-
Notifications
You must be signed in to change notification settings - Fork 128
Complete release readiness: Central 1.4.1 publication and independent maintainer recovery #111
Copy link
Copy link
Open
Labels
area: releaseSigned artifacts, release tooling, publication and custody.Signed artifacts, release tooling, publication and custody.documentationenhancementpriority: P0Active security release delivery; first priority when its external blocker clears.Active security release delivery; first priority when its external blocker clears.security-reviewSecurity-sensitive scope or acceptance criteria; not a vulnerability classification.Security-sensitive scope or acceptance criteria; not a vulnerability classification.triage: external-blockerRequires external access or individual confirmation; preserve evidence of what remains.Requires external access or individual confirmation; preserve evidence of what remains.
Milestone
Description
Activity
Metadata
Metadata
Assignees
Labels
area: releaseSigned artifacts, release tooling, publication and custody.Signed artifacts, release tooling, publication and custody.documentationenhancementpriority: P0Active security release delivery; first priority when its external blocker clears.Active security release delivery; first priority when its external blocker clears.security-reviewSecurity-sensitive scope or acceptance criteria; not a vulnerability classification.Security-sensitive scope or acceptance criteria; not a vulnerability classification.triage: external-blockerRequires external access or individual confirmation; preserve evidence of what remains.Requires external access or individual confirmation; preserve evidence of what remains.
Reviewed 2026-09-25 (America/Los_Angeles) against
mainatbd249f5. Execution order and cross-issue ownership: #169. Batch 00.This scope replaces the dated implementation prescriptions in the original report and earlier comments; linked historical evidence remains useful but must be rechecked before implementation.
Current state
PRs #156 and #164 added
RELEASING.md,MAINTAINERS.md, the project signing key, recovery instructions, and the README release link. Those documentation tasks are complete. GitHub has the signed 1.4.1 security release; a live check still finds Central'sencoder/1.4.1/encoder-1.4.1.pomreturning 404 and metadata listing 1.4.0.MAINTAINERS.mdrecords unconfirmed individual vault drills and publishing access/rehearsals. Continue the existing Central Support request; do not open another.Remaining acceptance criteria
RELEASING.md.This is the single owner for operational custody, access and rehearsal work previously repeated in #95. #95 retains future release-tooling modernization; it is not a prerequisite to uploading the existing bundle. This organization pass does not itself publish anything.
Batch 00 evidence — 2026-09-25 (America/Los_Angeles)
#171 merged as
6a3c3a9bd5d8eaa82c6ee956ab78ff9e11821b6f, recording the dated results and clarifying exact-bundle retry/comparison requirements and distinct nonpublished rehearsal versions. All 20 PR checks passed. The operational acceptance criteria below remain open. All five 1.4.1 POMs returned HTTP 404 from Central at 2026-09-26 04:48:36 UTC. Jim's current signed-in Portal account showed No Namespace(s) Found and disabled Publish Component. Namespace access therefore still blocks publication and his rehearsal; Jeremy's access remains unconfirmed. Continue the existing Support request; no new request or deployment was created.Jim confirmed initial key setup today, not retrieval and a drill from his own vault or a validated-and-dropped staging rehearsal. No independent confirmation was received from Jeremy. Keep those acceptance criteria open.
The retained GitHub bundle was downloaded and verified without alteration: 19 project-key signatures, both signed checksum manifests, all 17 bundled JARs/POMs and their matching standalone signatures, and all bundled MD5/SHA-1/SHA-256/SHA-512 checksums. SHA-256:
c70234d2290fff0011d484219b7bc8fae2581cf24b24b03abf5eab4413b6d4c3. Public artifact verification does not establish private-key recovery or publishing access. The OWASP project page still recommends 1.3.0; javadoc.io identifies 1.4.0. Reconcile these destinations with actual release availability as part of the follow-up.Detailed evidence. Central-pending notices and the 1.5 backlog gate remain in force; this issue remains open.