Record 1.4.1 Central publication and maintainer readiness - #208
Merged
Merged
Conversation
Closed
6 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Change
The repository still described 1.4.1 as unavailable from Maven Central after the retained signed release was published. Update consumer and release documentation to confirm availability, and add the deployment ID, bundle checksum, signing fingerprint, and exact artifact-comparison record.
Record Jim's verified namespace access and his September 26 confirmation that he and Jeremy completed the independent vault-recovery drills, namespace checks, and separate validated-and-dropped staging rehearsals that day. Distinguish this maintainer-reported completion from the directly verified publication; individual recovery records and rehearsal deployment IDs were not inspected. The 1.5 release gate remains unchanged.
Closes #111.
Compatibility and validation
Documentation only; no code, POM, release artifact, signature, or tag changes.
Central Portal deployment
ce91e36f-756c-489f-bbea-3629b728ad28:PUBLISHED.All 12 binary/source/Javadoc JARs, five POMs, and 17 signatures downloaded from Central matched the retained release byte for byte.
Before publication: verified 19 PGP signatures, both signed checksum manifests, all bundle checksums, and the signed release tag.
git diff --checkpassed; all checked local Markdown link targets exist.GitHub release notice updated and verified; OWASP page references 1.4.1. Javadoc indexing still showed 1.4.0 immediately after publication.
I kept the change scoped and preserved relevant notices.
I checked documentation/changelog and tests for any behavior change.
This PR contains no credentials or private vulnerability evidence.
Maintainer merge record
Jim requested this merge after publication of the 1.4.1 security release. All 28 checks passed on commit
3059735c6a655a1ddf9f591ce1c686243410d62a, including Java CI gate, Packaged consumer gate, and all three CodeQL language jobs. The normal merge path requires independent approval. Thejmanicoaccount's existing PR-only maintainer review bypass is used to publish the corrected security-release availability notes promptly. This is not independent approval; required-check protections and repository rules are unchanged.