot say for sure as I don’t know US regulation on this well. What’s required is to register the software for export and add a warning that the code contains encryption software to the README. Note that instruction on that page may be out of date. Here’s the ASF export list for comparison. [2]

I’m struct by a sense of irony that software that’s been mostly developed in China may need an US export license to be used in China when hosted for distribution at the ASF. :-)

Thanks,
Justin

1. http://www.apache.org/dev/crypto.html
2. http://www.apache.org/licenses/exports/
---------------------------------------------------------------------
To unsubscribe, e-mail: general-unsubscribe@incubator.apache.org
For additional commands, e-mail: general-help@incubator.apache.org


Re: [VOTE]: Release Apache Dubbo (Incubating) 2.6.2 [RC2]

Posted by Justin Mclean <ju...@classsoftware.com>.
Hi,

> As the most IPMC has a daily job, so we cannot always stand by for
> reviewing the kit.
> You may take advantage of sending the vote before the weekend and provide
> sophisticated verification in the internal vote thread to speed up the
> review process.

All of your mentors are IPMC members, you might want to remind them a vote is still open and get them to vote on the release. I’ll take a look and vote later today and/or tomorrow.

Thanks,
Justin
---------------------------------------------------------------------
To unsubscribe, e-mail: general-unsubscribe@incubator.apache.org
For additional commands, e-mail: general-help@incubator.apache.org


Re: [VOTE]: Release Apache Dubbo (Incubating) 2.6.2 [RC2]

Posted by Jun Liu <li...@apache.org>.
> As the most IPMC has a daily job, so we cannot always stand by for
> reviewing the kit.
> You may take advantage of sending the vote before the weekend and provide
> sophisticated verification in the internal vote thread to speed up the
> review process.

Thanks, we will provide a more detailed verification guide next time.

> BTW,There are some side projects of Apache Dubbo. Can I know if there are
> any release plan for these projects?

The side projects of Dubbo are registered under two organizations now: apache[1] and dubbo[2]. And they will all be released separately from the core Dubbo project.

For side projects under apache, there are two projects, incubator-dubbo-spring-boot-project[3] and incubator-dubbo-ops[4], that need a relatively regular release. We expect incubator-dubbo-spring-boot-project to start the release process soon after core.
For those under dubbo, which are mostly third-party extensions of Dubbo SPIs, will be evolved and released on demand.

1. https://github.com/apache
2. https://github.com/dubbo
3. https://github.com/apache/incubator-dubbo-spring-boot-project
4. https://github.com/apache/incubator-dubbo-ops

Best regards,
Jun

> On 2 Jun 2018, at 8:09 AM, Willem Jiang <wi...@gmail.com> wrote:
> 
> Hi,
> Here are my +1(binding) for this vote.
> 
> I checked the sign and signature they are OK.
> The License and Notice file are OK.
> The release kit has the incubating work
> I can build the binary from the source kit.
> 
> Here are some minor issues that I found:
> 1. The release kit's name should start with Apache.
> 2. The License of guava is just link, it's better to keep local copy of it
> as the link could be broken or the License content could be changed.
> 
> @Jun
> As the most IPMC has a daily job, so we cannot always stand by for
> reviewing the kit.
> You may take advantage of sending the vote before the weekend and provide
> sophisticated verification in the internal vote thread to speed up the
> review process.
> 
> BTW,There are some side projects of Apache Dubbo. Can I know if there are
> any release plan for these projects?
> 
> 
> Willem Jiang
> 
> Twitter: willemjiang
> Weibo: 姜宁willem
> 
> On Fri, Jun 1, 2018 at 10:41 AM, Jun Liu <li...@apache.org> wrote:
> 
>> Hello,
>> 
>> This vote has opened for nearly 72 hours, i am asking again for help to
>> check and vote on this release candidate.
>> 
>> Best regards,
>> Jun
>> 
>>> On 29 May 2018, at 4:47 PM, Jun Liu <li...@apache.org> wrote:
>>> 
>>> Hello All,
>>> 
>>> This is a call for vote to release Apache Dubbo (Incubating) version
>> 2.6.2.
>>> 
>>> The Apache Dubbo community has voted on and approved a proposal to
>> release Apache Dubbo (Incubating) version 2.6.2.
>>> 
>>> We now kindly request the Incubator PMC members review and vote on this
>> incubator release.
>>> 
>>> Apache Dubbo™ (incubating) is a high-performance, java based, open
>> source RPC framework. Dubbo offers three key functionalities, which include
>> interface based remote call, fault tolerance & load balancing, and
>> automatic service registration & discovery.
>>> 
>>> Dubbo vote thread:
>>> https://lists.apache.org/thread.html/38560cb159a5c32d0cf98485c9fe79
>> 1505fbc52d18d86a37713582f0@%3Cdev.dubbo.apache.org%3E <
>> https://lists.apache.org/thread.html/38560cb159a5c32d0cf98485c9fe79
>> 1505fbc52d18d86a37713582f0@%3Cdev.dubbo.apache.org%3E>
>>> 
>>> Dubbo vote result thread:
>>> https://lists.apache.org/thread.html/0b1e022a32e136ff0a9b42e7ef7da5
>> ccc7d256d175394c2d5858f1cf@%3Cdev.dubbo.apache.org%3E <
>> https://lists.apache.org/thread.html/0b1e022a32e136ff0a9b42e7ef7da5
>> ccc7d256d175394c2d5858f1cf@%3Cdev.dubbo.apache.org%3E>
>>> 
>>> The release candidates:
>>> https://dist.apache.org/repos/dist/dev/incubator/dubbo/2.6.2 <
>> https://dist.apache.org/repos/dist/dev/incubator/dubbo/2.6.2>
>>> 
>>> Git tag for the release:
>>> https://github.com/apache/incubator-dubbo/tree/dubbo-2.6.2 <
>> https://github.com/apache/incubator-dubbo/tree/dubbo-2.6.2>
>>> 
>>> Hash for the release tag:
>>> 5eeb240337ccfbc820d4bde023d8cf643f33d735
>>> 
>>> Release Notes:
>>> https://github.com/apache/incubator-dubbo/blob/2.6.2-release/CHANGES.md
>> <https://github.com/apache/incubator-dubbo/blob/2.6.2-release/CHANGES.md>
>>> 
>>> The artifacts have been signed with Key : 28681CB1, which can be found
>> in the keys file:
>>> https://dist.apache.org/repos/dist/dev/incubator/dubbo/KEYS <
>> https://dist.apache.org/repos/dist/dev/incubator/dubbo/KEYS>
>>> 
>>> The vote will be open for at least 72 hours or until necessary number of
>> votes are reached.
>>> 
>>> Please vote accordingly:
>>> [ ] +1 approve
>>> [ ] +0 no opinion
>>> [ ] -1 disapprove with the reason
>>> 
>>> Thanks.
>>> Jun Liu,
>>> on behalf of The Apache Dubbo (Incubating) Team
>> 
>> 


