+1 sigs ok, content ok, smoketest worked.
notes for next release: the one-time key could be also printed directly to System.out so that it lands in the console logger and could be easily read from container logs and/or console while testing. notice file would need a date bump at some point ;) -mbien On 9/18/26 01:28, Dave wrote: > Right o, here we go... > > Please review and vote on Apache Roller 6.1.6, candidate RC4. > > Source and convenience binary artifacts: > https://dist.apache.org/repos/dist/dev/roller/roller-6.1/v6.1.6 > > Source tag: roller-6.1.6-rc4 > https://github.com/apache/roller/tree/roller-6.1.6-rc4 > > commit 47c5cf0bbfa00fe199bc743a7fb88df8e6b21d32 > KEYS: https://downloads.apache.org/roller/KEYS > > Signing fingerprint: 3687 8574 1958 DE96 98FF DF4E 8FEC 6F9C BA59 703C > > Release notes: > https://github.com/apache/roller/blob/roller-6.1.6-rc4/CHANGES.md > > Changes since RC3: > - Secure initial Roller setup with a one-time operator token (#189) > - Normalize links in HTML subset formatting (#190) > - Format LDAP comment form values consistently (#191) > - Override bootstrap .table-striped row shading (#188) > - Add roller-release and roller-security AI skills (#186) > > Reviewers may want to exercise the new initial-setup flow in particular: > a first install now requires a one-time token printed to the server log, > as does an upgrade that migrates the database schema. > > The vote will remain open until at least 2026-09-20 20:00 EDT, > allowing at least 72 hours for review under the normal process. > > [ ] +1 Release this candidate > [ ] +0 No opinion > [ ] -1 Do not release, because [reason] > > Dave Johnson
