cordova-coho icon indicating copy to clipboard operation
cordova-coho copied to clipboard

Release approval criteria

Open brody4hire opened this issue 7 years ago • 3 comments

I think this is not clear for all members.

brody4hire avatar Oct 10 '18 18:10 brody4hire

There is really nothing more to it than what is listed in the voting guidelines linked from every vote thread.

When we (or at least, members of the PMC), vote on a release, we are expressing confidence that:

Our sources are properly licensed*. We have only compatibly licensed dependencies (and appropriate NOTICE lines)*. No IP was added without the consent of its owner**. Archives are properly signed & hashed. Repo tags match sha1 stated in vote email. We believe the quality of the release is better than the previous one.

  • These items are generally checked by the Release Manager. The Release Manager should state that they've checked them when they +1 the vote.

** It is the responsibility of committers to ensure that no invalid IP enters the codebase. It's not something that we need to re-check at each release.

purplecabbage avatar Oct 10 '18 20:10 purplecabbage

Shouldn't someone verify that the package is signed correctly?

I also encountered a couple members who needed more direct step-by-step instructions.

brody4hire avatar Oct 10 '18 21:10 brody4hire

Archives are properly signed & hashed.

purplecabbage avatar Oct 10 '18 22:10 purplecabbage