Re: [VOTE]: Release Apache Dubbo (Incubating) 2.6.2 [RC2]

Posted by Willem Jiang <wi...@gmail.com>.
Hi,
Here are my +1(binding) for this vote.

I checked the sign and signature they are OK.
The License and Notice file are OK.
The release kit has the incubating work
I can build the binary from the source kit.

Here are some minor issues that I found:
1. The release kit's name should start with Apache.
2. The License of guava is just link, it's better to keep local copy of it
as the link could be broken or the License content could be changed.

@Jun
As the most IPMC has a daily job, so we cannot always stand by for
reviewing the kit.
You may take advantage of sending the vote before the weekend and provide
sophisticated verification in the internal vote thread to speed up the
review process.

BTW,There are some side projects of Apache Dubbo. Can I know if there are
any release plan for these projects?


Willem Jiang

Twitter: willemjiang
Weibo: 姜宁willem

On Fri, Jun 1, 2018 at 10:41 AM, Jun Liu <li...@apache.org> wrote:

> Hello,
>
> This vote has opened for nearly 72 hours, i am asking again for help to
> check and vote on this release candidate.
>
> Best regards,
> Jun
>
> > On 29 May 2018, at 4:47 PM, Jun Liu <li...@apache.org> wrote:
> >
> > Hello All,
> >
> > This is a call for vote to release Apache Dubbo (Incubating) version
> 2.6.2.
> >
> > The Apache Dubbo community has voted on and approved a proposal to
> release Apache Dubbo (Incubating) version 2.6.2.
> >
> > We now kindly request the Incubator PMC members review and vote on this
> incubator release.
> >
> > Apache Dubbo™ (incubating) is a high-performance, java based, open
> source RPC framework. Dubbo offers three key functionalities, which include
> interface based remote call, fault tolerance & load balancing, and
> automatic service registration & discovery.
> >
> > Dubbo vote thread:
> > https://lists.apache.org/thread.html/38560cb159a5c32d0cf98485c9fe79
> 1505fbc52d18d86a37713582f0@%3Cdev.dubbo.apache.org%3E <
> https://lists.apache.org/thread.html/38560cb159a5c32d0cf98485c9fe79
> 1505fbc52d18d86a37713582f0@%3Cdev.dubbo.apache.org%3E>
> >
> > Dubbo vote result thread:
> > https://lists.apache.org/thread.html/0b1e022a32e136ff0a9b42e7ef7da5
> ccc7d256d175394c2d5858f1cf@%3Cdev.dubbo.apache.org%3E <
> https://lists.apache.org/thread.html/0b1e022a32e136ff0a9b42e7ef7da5
> ccc7d256d175394c2d5858f1cf@%3Cdev.dubbo.apache.org%3E>
> >
> > The release candidates:
> > https://dist.apache.org/repos/dist/dev/incubator/dubbo/2.6.2 <
> https://dist.apache.org/repos/dist/dev/incubator/dubbo/2.6.2>
> >
> > Git tag for the release:
> > https://github.com/apache/incubator-dubbo/tree/dubbo-2.6.2 <
> https://github.com/apache/incubator-dubbo/tree/dubbo-2.6.2>
> >
> > Hash for the release tag:
> > 5eeb240337ccfbc820d4bde023d8cf643f33d735
> >
> > Release Notes:
> > https://github.com/apache/incubator-dubbo/blob/2.6.2-release/CHANGES.md
> <https://github.com/apache/incubator-dubbo/blob/2.6.2-release/CHANGES.md>
> >
> > The artifacts have been signed with Key : 28681CB1, which can be found
> in the keys file:
> > https://dist.apache.org/repos/dist/dev/incubator/dubbo/KEYS <
> https://dist.apache.org/repos/dist/dev/incubator/dubbo/KEYS>
> >
> > The vote will be open for at least 72 hours or until necessary number of
> votes are reached.
> >
> > Please vote accordingly:
> > [ ] +1 approve
> > [ ] +0 no opinion
> > [ ] -1 disapprove with the reason
> >
> > Thanks.
> > Jun Liu,
> > on behalf of The Apache Dubbo (Incubating) Team
>
>

Re: [VOTE]: Release Apache Dubbo (Incubating) 2.6.2 [RC2]

Posted by Jun Liu <li...@apache.org>.
Hello,

This vote has opened for nearly 72 hours, i am asking again for help to check and vote on this release candidate.

Best regards,
Jun

> On 29 May 2018, at 4:47 PM, Jun Liu <li...@apache.org> wrote:
> 
> Hello All,
> 
> This is a call for vote to release Apache Dubbo (Incubating) version 2.6.2.
> 
> The Apache Dubbo community has voted on and approved a proposal to release Apache Dubbo (Incubating) version 2.6.2.
> 
> We now kindly request the Incubator PMC members review and vote on this incubator release.
> 
> Apache Dubbo™ (incubating) is a high-performance, java based, open source RPC framework. Dubbo offers three key functionalities, which include interface based remote call, fault tolerance & load balancing, and automatic service registration & discovery. 
> 
> Dubbo vote thread:
> https://lists.apache.org/thread.html/38560cb159a5c32d0cf98485c9fe791505fbc52d18d86a37713582f0@%3Cdev.dubbo.apache.org%3E <https://lists.apache.org/thread.html/38560cb159a5c32d0cf98485c9fe791505fbc52d18d86a37713582f0@%3Cdev.dubbo.apache.org%3E>
> 
> Dubbo vote result thread:
> https://lists.apache.org/thread.html/0b1e022a32e136ff0a9b42e7ef7da5ccc7d256d175394c2d5858f1cf@%3Cdev.dubbo.apache.org%3E <https://lists.apache.org/thread.html/0b1e022a32e136ff0a9b42e7ef7da5ccc7d256d175394c2d5858f1cf@%3Cdev.dubbo.apache.org%3E>
> 
> The release candidates:
> https://dist.apache.org/repos/dist/dev/incubator/dubbo/2.6.2 <https://dist.apache.org/repos/dist/dev/incubator/dubbo/2.6.2>
> 
> Git tag for the release:
> https://github.com/apache/incubator-dubbo/tree/dubbo-2.6.2 <https://github.com/apache/incubator-dubbo/tree/dubbo-2.6.2> 
> 
> Hash for the release tag:
> 5eeb240337ccfbc820d4bde023d8cf643f33d735
> 
> Release Notes:
> https://github.com/apache/incubator-dubbo/blob/2.6.2-release/CHANGES.md <https://github.com/apache/incubator-dubbo/blob/2.6.2-release/CHANGES.md>
> 
> The artifacts have been signed with Key : 28681CB1, which can be found in the keys file:
> https://dist.apache.org/repos/dist/dev/incubator/dubbo/KEYS <https://dist.apache.org/repos/dist/dev/incubator/dubbo/KEYS>
> 
> The vote will be open for at least 72 hours or until necessary number of votes are reached.
> 
> Please vote accordingly:
> [ ] +1 approve 
> [ ] +0 no opinion 
> [ ] -1 disapprove with the reason
> 
> Thanks.
> Jun Liu,
> on behalf of The Apache Dubbo (Incubating) Team


Re: [VOTE]: Release Apache Dubbo (Incubating) 2.6.2 [RC2]

Posted by Jun Liu <li...@apache.org>.
> I strongly recommend that you include the full fingerprint of the
> signing KEY in the KEYS file as well as the key ID. See [1] for an
> example where some of the keys have this. A few years ago an attack was
> demonstrated ([2], [3]) that show it was possible to create collisions
> in the key ID. Using the full fingerprint mitigates this attack.

The KEYS file I have updated with the full fingerprint added.

> No concerns with the file name used. Just a comment that the usual
> naming convention would be:
> apache-dubbo-incubating-2.6.2-src.zip

Will follow the naming convention for the next release.

> I'd suggest including the .gitignore file in the src release.

Will also add in the next release.

> I was a little surprised that the binary bundle was just the JARs rather
> than something that a user could unpack and run via dubbo.sh /
> dubbo.bat. There isn't anything wring with this, just not what I am used to.

Sure it would better be a packet for users to start Dubbo journey quickly, for example, packed samples or quick start guides which can be started by a start.sh. We are preparing for these samples and plan to replace current binary release in the next release.

