In order to release a new version of Apache Baremaps, follow these steps:
cd baremaps
git checkout -b release-$RELEASE_VERSION
./mvnw versions:set -DnewVersion=$RELEASE_VERSION
git commit -a -m "Release Baremaps $RELEASE_VERSION"
git push --set-upstream origin release-$RELEASE_VERSION
git tag v$RELEASE_VERSION-rc$CANDIDATE_NUMBER
git push origin v$RELEASE_VERSION-rc$CANDIDATE_NUMBER
./mvnw clean deploy -Papache-release
TODO: The following step is not yet fully automated. We need to add secrets and steps to publish the artifacts to the dev directory (APACHE_USERNAME, APACHE_PASSWORD) and to the maven repository (NEXUS_USERNAME, NEXUS_PASSWORD).
git tag -a v$RELEASE_VERSION
git push origin v$RELEASE_VERSION
svn cp https://dist.apache.org/repos/dist/dev/incubator/baremaps/$RELEASE_VERSION-rc$CANDIDATE_NUMBER https://dist.apache.org/repos/dist/release/incubator/baremaps/$RELEASE_VERSION -m "Release Apache Baremaps (incubating) $RELEASE_VERSION"
./mvnw versions:set -DnewVersion=$NEXT_VERSION-SNAPSHOT
git commit -a -m "Prepare for next development iteration"
git push origin
Reproducing the build
The release artifacts are bit-by-bit reproducible if the following conditions are met:
- The build is run with the same version of the JDK (e.g. OpenJDK 17 temurin)
- The build is run with the maven wrapper (e.g.
./mvnw)
The procedure has been tested on different operating systems (e.g. Linux and MacOS).
For convenience, we suggest to build the release artifacts on a clean environment (e.g. a fresh Docker container).
git checkout v$RELEASE_VERSION-rc$CANDIDATE_NUMBER
docker run \
-v $(pwd):/baremaps \
-w /baremaps \
eclipse-temurin:17-jdk \
./mvnw clean install -DskipTests
Verifying the release artifacts
Verify the GPG signature of the release artifacts:
gpg --verify apache-baremaps-$RELEASE_VERSION-incubating-bin.tar.gz.asc
gpg --verify apache-baremaps-$RELEASE_VERSION-incubating-src.tar.gz.asc
Verify the SHA512 checksum of the release artifacts:
shasum -a 512 -c apache-baremaps-$RELEASE_VERSION-incubating-bin.tar.gz.sha512
shasum -a 512 -c apache-baremaps-$RELEASE_VERSION-incubating-src.tar.gz.sha512
In order to release a new version of Apache Baremaps, follow these steps:
release-$RELEASE_VERSION)Reproducing the build
The release artifacts are bit-by-bit reproducible if the following conditions are met:
./mvnw)The procedure has been tested on different operating systems (e.g. Linux and MacOS).
For convenience, we suggest to build the release artifacts on a clean environment (e.g. a fresh Docker container).
Verifying the release artifacts
Verify the GPG signature of the release artifacts:
Verify the SHA512 checksum of the release artifacts: