+1 (binding)

------ Original Message ------
>From "Paul King" <[email protected]>
To "Groovy_Developers" <[email protected]>
Date 9/18/2026 9:52:15 PM
Subject [VOTE] Release Apache Groovy 6.0.0

>
>
>Dear development community,
>
>
>
>I am happy to start the VOTE thread for a Groovy 6.0.0 release!
>
>
>
>This release includes 10 bug fixes/improvements as outlined in the changelog:
>
>https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12318123&version=12357525
>
>
>
>Tag: https://github.com/apache/groovy/tree/GROOVY_6_0_0/
>
>Tag commit id: bc6b3cfd9f8f3397129f8ebbdf85a189d16d7360
>
>
>
>The artifacts to be voted on are located as follows (r87671).
>
>Source release: https://dist.apache.org/repos/dist/dev/groovy/6.0.0/sources
>
>Convenience binaries:
>
>https://dist.apache.org/repos/dist/dev/groovy/6.0.0/distribution
>
>Temporary artifacts:
>
>https://repository.apache.org/content/repositories/orgapachegroovy-1125
>
>
>
>Release artifacts are signed with a key from the following file:
>
>https://dist.apache.org/repos/dist/release/groovy/KEYS
>
>
>
>Please vote on releasing this package as Apache Groovy 6.0.0.
>
>
>
>Reminder on ASF release approval requirements for PMC members:
>
>http://www.apache.org/legal/release-policy.html#release-approval
>
>Hints on validating checksums/signatures (but replace md5sum with sha256sum):
>
>https://www.apache.org/info/verification.html
>
>
>
>The vote is open for the next 72 hours and passes if a majority of at
>
>least three +1 PMC votes are cast.
>
>
>
>[ ] +1 Release Apache Groovy 6.0.0
>
>[ ]  0 I don't have a strong opinion about this, but I assume it's ok
>
>[ ] -1 Do not release Apache Groovy 6.0.0 because...
>
>
>
>Here is my vote:
>
>
>
>+1 (binding)
>
>
>
>----
>
>
>
>My local verify.sh:
>
>
>
>✅ KEYS Downloaded
>
>✅ Source Distribution Verified
>
>✅ Binary Distribution Verified
>
>✅ Docs Distribution Verified
>
>✅ SDK Distribution Verified
>
>✅ Gradle Bootstrapped
>
>✅ RAT passed
>
>✅✅✅ Automatic verification finished.
>
>
>
>GroovyPolicyMCP:
>
>
>
>**Verdict: Apache Groovy 6.0.0 is clean. I would vote +1.** Every
>
>check on the release checklist passed, and my worktree for the RAT run
>
>was removed without touching your GROOVY_6_0_X checkout.
>
>
>
>**Tag and source**
>
>
>
>- The annotated tag on gitbox and GitHub resolves to commit
>
>bc6b3cfd9f8f3397129f8ebbdf85a189d16d7360, matching the vote email. Its
>
>parent is on origin/GROOVY_6_0_X, and it carries 12 commits after
>
>RC-3, all dependency bumps and the listed fixes.
>
>- The source zip is identical to `git archive` at the tag. The only
>
>absent files are the usual deliberate omissions: benchmark, perf
>
>dashboard, wrapper, governance docs, CI configs, ABI surface.
>
>- No compiled code or archives in the source zip. The full project RAT
>
>check passes at the tag. The version is 6.0.0 with no SNAPSHOT or RC
>
>remnants in the properties, jar manifests, or poms.
>
>- The JIRA changelog lists 10 unique issues, as the email says.
>
>
>
>**Signatures and checksums**
>
>
>
>| Location                           | Artifacts | Signed by
>
>6A65176A0FB1CD0B | Checksums                           |
>
>| ---------------------------------- | --------- |
>
>-------------------------- | ----------------------------------- |
>
>| dist.apache.org zips               | 4         | 4 good
>
>        | SHA-256 match                       |
>
>| Nexus staging orgapachegroovy-1125 | 297       | 297 good
>
>        | md5, sha1, sha256, sha512 all match |
>
>
>
>The key is in the published KEYS file at dist/release/groovy.
>
>
>
>**LICENSE and NOTICE**
>
>
>
>- All four zips' LICENSE and NOTICE files are byte-identical to
>
>RC-3's. Pointers resolve 18 of 18 in binary and SDK, 6 of 6 in source,
>
>4 of 4 in docs, with no unreferenced texts. NOTICE carries the 13
>
>upstream credits.
>
>- The lib set changed only in versions since RC-3: JLine and jansi to
>
>4.4.5, jcl-over-slf4j to 2.0.19, and the maven-resolver family to
>
>2.0.23. JLine 4.4.5's pom still declares BSD-3-Clause, and the other
>
>two keep their MIT and Apache licences, so the existing LICENSE text
>
>covers them.
>
>- All 167 staged jars carry META-INF LICENSE and NOTICE with every
>
>pointer resolving. Raw, shaded, grooid, sources and groovy-all-sources
>
>declarations match their content. Sources, javadoc and groovydoc jars
>
>contain no classes.
>
>- The core, grooid and groovy-test-grooid jars in the binary zip are
>
>byte-identical to the staged ones, as are all 39 module jars in lib/,
>
>and the staged groovy-binary zip is byte-identical to the dist binary
>
>zip.
>
>- All 43 poms declare the licence with no SNAPSHOT or RC dependencies.
>
>SBOMs show 729 of 729 components licensed.

Reply via email to