Best regards,
Jun

> On 4 Jun 2018, at 4:05 PM, Mark Thomas <ma...@apache.org> wrote:
> 
> Checks:
> 
> Source bundle:
> - Hash and signature are correct
> - Hash of tag matches the hash quoted in the release vote mail
> - Contents of git tag match src bundle except for .gitignore file
> - Maven build passes
> - LICENSE and NOTICE look correct for source bundle
> - LICENSE and NOTICE look correct for binary bundle
> 
> +1 to release
> 
> 
> 
> I have the following minor review comments (none of which warrant
> another RC):
> 
> I strongly recommend that you include the full fingerprint of the
> signing KEY in the KEYS file as well as the key ID. See [1] for an
> example where some of the keys have this. A few years ago an attack was
> demonstrated ([2], [3]) that show it was possible to create collisions
> in the key ID. Using the full fingerprint mitigates this attack.
> 
> No concerns with the file name used. Just a comment that the usual
> naming convention would be:
> apache-dubbo-incubating-2.6.2-src.zip
> 
> I'd suggest including the .gitignore file in the src release.
> 
> I was a little surprised that the binary bundle was just the JARs rather
> than something that a user could unpack and run via dubbo.sh /
> dubbo.bat. There isn't anything wring with this, just not what I am used to.
> 
> Mark
> 
> 
> [1] https://dist.apache.org/repos/dist/release/tomcat/tomcat-9/KEYS
> [2] http://pgp.mit.edu/pks/lookup?op=get&search=0x10C01C5A2F6059E7
> [3] http://pgp.mit.edu/pks/lookup?op=get&search=0xB6FB7A022F6059E7
> 
> On 29/05/18 09:47, Jun Liu wrote:
>> Hello All,
>> 
>> This is a call for vote to release Apache Dubbo (Incubating) version 2.6.2.
>> 
>> The Apache Dubbo community has voted on and approved a proposal to release Apache Dubbo (Incubating) version 2.6.2.
>> 
>> We now kindly request the Incubator PMC members review and vote on this incubator release.
>> 
>> Apache Dubbo™ (incubating) is a high-performance, java based, open source RPC framework. Dubbo offers three key functionalities, which include interface based remote call, fault tolerance & load balancing, and automatic service registration & discovery. 
>> 
>> Dubbo vote thread:
>> https://lists.apache.org/thread.html/38560cb159a5c32d0cf98485c9fe791505fbc52d18d86a37713582f0@%3Cdev.dubbo.apache.org%3E <https://lists.apache.org/thread.html/38560cb159a5c32d0cf98485c9fe791505fbc52d18d86a37713582f0@%3Cdev.dubbo.apache.org%3E>
>> 
>> Dubbo vote result thread:
>> https://lists.apache.org/thread.html/0b1e022a32e136ff0a9b42e7ef7da5ccc7d256d175394c2d5858f1cf@%3Cdev.dubbo.apache.org%3E <https://lists.apache.org/thread.html/0b1e022a32e136ff0a9b42e7ef7da5ccc7d256d175394c2d5858f1cf@%3Cdev.dubbo.apache.org%3E>
>> 
>> The release candidates:
>> https://dist.apache.org/repos/dist/dev/incubator/dubbo/2.6.2 <https://dist.apache.org/repos/dist/dev/incubator/dubbo/2.6.2>
>> 
>> Git tag for the release:
>> https://github.com/apache/incubator-dubbo/tree/dubbo-2.6.2 <https://github.com/apache/incubator-dubbo/tree/dubbo-2.6.2> 
>> 
>> Hash for the release tag:
>> 5eeb240337ccfbc820d4bde023d8cf643f33d735
>> 
>> Release Notes:
>> https://github.com/apache/incubator-dubbo/blob/2.6.2-release/CHANGES.md <https://github.com/apache/incubator-dubbo/blob/2.6.2-release/CHANGES.md>
>> 
>> The artifacts have been signed with Key : 28681CB1, which can be found in the keys file:
>> https://dist.apache.org/repos/dist/dev/incubator/dubbo/KEYS <https://dist.apache.org/repos/dist/dev/incubator/dubbo/KEYS>
>> 
>> The vote will be open for at least 72 hours or until necessary number of votes are reached.
>> 
>> Please vote accordingly:
>> [ ] +1 approve 
>> [ ] +0 no opinion 
>> [ ] -1 disapprove with the reason
>> 
>> Thanks.
>> Jun Liu,
>> on behalf of The Apache Dubbo (Incubating) Team
>> 
> 


Re: [VOTE]: Release Apache Dubbo (Incubating) 2.6.2 [RC2]

Posted by Jun Liu <li...@apache.org>.
> I strongly recommend that you include the full fingerprint of the
> signing KEY in the KEYS file as well as the key ID. See [1] for an
> example where some of the keys have this. A few years ago an attack was
> demonstrated ([2], [3]) that show it was possible to create collisions
> in the key ID. Using the full fingerprint mitigates this attack.

The KEYS file I have updated with the full fingerprint added.

> No concerns with the file name used. Just a comment that the usual
> naming convention would be:
> apache-dubbo-incubating-2.6.2-src.zip

Will follow the naming convention for the next release.

> I'd suggest including the .gitignore file in the src release.

Will also add in the next release.

> I was a little surprised that the binary bundle was just the JARs rather
> than something that a user could unpack and run via dubbo.sh /
> dubbo.bat. There isn't anything wring with this, just not what I am used to.

Sure it would better be a packet for users to start Dubbo journey quickly, for example, packed samples or quick start guides which can be started by a start.sh. We are preparing for these samples and plan to replace current binary release in the next release.

Best regards,
Jun

> On 4 Jun 2018, at 4:05 PM, Mark Thomas <ma...@apache.org> wrote:
> 
> Checks:
> 
> Source bundle:
> - Hash and signature are correct
> - Hash of tag matches the hash quoted in the release vote mail
> - Contents of git tag match src bundle except for .gitignore file
> - Maven build passes
> - LICENSE and NOTICE look correct for source bundle
> - LICENSE and NOTICE look correct for binary bundle
> 
> +1 to release
> 
> 
> 
> I have the following minor review comments (none of which warrant
> another RC):
> 
> I strongly recommend that you include the full fingerprint of the
> signing KEY in the KEYS file as well as the key ID. See [1] for an
> example where some of the keys have this. A few years ago an attack was
> demonstrated ([2], [3]) that show it was possible to create collisions
> in the key ID. Using the full fingerprint mitigates this attack.
> 
> No concerns with the file name used. Just a comment that the usual
> naming convention would be:
> apache-dubbo-incubating-2.6.2-src.zip
> 
> I'd suggest including the .gitignore file in the src release.
> 
> I was a little surprised that the binary bundle was just the JARs rather
> than something that a user could unpack and run via dubbo.sh /
> dubbo.bat. There isn't anything wring with this, just not what I am used to.
> 
> Mark
> 
> 
> [1] https://dist.apache.org/repos/dist/release/tomcat/tomcat-9/KEYS
> [2] http://pgp.mit.edu/pks/lookup?op=get&search=0x10C01C5A2F6059E7
> [3] http://pgp.mit.edu/pks/lookup?op=get&search=0xB6FB7A022F6059E7
> 
> On 29/05/18 09:47, Jun Liu wrote:
>> Hello All,
>> 
>> This is a call for vote to release Apache Dubbo (Incubating) version 2.6.2.
>> 
>> The Apache Dubbo community has voted on and approved a proposal to release Apache Dubbo (Incubating) version 2.6.2.
>> 
>> We now kindly request the Incubator PMC members review and vote on this incubator release.
>> 
>> Apache Dubbo™ (incubating) is a high-performance, java based, open source RPC framework. Dubbo offers three key functionalities, which include interface based remote call, fault tolerance & load balancing, and automatic service registration & discovery. 
>> 
>> Dubbo vote thread:
>> https://lists.apache.org/thread.html/38560cb159a5c32d0cf98485c9fe791505fbc52d18d86a37713582f0@%3Cdev.dubbo.apache.org%3E <https://lists.apache.org/thread.html/38560cb159a5c32d0cf98485c9fe791505fbc52d18d86a37713582f0@%3Cdev.dubbo.apache.org%3E>
>> 
>> Dubbo vote result thread:
>> https://lists.apache.org/thread.html/0b1e022a32e136ff0a9b42e7ef7da5ccc7d256d175394c2d5858f1cf@%3Cdev.dubbo.apache.org%3E <https://lists.apache.org/thread.html/0b1e022a32e136ff0a9b42e7ef7da5ccc7d256d175394c2d5858f1cf@%3Cdev.dubbo.apache.org%3E>
>> 
>> The release candidates:
>> https://dist.apache.org/repos/dist/dev/incubator/dubbo/2.6.2 <https://dist.apache.org/repos/dist/dev/incubator/dubbo/2.6.2>
>> 
>> Git tag for the release:
>> https://github.com/apache/incubator-dubbo/tree/dubbo-2.6.2 <https://github.com/apache/incubator-dubbo/tree/dubbo-2.6.2> 
>> 
>> Hash for the release tag:
>> 5eeb240337ccfbc820d4bde023d8cf643f33d735
>> 
>> Release Notes:
>> https://github.com/apache/incubator-dubbo/blob/2.6.2-release/CHANGES.md <https://github.com/apache/incubator-dubbo/blob/2.6.2-release/CHANGES.md>
>> 
>> The artifacts have been signed with Key : 28681CB1, which can be found in the keys file:
>> https://dist.apache.org/repos/dist/dev/incubator/dubbo/KEYS <https://dist.apache.org/repos/dist/dev/incubator/dubbo/KEYS>
>> 
>> The vote will be open for at least 72 hours or until necessary number of votes are reached.
>> 
>> Please vote accordingly:
>> [ ] +1 approve 
>> [ ] +0 no opinion 
>> [ ] -1 disapprove with the reason
>> 
>> Thanks.
>> Jun Liu,
>> on behalf of The Apache Dubbo (Incubating) Team
>> 
> 


Re: [VOTE]: Release Apache Dubbo (Incubating) 2.6.2 [RC2]

Posted by Mark Thomas <ma...@apache.org>.
Checks:

Source bundle:
- Hash and signature are correct
- Hash of tag matches the hash quoted in the release vote mail
- Contents of git tag match src bundle except for .gitignore file
- Maven build passes
- LICENSE and NOTICE look correct for source bundle
- LICENSE and NOTICE look correct for binary bundle

+1 to release



I have the following minor review comments (none of which warrant
another RC):

I strongly recommend that you include the full fingerprint of the
signing KEY in the KEYS file as well as the key ID. See [1] for an
example where some of the keys have this. A few years ago an attack was
demonstrated ([2], [3]) that show it was possible to create collisions
in the key ID. Using the full fingerprint mitigates this attack.

No concerns with the file name used. Just a comment that the usual
naming convention would be:
apache-dubbo-incubating-2.6.2-src.zip

I'd suggest including the .gitignore file in the src release.

I was a little surprised that the binary bundle was just the JARs rather
than something that a user could unpack and run via dubbo.sh /
dubbo.bat. There isn't anything wring with this, just not what I am used to.

Mark


[1] https://dist.apache.org/repos/dist/release/tomcat/tomcat-9/KEYS
[2] http://pgp.mit.edu/pks/lookup?op=get&search=0x10C01C5A2F6059E7
[3] http://pgp.mit.edu/pks/lookup?op=get&search=0xB6FB7A022F6059E7

