ppkarwasz commented on PR #512: URL: https://github.com/apache/logging-parent/pull/512#issuecomment-5713114776
@vy, This PR is a change required by Flume. In the main Flume repo we can not have the inheritance chain `logging-parent` -> `flume-bom` -> `flume-parent` -> artifact, because `flume-parent` is **reused** by other repos and `flume-bom` is flattened. This means we need to have **two** artifacts that directly inherit from `logging-parent`. Those artifacts need to declare `revision` and `project.build.outputTimestamp` separately. We are still **dogfooding** the BOM as in other repos, we just don't do it via inheritance, but via BOM import. That didn't change. ### About `GIT_AUTHOR_DATE` You might be wondering why I care about `GIT_AUTHOR_DATE`. As you know, in the medium term I would like for all `release/*` branches to be protected. This way we can cryptographically verify (SLSA Source Attestations published to the public Rekor store) that **each** commit has been reviewed before. In that case, we need to split `deploy-build-reusable` into two parts: - One will keep helping us in release automation and it will complete every **internal** PR to `release/*`. It can even run on `pull_request_target`. - Another part will make an RC for **each** commit to `release/*`. This workflow can check that `revision == name of the branch` and that `project.build.outputTimestamp` is equal to the author date of the commit. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
