> In short: A targz file is just easier to "manually" review.

This is off-topic: I'm curious about if some part of the manual review
can be done at daily automated routines (tests, precommit checks,
etc.). I'm not against having a binary distribution for pre-release
review or other purposes (as it used to be done) at all; I just hope
we could reduce the manual effort and worries for every release...

Tomoko

2021年10月12日(火) 19:32 Dawid Weiss <[email protected]>:
>
> > Why I am telling this: I'd like to test the "official" to-be-released JAR 
> > files with their hashes as seen and uploaded to ASF servers, so mavenLocal 
> > is not my first preference.
>
> Correct - the same build (from the same git revision) will not result
> in identical JARs. This can be done but you'll pay the price -- you'd
> have to remove all of the variable jar manifest entries (user,
> compiler, etc.). This is valuable, I think, so  don't consider this a
> priority.
>
> D.
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
>

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to