On 29/05/18 09:47, Jun Liu wrote:
> Hello All,
> 
> This is a call for vote to release Apache Dubbo (Incubating) version 2.6.2.
> 
> The Apache Dubbo community has voted on and approved a proposal to release Apache Dubbo (Incubating) version 2.6.2.
> 
> We now kindly request the Incubator PMC members review and vote on this incubator release.
> 
> Apache Dubbo™ (incubating) is a high-performance, java based, open source RPC framework. Dubbo offers three key functionalities, which include interface based remote call, fault tolerance & load balancing, and automatic service registration & discovery. 
> 
> Dubbo vote thread:
> https://lists.apache.org/thread.html/38560cb159a5c32d0cf98485c9fe791505fbc52d18d86a37713582f0@%3Cdev.dubbo.apache.org%3E <https://lists.apache.org/thread.html/38560cb159a5c32d0cf98485c9fe791505fbc52d18d86a37713582f0@%3Cdev.dubbo.apache.org%3E>
> 
> Dubbo vote result thread:
> https://lists.apache.org/thread.html/0b1e022a32e136ff0a9b42e7ef7da5ccc7d256d175394c2d5858f1cf@%3Cdev.dubbo.apache.org%3E <https://lists.apache.org/thread.html/0b1e022a32e136ff0a9b42e7ef7da5ccc7d256d175394c2d5858f1cf@%3Cdev.dubbo.apache.org%3E>
> 
> The release candidates:
> https://dist.apache.org/repos/dist/dev/incubator/dubbo/2.6.2 <https://dist.apache.org/repos/dist/dev/incubator/dubbo/2.6.2>
> 
> Git tag for the release:
> https://github.com/apache/incubator-dubbo/tree/dubbo-2.6.2 <https://github.com/apache/incubator-dubbo/tree/dubbo-2.6.2> 
> 
> Hash for the release tag:
> 5eeb240337ccfbc820d4bde023d8cf643f33d735
> 
> Release Notes:
> https://github.com/apache/incubator-dubbo/blob/2.6.2-release/CHANGES.md <https://github.com/apache/incubator-dubbo/blob/2.6.2-release/CHANGES.md>
> 
> The artifacts have been signed with Key : 28681CB1, which can be found in the keys file:
> https://dist.apache.org/repos/dist/dev/incubator/dubbo/KEYS <https://dist.apache.org/repos/dist/dev/incubator/dubbo/KEYS>
> 
> The vote will be open for at least 72 hours or until necessary number of votes are reached.
> 
> Please vote accordingly:
> [ ] +1 approve 
> [ ] +0 no opinion 
> [ ] -1 disapprove with the reason
> 
> Thanks.
> Jun Liu,
> on behalf of The Apache Dubbo (Incubating) Team
> 


Re: [VOTE]: Release Apache Dubbo (Incubating) 2.6.2 [RC2]

Posted by Xin Wang <wa...@apache.org>.
+1 (non-binding)

Huxing Zhang <hu...@apache.org> 于2018年5月31日周四 下午10:41写道:

> +1 (non-binding)
>
> On Tue, May 29, 2018 at 4:47 PM, Jun Liu <li...@apache.org> wrote:
> > Hello All,
> >
> > This is a call for vote to release Apache Dubbo (Incubating) version
> 2.6.2.
> >
> > The Apache Dubbo community has voted on and approved a proposal to
> release Apache Dubbo (Incubating) version 2.6.2.
> >
> > We now kindly request the Incubator PMC members review and vote on this
> incubator release.
> >
> > Apache Dubbo™ (incubating) is a high-performance, java based, open
> source RPC framework. Dubbo offers three key functionalities, which include
> interface based remote call, fault tolerance & load balancing, and
> automatic service registration & discovery.
> >
> > Dubbo vote thread:
> >
> https://lists.apache.org/thread.html/38560cb159a5c32d0cf98485c9fe791505fbc52d18d86a37713582f0@%3Cdev.dubbo.apache.org%3E
> <
> https://lists.apache.org/thread.html/38560cb159a5c32d0cf98485c9fe791505fbc52d18d86a37713582f0@%3Cdev.dubbo.apache.org%3E
> >
> >
> > Dubbo vote result thread:
> >
> https://lists.apache.org/thread.html/0b1e022a32e136ff0a9b42e7ef7da5ccc7d256d175394c2d5858f1cf@%3Cdev.dubbo.apache.org%3E
> <
> https://lists.apache.org/thread.html/0b1e022a32e136ff0a9b42e7ef7da5ccc7d256d175394c2d5858f1cf@%3Cdev.dubbo.apache.org%3E
> >
> >
> > The release candidates:
> > https://dist.apache.org/repos/dist/dev/incubator/dubbo/2.6.2 <
> https://dist.apache.org/repos/dist/dev/incubator/dubbo/2.6.2>
> >
> > Git tag for the release:
> > https://github.com/apache/incubator-dubbo/tree/dubbo-2.6.2 <
> https://github.com/apache/incubator-dubbo/tree/dubbo-2.6.2>
> >
> > Hash for the release tag:
> > 5eeb240337ccfbc820d4bde023d8cf643f33d735
> >
> > Release Notes:
> > https://github.com/apache/incubator-dubbo/blob/2.6.2-release/CHANGES.md
> <https://github.com/apache/incubator-dubbo/blob/2.6.2-release/CHANGES.md>
> >
> > The artifacts have been signed with Key : 28681CB1, which can be found
> in the keys file:
> > https://dist.apache.org/repos/dist/dev/incubator/dubbo/KEYS <
> https://dist.apache.org/repos/dist/dev/incubator/dubbo/KEYS>
> >
> > The vote will be open for at least 72 hours or until necessary number of
> votes are reached.
> >
> > Please vote accordingly:
> > [ ] +1 approve
> > [ ] +0 no opinion
> > [ ] -1 disapprove with the reason
> >
> > Thanks.
> > Jun Liu,
> > on behalf of The Apache Dubbo (Incubating) Team
>
> --
> Best Regards!
> Huxing
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: general-unsubscribe@incubator.apache.org
> For additional commands, e-mail: general-help@incubator.apache.org
>
>

