Totally agree. I would say we should keep merging dependabot PRs into
2.x for  some months, but only do a release if we have reports of a
bug, like the one we patched in 2.8.8.
Otherwise, 3.0.0 will be the way to go to better utilise our manpower resources.

On Wed, 20 May 2026 at 18:38, Richard Zowalla <[email protected]> wrote:
>
> Given our current man power it might be beneficial, if we decide on a
> EOL strategy for the 2.x release line before going into 3.x (dropped
> clojure, Java 21 baseline), so we have a clear way on how long we want
> to support the 2.x branch with releases.
>
> Given our slow pace in getting the required votes, we might have an
> issue with maintaing to release lines in parallel over a longer period
> of time. Think we can do that for a few months but not endlessly.
>
> Might be worth a discussion thread on the dev@ list. wdyt?
>
> Am Mittwoch, dem 20.05.2026 um 16:44 +0100 schrieb Rui Abreu:
> > Hello @Richard Zowalla
> >
> > We can consider releasing 3.0.0 over the next week or so.
> >
> > On Sun, 10 May 2026 at 23:09, Rui Abreu <[email protected]> wrote:
> > >
> > > Thanks for the PRs @Richard Zowalla , much appreciated.
> > > I have merged them and dealt with the subsequent dependabot
> > > avalanche.
> > > Apologies if you received a whole bunch of Jenkins errors.
> > > I was using AI + GH client to deal with the dependabot PRs in
> > > batches
> > > and it was being quite helpful, right up until the point and it
> > > decided to merge a few PRs whose tests were still ongoing
> > >
> > >   problematic Merges
> > >    * #8632 (Jersey 4.0.2 upgrade on 2.x)
> > >    * #8615 (Checkstyle 13.4.2 on master)
> > >
> > > Both have been reverted and both master and 2.x are ok.
> > >
> > > I'll create a RC for 2.8.8 during the week.
> > >
> > > On Sun, 10 May 2026 at 17:01, Rui Abreu <[email protected]>
> > > wrote:
> > > >
> > > > Ok, we can hold off on 3.0.0 for now.
> > > > I'll focus on making sure 2.8.8 has the necessary changeset and
> > > > then we can get the RC going.
> > > >
> > > > On Sun, May 10, 2026, 16:58 Richard Zowalla <[email protected]>
> > > > wrote:
> > > > >
> > > > > Hi all,
> > > > >
> > > > > 2.8.8 is fine for me. Guess we need to confirmed dependabot for
> > > > > 2.x branches too (+ license update action)
> > > > >
> > > > > 3.0.0 would need the Java 21 bump before (as discussed in the
> > > > > related discussion - dont know if there are other things like
> > > > > the Jitter RFC stuff for it) - perhaps there is something else.
> > > > >
> > > > > Gruß
> > > > > Richard
> > > > >
> > > > > > Am 10.05.2026 um 17:13 schrieb Rui Abreu <[email protected]>:
> > > > > >
> > > > > > Hi folks,
> > > > > >
> > > > > > Just trying to understand if you are keen on performing a
> > > > > > release for both
> > > > > > versions shortly
>

Reply via email to