Skip to content

Record 1.4.1 Central publication and maintainer readiness - #208

Merged
jmanico merged 2 commits into
mainfrom
docs/1.4.1-central-publication
Sep 27, 2026
Merged

jmanico merged 2 commits into
mainfrom
docs/1.4.1-central-publication

Conversation

@jmanico

@jmanico jmanico commented Sep 27, 2026 •

Copy link
Copy Markdown
Member

Change

The repository still described 1.4.1 as unavailable from Maven Central after the retained signed release was published. Update consumer and release documentation to confirm availability, and add the deployment ID, bundle checksum, signing fingerprint, and exact artifact-comparison record.

Record Jim's verified namespace access and his September 26 confirmation that he and Jeremy completed the independent vault-recovery drills, namespace checks, and separate validated-and-dropped staging rehearsals that day. Distinguish this maintainer-reported completion from the directly verified publication; individual recovery records and rehearsal deployment IDs were not inspected. The 1.5 release gate remains unchanged.

Closes #111.

Compatibility and validation

Documentation only; no code, POM, release artifact, signature, or tag changes.

  • Central Portal deployment ce91e36f-756c-489f-bbea-3629b728ad28: PUBLISHED.

  • All 12 binary/source/Javadoc JARs, five POMs, and 17 signatures downloaded from Central matched the retained release byte for byte.

  • Before publication: verified 19 PGP signatures, both signed checksum manifests, all bundle checksums, and the signed release tag.

  • git diff --check passed; all checked local Markdown link targets exist.

  • GitHub release notice updated and verified; OWASP page references 1.4.1. Javadoc indexing still showed 1.4.0 immediately after publication.

  • I kept the change scoped and preserved relevant notices.

  • I checked documentation/changelog and tests for any behavior change.

  • This PR contains no credentials or private vulnerability evidence.

Maintainer merge record

Jim requested this merge after publication of the 1.4.1 security release. All 28 checks passed on commit 3059735c6a655a1ddf9f591ce1c686243410d62a, including Java CI gate, Packaged consumer gate, and all three CodeQL language jobs. The normal merge path requires independent approval. The jmanico account's existing PR-only maintainer review bypass is used to publish the corrected security-release availability notes promptly. This is not independent approval; required-check protections and repository rules are unchanged.

@jmanico
jmanico requested a review from jeremylong as a code owner September 27, 2026 04:50
@jmanico jmanico changed the title Record verified Maven Central publication of 1.4.1 Record 1.4.1 Central publication and maintainer readiness Sep 27, 2026
@jmanico
jmanico merged commit 1111f79 into main Sep 27, 2026
28 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Complete release readiness: Central 1.4.1 publication and independent maintainer recovery

1 participant