Re: [VOTE]: Release Apache Dubbo (Incubating) 2.6.2 [RC2]

Posted by Huxing Zhang <hu...@apache.org>.
+1 (non-binding)

On Tue, May 29, 2018 at 4:47 PM, Jun Liu <li...@apache.org> wrote:
> Hello All,
>
> This is a call for vote to release Apache Dubbo (Incubating) version 2.6.2.
>
> The Apache Dubbo community has voted on and approved a proposal to release Apache Dubbo (Incubating) version 2.6.2.
>
> We now kindly request the Incubator PMC members review and vote on this incubator release.
>
> Apache Dubbo™ (incubating) is a high-performance, java based, open source RPC framework. Dubbo offers three key functionalities, which include interface based remote call, fault tolerance & load balancing, and automatic service registration & discovery.
>
> Dubbo vote thread:
> https://lists.apache.org/thread.html/38560cb159a5c32d0cf98485c9fe791505fbc52d18d86a37713582f0@%3Cdev.dubbo.apache.org%3E <https://lists.apache.org/thread.html/38560cb159a5c32d0cf98485c9fe791505fbc52d18d86a37713582f0@%3Cdev.dubbo.apache.org%3E>
>
> Dubbo vote result thread:
> https://lists.apache.org/thread.html/0b1e022a32e136ff0a9b42e7ef7da5ccc7d256d175394c2d5858f1cf@%3Cdev.dubbo.apache.org%3E <https://lists.apache.org/thread.html/0b1e022a32e136ff0a9b42e7ef7da5ccc7d256d175394c2d5858f1cf@%3Cdev.dubbo.apache.org%3E>
>
> The release candidates:
> https://dist.apache.org/repos/dist/dev/incubator/dubbo/2.6.2 <https://dist.apache.org/repos/dist/dev/incubator/dubbo/2.6.2>
>
> Git tag for the release:
> https://github.com/apache/incubator-dubbo/tree/dubbo-2.6.2 <https://github.com/apache/incubator-dubbo/tree/dubbo-2.6.2>
>
> Hash for the release tag:
> 5eeb240337ccfbc820d4bde023d8cf643f33d735
>
> Release Notes:
> https://github.com/apache/incubator-dubbo/blob/2.6.2-release/CHANGES.md <https://github.com/apache/incubator-dubbo/blob/2.6.2-release/CHANGES.md>
>
> The artifacts have been signed with Key : 28681CB1, which can be found in the keys file:
> https://dist.apache.org/repos/dist/dev/incubator/dubbo/KEYS <https://dist.apache.org/repos/dist/dev/incubator/dubbo/KEYS>
>
> The vote will be open for at least 72 hours or until necessary number of votes are reached.
>
> Please vote accordingly:
> [ ] +1 approve
> [ ] +0 no opinion
> [ ] -1 disapprove with the reason
>
> Thanks.
> Jun Liu,
> on behalf of The Apache Dubbo (Incubating) Team

-- 
Best Regards!
Huxing

---------------------------------------------------------------------
To unsubscribe, e-mail: general-unsubscribe@incubator.apache.org
For additional commands, e-mail: general-help@incubator.apache.org


[RESULT][VOTE]: Release Apache Dubbo (Incubating) 2.6.2 [RC2]

Posted by Jun Liu <li...@apache.org>.
Hi,

This vote has passed with 3 +1 votes (bindings), 2 +1 votes (non-binding) and no 0 or -1 votes.

+1 (binding), Willem Jiang
+1 (binding), Justin Mclean
+1 (binding), Mark Thomas

+1 (non-binding), Huxing Zhang
+1 (non-binding), Xin Wang

Thank you all for your votes and suggestions to this release.

Best regards,
Jun

> On 29 May 2018, at 4:47 PM, Jun Liu <li...@apache.org> wrote:
> 
> Hello All,
> 
> This is a call for vote to release Apache Dubbo (Incubating) version 2.6.2.
> 
> The Apache Dubbo community has voted on and approved a proposal to release Apache Dubbo (Incubating) version 2.6.2.
> 
> We now kindly request the Incubator PMC members review and vote on this incubator release.
> 
> Apache Dubbo™ (incubating) is a high-performance, java based, open source RPC framework. Dubbo offers three key functionalities, which include interface based remote call, fault tolerance & load balancing, and automatic service registration & discovery. 
> 
> Dubbo vote thread:
> https://lists.apache.org/thread.html/38560cb159a5c32d0cf98485c9fe791505fbc52d18d86a37713582f0@%3Cdev.dubbo.apache.org%3E <https://lists.apache.org/thread.html/38560cb159a5c32d0cf98485c9fe791505fbc52d18d86a37713582f0@%3Cdev.dubbo.apache.org%3E>
> 
> Dubbo vote result thread:
> https://lists.apache.org/thread.html/0b1e022a32e136ff0a9b42e7ef7da5ccc7d256d175394c2d5858f1cf@%3Cdev.dubbo.apache.org%3E <https://lists.apache.org/thread.html/0b1e022a32e136ff0a9b42e7ef7da5ccc7d256d175394c2d5858f1cf@%3Cdev.dubbo.apache.org%3E>
> 
> The release candidates:
> https://dist.apache.org/repos/dist/dev/incubator/dubbo/2.6.2 <https://dist.apache.org/repos/dist/dev/incubator/dubbo/2.6.2>
> 
> Git tag for the release:
> https://github.com/apache/incubator-dubbo/tree/dubbo-2.6.2 <https://github.com/apache/incubator-dubbo/tree/dubbo-2.6.2> 
> 
> Hash for the release tag:
> 5eeb240337ccfbc820d4bde023d8cf643f33d735
> 
> Release Notes:
> https://github.com/apache/incubator-dubbo/blob/2.6.2-release/CHANGES.md <https://github.com/apache/incubator-dubbo/blob/2.6.2-release/CHANGES.md>
> 
> The artifacts have been signed with Key : 28681CB1, which can be found in the keys file:
> https://dist.apache.org/repos/dist/dev/incubator/dubbo/KEYS <https://dist.apache.org/repos/dist/dev/incubator/dubbo/KEYS>
> 
> The vote will be open for at least 72 hours or until necessary number of votes are reached.
> 
> Please vote accordingly:
> [ ] +1 approve 
> [ ] +0 no opinion 
> [ ] -1 disapprove with the reason
> 
> Thanks.
> Jun Liu,
> on behalf of The Apache Dubbo (Incubating) Team


