FreeAndNil opened a new pull request, #330: URL: https://github.com/apache/logging-log4net/pull/330
build-release.ps1 built the binaries from the working tree but archived the local master ref, so the signed source zip need not match the signed binaries. * Refuse a dirty tree, archive HEAD, ship the commit as a signed .commit artifact. No origin/master check: that needs the network and forbids cutting a release from a tag or a release branch. * Both verifiers hold it against the commit git archive writes into the zip comment, and require both files, or stripping one would skip the check. * sign-log4net-libraries.sh gains set -euo pipefail and shopt -s nullglob. An empty directory iterated the glob patterns and still exited 0. * build-release.ps1 takes an Rc parameter, default 1. It and $Preview in build-preview.ps1 are positive ints, so a bad value fails at binding rather than after the confirmation pause. audit da18b6fd-f025 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
