You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@tez.apache.org by "Stamatis Zampetakis (Jira)" <ji...@apache.org> on 2024/01/19 12:57:00 UTC

[jira] [Created] (TEZ-4532) Remove KEYS file from git repo and source distribution

Stamatis Zampetakis created TEZ-4532:
----------------------------------------

             Summary: Remove KEYS file from git repo and source distribution
                 Key: TEZ-4532
                 URL: https://issues.apache.org/jira/browse/TEZ-4532
             Project: Apache Tez
          Issue Type: Task
            Reporter: Stamatis Zampetakis
            Assignee: Stamatis Zampetakis


As per [release distribution instructions:|https://infra.apache.org/release-distribution.html#sigs-and-sums]

Projects must publish a KEYS file in their distribution directory which contains all public keys used to sign artifacts.

https://dist.apache.org/repos/dist/release/tez/KEYS

Currently the KEYS file (or a version of it) is also in the [git repo|https://github.com/apache/tez/blob/21611246b1dc4cdc61d3c1970c646fb9a6943351/KEYS] and is also bundled inside each source distribution.

The file in the git repo is not serving any purpose since it shouldn't be used to verify releases. It adds maintenance overhead (assuming that is kept in sync) and possible confusion to the users with respect to which file they should use to validate the artifacts.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)