Re: [VOTE]: Release Apache Dubbo (Incubating) 2.6.2 [RC2]

Posted by Mark Thomas <ma...@apache.org>.
Checks:

Source bundle:
- Hash and signature are correct
- Hash of tag matches the hash quoted in the release vote mail
- Contents of git tag match src bundle except for .gitignore file
- Maven build passes
- LICENSE and NOTICE look correct for source bundle
- LICENSE and NOTICE look correct for binary bundle

+1 to release



I have the following minor review comments (none of which warrant
another RC):

I strongly recommend that you include the full fingerprint of the
signing KEY in the KEYS file as well as the key ID. See [1] for an
example where some of the keys have this. A few years ago an attack was
demonstrated ([2], [3]) that show it was possible to create collisions
in the key ID. Using the full fingerprint mitigates this attack.

No concerns with the file name used. Just a comment that the usual
naming convention would be:
apache-dubbo-incubating-2.6.2-src.zip

I'd suggest including the .gitignore file in the src release.

I was a little surprised that the binary bundle was just the JARs rather
than something that a user could unpack and run via dubbo.sh /
dubbo.bat. There isn't anything wring with this, just not what I am used to.

Mark


[1] https://dist.apache.org/repos/dist/release/tomcat/tomcat-9/KEYS
[2] http://pgp.mit.edu/pks/lookup?op=get&search=0x10C01C5A2F6059E7
[3] http://pgp.mit.edu/pks/lookup?op=get&search=0xB6FB7A022F6059E7

On 29/05/18 09:47, Jun Liu wrote:
> Hello All,
> 
> This is a call for vote to release Apache Dubbo (Incubating) version 2.6.2.
> 
> The Apache Dubbo community has voted on and approved a proposal to release Apache Dubbo (Incubating) version 2.6.2.
> 
> We now kindly request the Incubator PMC members review and vote on this incubator release.
> 
> Apache Dubbo™ (incubating) is a high-performance, java based, open source RPC framework. Dubbo offers three key functionalities, which include interface based remote call, fault tolerance & load balancing, and automatic service registration & discovery. 
> 
> Dubbo vote thread:
> https://lists.apache.org/thread.html/38560cb159a5c32d0cf98485c9fe791505fbc52d18d86a37713582f0@%3Cdev.dubbo.apache.org%3E <https://lists.apache.org/thread.html/38560cb159a5c32d0cf98485c9fe791505fbc52d18d86a37713582f0@%3Cdev.dubbo.apache.org%3E>
> 
> Dubbo vote result thread:
> https://lists.apache.org/thread.html/0b1e022a32e136ff0a9b42e7ef7da5ccc7d256d175394c2d5858f1cf@%3Cdev.dubbo.apache.org%3E <https://lists.apache.org/thread.html/0b1e022a32e136ff0a9b42e7ef7da5ccc7d256d175394c2d5858f1cf@%3Cdev.dubbo.apache.org%3E>
> 
> The release candidates:
> https://dist.apache.org/repos/dist/dev/incubator/dubbo/2.6.2 <https://dist.apache.org/repos/dist/dev/incubator/dubbo/2.6.2>
> 
> Git tag for the release:
> https://github.com/apache/incubator-dubbo/tree/dubbo-2.6.2 <https://github.com/apache/incubator-dubbo/tree/dubbo-2.6.2> 
> 
> Hash for the release tag:
> 5eeb240337ccfbc820d4bde023d8cf643f33d735
> 
> Release Notes:
> https://github.com/apache/incubator-dubbo/blob/2.6.2-release/CHANGES.md <https://github.com/apache/incubator-dubbo/blob/2.6.2-release/CHANGES.md>
> 
> The artifacts have been signed with Key : 28681CB1, which can be found in the keys file:
> https://dist.apache.org/repos/dist/dev/incubator/dubbo/KEYS <https://dist.apache.org/repos/dist/dev/incubator/dubbo/KEYS>
> 
> The vote will be open for at least 72 hours or until necessary number of votes are reached.
> 
> Please vote accordingly:
> [ ] +1 approve 
> [ ] +0 no opinion 
> [ ] -1 disapprove with the reason
> 
> Thanks.
> Jun Liu,
> on behalf of The Apache Dubbo (Incubating) Team
> 


---------------------------------------------------------------------
To unsubscribe, e-mail: general-unsubscribe@incubator.apache.org
For additional commands, e-mail: general-help@incubator.apache.org