rmannibucau commented on issue #8608:
URL: https://github.com/apache/hop/issues/8608#issuecomment-5857996428

   @hansva I'm not sure it would be intended nor desired, at Apache the 
ownership is really by PMC so there should be a set of key per PMC (not 
strictly per project if you look at incubator or commons for ex) even if owned 
by Apache infra. Ultimately PMC must have access to a set of keys too since 
they are legal owners of the content.
   Short term I guess the refresh job on github action with an infra secret can 
be a compromise.
   But it is not very different than docker images - generally speaking, as 
soon as it is no more sources it is no more 100% required to be done at apache 
- where some people handle it outside apache.
   
   @marc0der how is it managed by all projects on sdkman today - I know some 
are not aligned with your security rules for example and several are done by 
individual?
   
   ```
   Apache ActiveMQ (Classic) (5.17.1)                  
https://activemq.apache.org/
   Ant (1.10.17)                                            
https://ant.apache.org/
   CXF (3.2.5)                                              
https://cxf.apache.org/
   Flink (1.19.0)                                         
https://flink.apache.org/
   hadoop (3.4.1)                                        
https://hadoop.apache.org/
   Apache JMeter (5.6.3)                                 
https://jmeter.apache.org/
   Karaf (4.2.8)                                          
https://karaf.apache.org/
   Maven (3.9.16)                                         
https://maven.apache.org/
   Spark (4.1.1)                                          
https://spark.apache.org/
   Apache Tomcat (11.0.22)                               
https://tomcat.apache.org/
   ```
   
   Since Apache are standardized (either using central or 
https://archive.apache.org/dist/ - and guess we can ask all projects to 
converge to central if it helps - including Apache Hop) any way there is a 
scheduled job synchronizing releases in sdkman instead of awaiting for a push? 
Can also make it smoother for everyone.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to